Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,407GitHub PoC 14,247VulnCheck XDB 8,663Nuclei 4,287Metasploit 3,474✓ verified onlyrecentpopularrisk
24,455 exploits
Exploit-DB✓ VexDay Proof
EZContents 2.0.3 - 'toprated.php?GLOBALS[language_home]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
VisualShapers EZContents 2.0.3 - 'Loginreq2.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in loginreq2.php in Visual Shapers ezContents 2.0.3 allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
EZContents 2.0.3 - 'shownews.php?GLOBALS[admin_home]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
Learn.com - 'Learncenter.asp' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in learncenter.asp in Learn.com LearnCenter allows remote attackers to inject a
23RISK
open ↗Exploit-DB✓ VexDay Proof
EZContents 2.0.3 - 'search.php?GLOBALS[language_home]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
EZContents 2.0.3 - 'showguestbook.php?GLOBALS[admin_home]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
HLstats 1.34 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in index.php in HLStats 1.34 allows remote attackers to inject arbitrary web sc
23RISK
open ↗Exploit-DB✓ VexDay Proof
ModuleBased CMS - Multiple Remote File Inclusions
PHP remote file inclusion vulnerability in ModuleBased CMS Pre-Alpha allows remote attackers to execute arbitrary PHP co
23RISK
open ↗Exploit-DB✓ VexDay Proof
Streamripper 1.61.25 - HTTP Header Parsing Buffer Overflow (1)
Buffer overflow in the HTTP header parsing in Streamripper before 1.61.26 allows remote attackers to cause a denial of s
28RISK
open ↗Exploit-DB✓ VexDay Proof
Streamripper 1.61.25 - HTTP Header Parsing Buffer Overflow (2)
Buffer overflow in the HTTP header parsing in Streamripper before 1.61.26 allows remote attackers to cause a denial of s
28RISK
open ↗Exploit-DB✓ VexDay Proof
HLstats 1.34 - 'hlstats.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in hlstats.php in HLstats 1.34 allows remote attackers to inject arbitrary web
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cybozu Products - 'id' Arbitrary File Retrieval
Multiple directory traversal vulnerabilities in Cybozu Office before 6.6 Build 1.3 and Share 360 before 2.5 Build 0.3 al
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1 - Daxctle.OCX Spline Method Heap Buffer Overflow
Heap-based buffer overflow in DirectAnimation.PathControl COM object (daxctle.ocx) in Microsoft Internet Explorer 6.0 SP
35RISK
open ↗Exploit-DB✓ VexDay Proof
Cybuzu Garoon 2.1.0 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Cybozu Garoon 2.1.0 for Windows allow remote authenticated users to execute ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - NetpIsRemote() Remote Overflow (MS06-040) (2)
Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote a
60RISK
open ↗Exploit-DB✓ VexDay Proof
Ay System CMS 2.6 - 'main.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Ay System Solutions CMS 2.6 and earlier allow remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
Symantec AntiVirus - IOCTL Kernel Privilege Escalation (2)
The (a) NAVENG (NAVENG.SYS) and (b) NAVEX15 (NAVEX15.SYS) device drivers 20061.3.0.12 and later, as used in Symantec Ant
23RISK
open ↗Exploit-DB✓ VexDay Proof
Alt-N MDaemon POP3 Server < 9.06 - 'USER' Remote Heap Overflow
Multiple heap-based buffer overflows in the POP3 server in Alt-N Technologies MDaemon before 9.0.6 allow remote attacker
35RISK
open ↗Exploit-DB✓ VexDay Proof
Jupiter CMS 1.1.5 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to execute arbitrary P
48RISK
open ↗Exploit-DB✓ VexDay Proof
Jetbox CMS 2.1 - 'Search_function.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/phpdig/libs/search_function.php in Jetbox CMS 2.1 allows remote atta
23RISK
open ↗Exploit-DB✓ VexDay Proof
BigACE 1.8.2 - 'download.cmd.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Bigace 1.8.2 allow remote attackers to execute arbitrary PHP code
23RISK
open ↗Exploit-DB✓ VexDay Proof
BigACE 1.8.2 - 'admin.cmd.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Bigace 1.8.2 allow remote attackers to execute arbitrary PHP code
23RISK
open ↗Exploit-DB✓ VexDay Proof
Symantec AntiVirus - IOCTL Kernel Privilege Escalation (1)
The (a) NAVENG (NAVENG.SYS) and (b) NAVEX15 (NAVEX15.SYS) device drivers 20061.3.0.12 and later, as used in Symantec Ant
23RISK
open ↗Exploit-DB✓ VexDay Proof
MyBB 1.1.7 - Multiple HTML Injection Vulnerabilities
Cross-site scripting (XSS) vulnerability in attachment.php in MyBulletinBoard (MyBB) 1.1.7 and possibly other versions a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! / Mambo Component Comprofiler 1.0 - 'class.php' Remote File Inclusion
PHP remote file inclusion vulnerability in plugin.class.php in the com_comprofiler Components 1.0 RC2 for Mambo and Joom
23RISK
open ↗Exploit-DB✓ VexDay Proof
BigACE 1.8.2 - 'item_main.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Bigace 1.8.2 allow remote attackers to execute arbitrary PHP code
23RISK
open ↗Exploit-DB✓ VexDay Proof
BigACE 1.8.2 - 'upload_form.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Bigace 1.8.2 allow remote attackers to execute arbitrary PHP code
23RISK
open ↗Exploit-DB✓ VexDay Proof
Alstrasoft Video Share Enterprise 4.x - 'MyajaxPHP.php' Remote File Inclusion
PHP remote file inclusion vulnerability in myajaxphp.php in AlstraSoft Video Share Enterprise allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
BlackBoard Products 6 - Multiple HTML Injection Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Learning System 6, Blackboard Learning and Community P
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHPCOIN 1.2.3 - 'session_set.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in phpCOIN 1.2.3 allow remote attackers to execute arbitrary PHP code
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.