Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,367GitHub PoC 14,225VulnCheck XDB 8,649Nuclei 4,283Metasploit 3,474✓ verified onlyrecentpopularrisk
24,451 exploits
Exploit-DB✓ VexDay Proof
Xt-News 0.1 - 'show_news.php?id_news' SQL Injection
SQL injection vulnerability in show_news.php in Xt-News 0.1 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Efkan Forum 1.0 - 'Grup' SQL Injection
SQL injection vulnerability in default.asp in Efkan Forum 1.0 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
KISGB 5.1.1 - 'Authenticate.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the Keep It Simple Guest Book (KISGB) allow remote attackers to ex
23RISK
open ↗Exploit-DB✓ VexDay Proof
Xt-News 0.1 - 'add_comment.php?id_news' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Xt-News 0.1 allow remote attackers to inject arbitrary web script
23RISK
open ↗Exploit-DB✓ VexDay Proof
Xt-News 0.1 - 'show_news.php?id_news' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Xt-News 0.1 allow remote attackers to inject arbitrary web script
23RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Portal 9i/10g - Container_Tabs.jsp Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Oracle Portal 9i and 10g allow remote attackers to inject arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
XM Easy Personal FTP Server 5.2.1 - 'USER' Format String Denial of Service
Format string vulnerability in XM Easy Personal FTP Server 5.2.1 allows remote attackers to cause a denial of service (a
23RISK
open ↗Exploit-DB✓ VexDay Proof
MKPortal M1.1.1 - 'Urlobox' Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in urlobox in MKPortal allows remote attackers to delete arbitrary messa
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mono XSP 1.x/2.0 - Source Code Information Disclosure
The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, whi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Typo3 3.7/3.8/4.0 - 'Class.TX_RTEHTMLArea_PI1.php' Multiple Remote Command Execution Vulnerabilities
rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php in Typo3 4.0.0 through 4.0.3, 3.7 and 3.8 with the rtehtmlarea extension, a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Portal 9.0.2 - Calendar.jsp Multiple HTTP Response Splitting Vulnerabilities
CRLF injection vulnerability in webapp/jsp/calendar.jsp in Oracle Portal 10g and earlier, including 9.0.2, allows remote
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'MessageBox' Memory Corruption Local Denial of Service
Double free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain privileges by callin
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP Advanced Transfer Manager 1.30 - Source Code Disclosure
PHP Advanced Transfer Manager 1.00 through 1.30 stores sensitive information, including password hashes, under the web r
23RISK
open ↗Exploit-DB✓ VexDay Proof
Burak Yilmaz Download Portal - 'down.asp' SQL Injection
SQL injection vulnerability in down.asp in Burak Yylmaz Download Portal allows remote attackers to execute arbitrary SQL
23RISK
open ↗Exploit-DB✓ VexDay Proof
KDE LibkHTML 4.2 - NodeType Function Denial of Service
The nodeType function in KDE libkhtml 4.2.0 and earlier, as used by Konquerer, KMail, and other programs, allows remote
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mini Web Shop 2.1.c - 'view.php?Viewcategory.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1
23RISK
open ↗Exploit-DB✓ VexDay Proof
Intel 2200BG 802.11 - Beacon frame Kernel Memory Corruption
Race condition in W29N51.SYS in the Intel 2200BG wireless driver 9.0.3.9 allows remote attackers to cause memory corrupt
23RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle 9i/10g - 'extproc' Local/Remote Command Execution
Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries
28RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle 9i/10g - 'utl_file' FileSystem Access
Absolute path traversal vulnerability in Oracle Database Server, when utl_file_dir is set to a wildcard value or "CREATE
23RISK
open ↗Exploit-DB✓ VexDay Proof
osTicket 1.2/1.3 Support Cards - 'view.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in support/view.php in Support Cards 1 (osTicket) allows remote attackers to in
23RISK
open ↗Exploit-DB✓ VexDay Proof
KDE libkhtml 3.5 < 4.2.0 - Unhandled HTML Parse Exception
The nodeType function in KDE libkhtml 4.2.0 and earlier, as used by Konquerer, KMail, and other programs, allows remote
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Outlook - ActiveX Control Remote Internet Explorer Denial of Service
The Microsoft Office Outlook Recipient ActiveX control (ole32.dll) in Windows XP SP2 allows remote attackers to cause a
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Office Outlook Recipient Control - 'ole32.dll' Denial of Service
The Microsoft Office Outlook Recipient ActiveX control (ole32.dll) in Windows XP SP2 allows remote attackers to cause a
28RISK
open ↗Exploit-DB✓ VexDay Proof
RateMe 1.3.2 - 'main.inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in main.inc.php in planetluc.com RateMe 1.3.2 and earlier allows remote attacker
23RISK
open ↗Exploit-DB✓ VexDay Proof
Grsecurity Kernel PaX - Local Privilege Escalation
Unspecified vulnerability in the expand_stack function in grsecurity PaX allows local users to gain privileges via unspe
41RISK
open ↗Exploit-DB✓ VexDay Proof
Knusperleicht Shoutbox 2.6 - 'Shout.php' HTML Injection
Multiple cross-site scripting (XSS) vulnerabilities in shout.php in Knusperleicht ShoutBox 2.6 allow remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
Omniture SiteCatalyst - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Omniture SiteCatalyst allow remote attackers to inject arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
Contra Haber Sistemi 1.0 - 'Haber.asp' SQL Injection
SQL injection vulnerability in haber.asp in Contra Haber Sistemi 1.0 allows remote attackers to execute arbitrary SQL co
23RISK
open ↗Exploit-DB✓ VexDay Proof
Multiple Vendor Firewall - HIPS Process Spoofing
AVG Anti-Virus plus Firewall 7.5.431 relies on the Process Environment Block (PEB) to identify a process, which allows l
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Media Player 6.4/10.0 - MID Malformed Header Chunk Denial of Service
Windows Media Player 10.00.00.4036 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial o
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.