Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,367GitHub PoC 14,225VulnCheck XDB 8,649Nuclei 4,283Metasploit 3,474✓ verified onlyrecentpopularrisk
24,451 exploits
Exploit-DB✓ VexDay Proof
HP (Multiple Products) - PML Driver HPZ12 Privilege Escalation
The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE
23RISK
open ↗Exploit-DB✓ VexDay Proof
Application Enhancer (APE) 2.0.2 - Local Privilege Escalation
Unsanity Application Enhancer (APE) 2.0.2 installs with insecure permissions for the (1) ApplicationEnhancer binary and
23RISK
open ↗Exploit-DB✓ VexDay Proof
OpenBSD 3.x < 4.0 - 'vga_ioctl()' Local Privilege Escalation
Unspecified vulnerability in sys/dev/pci/vga_pci.c in the VGA graphics driver for wscons in OpenBSD 3.9 and 4.0, when th
23RISK
open ↗Exploit-DB✓ VexDay Proof
NaviCOPA Web Server 2.01 - 'GET' Remote Buffer Overflow (Metasploit)
Buffer overflow in InterVations NaviCOPA Web Server 2.01 allows remote attackers to execute arbitrary code via a long HT
50RISK
open ↗Exploit-DB✓ VexDay Proof
Easy Banner Pro 2.8 - 'info.php' Remote File Inclusion
PHP remote file inclusion vulnerability in info.php in Easy Banner Pro 2.8 allows remote attackers to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Core 2.0.5 - Trackback UTF-7 SQL Injection
WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query,
23RISK
open ↗Exploit-DB✓ VexDay Proof
Shopstorenow E-Commerce Shopping Cart - 'Orange.asp' SQL Injection
SQL injection vulnerability in orange.asp in ShopStoreNow E-commerce Shopping Cart allows remote attackers to execute ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
Multiple PDF Readers - Multiple Remote Buffer Overflows
The Adobe PDF specification 1.3, as implemented by Adobe Acrobat before 8.0.0, allows remote attackers to have an unknow
28RISK
open ↗Exploit-DB✓ VexDay Proof
EditTag 1.2 - 'edittag_mp.cgi?file' Arbitrary File Disclosure
Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an ab
23RISK
open ↗Exploit-DB✓ VexDay Proof
EditTag 1.2 - 'mkpw.pl?plain' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in EditTag 1.2 allow remote attackers to inject arbitrary web script
23RISK
open ↗Exploit-DB✓ VexDay Proof
EditTag 1.2 - 'mkpw.cgi?plain' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in EditTag 1.2 allow remote attackers to inject arbitrary web script
23RISK
open ↗Exploit-DB✓ VexDay Proof
EditTag 1.2 - 'edittag_mp.pl?file' Arbitrary File Disclosure
Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an ab
23RISK
open ↗Exploit-DB✓ VexDay Proof
Coppermine Photo Gallery 1.4.10 - 'xpl.php' SQL Injection
SQL injection vulnerability in Coppermine Photo Gallery (CPG) before 1.4.11 allows remote attackers to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.4.8 - DiskManagement BOM Privilege Escalation
DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader Plugin 7.0.x - 'acroreader' Cross-Site Scripting
Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows re
35RISK
open ↗Exploit-DB✓ VexDay Proof
EditTag 1.2 - 'edittag.pl?file' Arbitrary File Disclosure
Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an ab
23RISK
open ↗Exploit-DB✓ VexDay Proof
ig shop 1.0 - Code Execution / SQL Injection
Multiple SQL injection vulnerabilities in display_review.php in iGeneric iG Shop 1.4 and earlier allow remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
EditTag 1.2 - 'edittag.cgi?file' Arbitrary File Disclosure
Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an ab
23RISK
open ↗Exploit-DB✓ VexDay Proof
Symantec Backup Exec System Recovery Manager 7.0 - FileUpload Class Unauthorized File Upload
Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, a
28RISK
open ↗Exploit-DB✓ VexDay Proof
Kolayindir Download - 'down.asp' SQL Injection
SQL injection vulnerability in down.asp in Kolayindir Download (Yenionline) allows remote attackers to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
RI Blog 1.3 - 'search.asp' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.asp in RI Blog 1.3 allows remote attackers to inject arbitrary web sc
23RISK
open ↗Exploit-DB✓ VexDay Proof
Coppermine Photo Gallery 1.4.11 - SQL Injection
Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated adminis
23RISK
open ↗Exploit-DB✓ VexDay Proof
EditTag 1.2 - 'mkpw_mp.cgi?plain' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in EditTag 1.2 allow remote attackers to inject arbitrary web script
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.4.8 - DiskManagement BOM 'cron' Local Privilege Escalation
DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple QuickTime (Windows 2000) - 'rtsp URL Handler' Remote Buffer Overflow
Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
50RISK
open ↗Exploit-DB✓ VexDay Proof
Apple QuickTime 7.1.3 - 'HREFTrack' Cross-Zone Scripting
Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitr
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Reader 9.1.3 Plugin - Cross-Site Scripting
Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attack
35RISK
open ↗Exploit-DB✓ VexDay Proof
MyServer 0.9.8 - Post.MSCGI Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the cgi-bin/post.mscgi sample page in MyServer 0.8.9 allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
Georgia SoftWorks Secure Shell Server 7.1.3 - Multiple Remote Code Execution Vulnerabilities
Multiple buffer overflows in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allow remote attackers to ex
23RISK
open ↗Exploit-DB✓ VexDay Proof
AShop Deluxe 4.5 - 'basket.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote atta
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.