Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,407GitHub PoC 14,247VulnCheck XDB 8,663Nuclei 4,287Metasploit 3,474✓ verified onlyrecentpopularrisk
24,455 exploits
Exploit-DB✓ VexDay Proof
PHPCOIN 1.2.3 - 'session_set.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in phpCOIN 1.2.3 allow remote attackers to execute arbitrary PHP code
23RISK
open ↗Exploit-DB✓ VexDay Proof
RedBlog 0.5 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in RedBLoG 0.5 allows remote attackers to execute arbitrary PHP cod
23RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris 10 sysinfo(2) - Local Kernel Memory Disclosure (2)
systeminfo.c for Sun Solaris allows local users to read kernel memory via a 0 variable count argument to the sysinfo sys
23RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris 8/9 - '/usr/ucb/ps' Local Information Leak
/usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environmen
23RISK
open ↗Exploit-DB✓ VexDay Proof
2WIRE Modems/Routers - 'CRLF' Denial of Service
The management interface on the 2wire Gateway 1700HG, 1701HG, 1800HW, 2071, 2700HG, and 2701HG-T with software before 5.
23RISK
open ↗Exploit-DB✓ VexDay Proof
cPanel 10.x - 'dohtaccess.html?dir' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote attackers to inject arbitrary web script o
23RISK
open ↗Exploit-DB✓ VexDay Proof
Easy File Sharing FTP Server 2.0 - 'PASS' Remote
Stack-based buffer overflow in EFS Software Easy File Sharing FTP Server 2.0 allows remote attackers to execute arbitrar
50RISK
open ↗Exploit-DB✓ VexDay Proof
DieselScripts Smart Traffic - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in clients/index.php in Diesel Smart Traffic allows remote attackers to execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 6 - Multiple COM Object Color Property Denial of Service Vulnerabilities
Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) via a long Color attrib
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - Multiple COM Object Instantiation Code Execution Vulnerabilities
Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execut
28RISK
open ↗Exploit-DB✓ VexDay Proof
DieselScripts DieselPay - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Diesel Pay allows remote attackers to inject arbitrary web scri
23RISK
open ↗Exploit-DB✓ VexDay Proof
cPanel 10.x - 'editit.html?File' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote attackers to inject arbitrary web script o
23RISK
open ↗Exploit-DB✓ VexDay Proof
cPanel 10.x - 'showfile.html?File' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote attackers to inject arbitrary web script o
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHProjekt Content Management Module 0.6.1 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in the Content Management module ("Content manager") for PHProjekt 0.
23RISK
open ↗Exploit-DB✓ VexDay Proof
ToendaCMS 0.x/1.0.x - 'TCMS_Administer' Remote File Inclusion
PHP remote file inclusion vulnerability in ToendaCMS 1.0.3 and earlier allows remote attackers to execute arbitrary PHP
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mambo Component EstateAgent 1.0.2 - MosConfig_absolute_path Remote File Inclusion
PHP remote file inclusion vulnerability in estateagent.php in the EstateAgent component (com_estateagent) for Mambo, whe
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache < 1.3.37/2.0.59/2.2.3 mod_rewrite - Remote Overflow
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and o
60RISK
open ↗Exploit-DB✓ VexDay Proof
DieselScripts Diesel Paid Mail - 'Getad.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in getad.php in Diesel Paid Mail allows remote attackers to inject arbitrary we
23RISK
open ↗Exploit-DB✓ VexDay Proof
XennoBB 1.0.x/2.2 - Icon_Topic SQL Injection
SQL injection vulnerability in topic_post.php in XennoBB 2.2.1 and earlier allows remote attackers to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - CanonicalizePathName() Remote (MS06-040)
Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote a
60RISK
open ↗Exploit-DB✓ VexDay Proof
Tutti Nova 1.6 - 'TNLIB_DIR' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Tutti Nova 1.6 and earlier allow remote attackers to execute arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
Novell Identity Manager - Arbitrary Command Execution
Mozilla Firefox 1.5.0.6 allows remote attackers to cause a denial of service (crash) via a crafted FTP response, when at
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Artlinks 1.0b4 - Remote File Inclusion
PHP remote file inclusion vulnerability in artlinks.dispnew.php in the Artlinks component (com_artlinks) for Mambo allow
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sonium Enterprise Adressbook 0.2 - 'folder' Include
PHP remote file inclusion vulnerability in Sonium Enterprise Adressbook 0.2 allows remote attackers to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Mosets Tree 1.0 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Paul M. Jones Savant2, possibly when used with the com_mtree compo
28RISK
open ↗Exploit-DB✓ VexDay Proof
MySQL 4/5 - SUID Routine Miscalculation Arbitrary DML Statement Execution
MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's
28RISK
open ↗Exploit-DB✓ VexDay Proof
CubeCart 3.0.11 - 'oid' Blind SQL Injection
Multiple SQL injection vulnerabilities in CubeCart 3.0.11 and earlier allow remote attackers to execute arbitrary SQL co
23RISK
open ↗Exploit-DB✓ VexDay Proof
GNU BinUtils 2.1x - GAS Buffer Overflow
Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundati
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 6 - 'TSUserEX.dll' ActiveX Control Memory Corruption
The Terminal Services COM object (tsuserex.dll) allows remote attackers to cause a denial of service (crash) and possibl
28RISK
open ↗Exploit-DB✓ VexDay Proof
PHP 4.4.3/5.1.4 - 'sscanf' Local Buffer Overflow
scanf.c in PHP 5.1.4 and earlier, and 4.4.3 and earlier, allows context-dependent attackers to execute arbitrary code vi
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.