Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,407GitHub PoC 14,247VulnCheck XDB 8,663Nuclei 4,287Metasploit 3,474✓ verified onlyrecentpopularrisk
24,455 exploits
Exploit-DB✓ VexDay Proof
Tagger Luxury Edition - 'BBCodeFile' Remote File Inclusion
Eval injection vulnerability in Tagger LE allows remote attackers to execute arbitrary PHP code via the query string in
23RISK
open ↗Exploit-DB✓ VexDay Proof
IrfanView 3.98 - '.ANI' Image File Denial of Service
IrfanView 3.98 (with plugins) allows user-assisted attackers to cause a denial of service (application crash) via a craf
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache 2.2.2 - CGI Script Source Code Information Disclosure
Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that co
35RISK
open ↗Exploit-DB✓ VexDay Proof
AlsaPlayer 0.99.x - Multiple Buffer Overflow Vulnerabilities
Multiple buffer overflows in Andy Lo-A-Foe AlsaPlayer 0.99.76 and earlier allow remote attackers to cause a denial of se
28RISK
open ↗Exploit-DB✓ VexDay Proof
XennoBB 1.0.5/1.0.6/2.1/2.2 - 'profile.php' Directory Traversal
Directory traversal vulnerability in the avatar_gallery action in profile.php in XennoBB 2.1.0 and earlier allows remote
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cwfm 0.9.1 - 'Language' Remote File Inclusion
PHP remote file inclusion vulnerability in CheckUpload.php in Vincenzo Valvano Comet WebFileManager (CWFM) 0.9.1, and po
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 6 - Visual Studio COM Object Instantiation Denial of Service
Microsoft Visual Studio 6.0 allows remote attackers to cause a denial of service (memory corruption) and possibly execut
28RISK
open ↗Exploit-DB✓ VexDay Proof
Barracuda Spam Firewall 3.3.03.053 - Remote Code Execution (2)
preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote attackers to execute comm
23RISK
open ↗Exploit-DB✓ VexDay Proof
VWar 1.5 - 'stats.php?vwar_root' Remote File Inclusion
PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP cod
23RISK
open ↗Exploit-DB✓ VexDay Proof
VWar 1.5 - 'calendar.php?vwar_root' Remote File Inclusion
PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP cod
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpPrintAnalyzer 1.1 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Thomas Pequet phpPrintAnalyzer 1.1, when register_globals is ena
23RISK
open ↗Exploit-DB✓ VexDay Proof
VWar 1.5 - 'member.php?vwar_root' Remote File Inclusion
PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP cod
23RISK
open ↗Exploit-DB✓ VexDay Proof
eIQnetworks License Manager - Remote Buffer Overflow (Metasploit) (3)
Multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) before 2.5.0, as used in product
60RISK
open ↗Exploit-DB✓ VexDay Proof
VWar 1.5 - 'war.php?vwar_root' Remote File Inclusion
PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP cod
23RISK
open ↗Exploit-DB✓ VexDay Proof
ME Download System 1.3 - 'header.php' Remote File Inclusion
PHP remote file inclusion vulnerability in templates/header.php in ME Download System 1.3 allows remote attackers to exe
23RISK
open ↗Exploit-DB✓ VexDay Proof
SAPID 1.2.3.05 - 'ROOT_PATH' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Csaba Godor SAPID Blog Beta 2 and earlier allow remote attackers t
23RISK
open ↗Exploit-DB✓ VexDay Proof
TWiki 4.0.4 - 'configure' Remote Command Execution
Eval injection vulnerability in the configure script in TWiki 4.0.0 through 4.0.4 allows remote attackers to execute arb
23RISK
open ↗Exploit-DB✓ VexDay Proof
SAPID Shop 1.2 - 'ROOT_PATH' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Csaba Godor SAPID Blog Beta 2 and earlier allow remote attackers t
23RISK
open ↗Exploit-DB✓ VexDay Proof
VWar 1.5 - 'challenge.php?vwar_root' Remote File Inclusion
PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP cod
23RISK
open ↗Exploit-DB✓ VexDay Proof
VWar 1.5 - 'news.php?vwar_root' Remote File Inclusion
PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP cod
23RISK
open ↗Exploit-DB✓ VexDay Proof
SAPID Gallery 1.0 - 'ROOT_PATH' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Csaba Godor SAPID Blog Beta 2 and earlier allow remote attackers t
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHPCodeCabinet 0.5 - 'Core.php' Remote File Inclusion
PHP remote file inclusion vulnerability in Beautifier/Core.php in Brad Fears phpCodeCabinet 0.5 and earlier allows remot
23RISK
open ↗Exploit-DB✓ VexDay Proof
Clam Anti-Virus ClamAV 0.88.x - UPX Compressed PE File Heap Buffer Overflow
Heap-based buffer overflow in the pefromupx function in libclamav/upx.c in Clam AntiVirus (ClamAV) 0.81 through 0.88.3 a
28RISK
open ↗Exploit-DB✓ VexDay Proof
Festalon 0.5 - '.HES' Remote Heap Buffer Overflow
The FESTAHES_Load function in pce/hes.c in Festalon 0.5.0 through 0.5.5 allows user-assisted attackers to cause a denial
23RISK
open ↗Exploit-DB✓ VexDay Proof
ModernBill 1.6 - 'config.php' Remote File Inclusion
PHP remote file inclusion vulnerability in include/html/config.php in ModernGigabyte ModernBill 1.6 allows remote attack
23RISK
open ↗Exploit-DB✓ VexDay Proof
XennoBB 2.1 - 'profile.php' Multiple SQL Injections
SQL injection vulnerability in profile.php in XennoBB 2.1.0 and earlier allows remote authenticated users to execute arb
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpAutoMembersArea 3.2.5 - 'installed_config_file' Remote File Inclusion
PHP remote file inclusion vulnerability in auto_check_renewals.php in phpAutoMembersArea (phpAMA) 3.2.4 and earlier allo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.17.7 - NFS and EXT3 Combination Remote Denial of Service
Linux kernel 2.6.x, when using both NFS and EXT3, allows remote attackers to cause a denial of service (file system pani
28RISK
open ↗Exploit-DB✓ VexDay Proof
VWar 1.5 - 'joinus.php?vwar_root' Remote File Inclusion
PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP cod
23RISK
open ↗Exploit-DB✓ VexDay Proof
Barracuda Spam Firewall 3.3.03.053 - Remote Code Execution (1)
preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote attackers to execute comm
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.