Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,587cataloged exploits
35,644CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,428GitHub PoC 14,268VulnCheck XDB 8,663Nuclei 4,299Metasploit 3,474✓ verified onlyrecentpopularrisk
24,455 exploits
Exploit-DB✓ VexDay Proof
BT Voyager 2091 (Wireless ADSL) - Multiple Vulnerabilities
BT Voyager 2091 Wireless firmware 2.21.05.08m_A2pB018c1.d16d and earlier, and 3.01m and earlier, allow remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
Invision Power Board 2.1 < 2.1.6 - SQL Injection (2)
SQL injection vulnerability in classes/class_session.php in Invision Power Board (IPB) 2.1 up to 2.1.6 allows remote att
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.13 < 2.6.17.4 - 'logrotate prctl()' Local Privilege Escalation
The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a l
23RISK
open ↗Exploit-DB✓ VexDay Proof
MySQL 4.x/5.x - Server Date_Format Denial of Service
Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authe
28RISK
open ↗Exploit-DB✓ VexDay Proof
ListMessenger 0.9.3 - 'LM_Path' Remote File Inclusion
PHP remote file inclusion vulnerability in enduser/listmessenger.php in ListMessenger 0.9.3 allows remote attackers to e
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mambo Component perForms 1.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in performs.php in the perForms component (com_performs) 1.0 and earlier for Joo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mambo Module Calendar 1.5.7 - 'Com_Calendar.php' Remote File Inclusion
PHP remote file inclusion vulnerability in com_calendar.php in Calendar Mambo Module 1.5.7 and earlier allows remote att
23RISK
open ↗Exploit-DB✓ VexDay Proof
Agnitum Outpost Firewall 3.5.631 - 'FiltNT.SYS' Local Denial of Service
filtnt.sys in Outpost Firewall Pro before 3.51.759.6511 (462) allows local users to cause a denial of service (crash) vi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mambo Component pollxt 1.22.07 - Remote File Inclusion
Unspecified vulnerability in PollXT component (com_pollxt) 1.22.07 and earlier for Joomla! has unspecified impact and at
23RISK
open ↗Exploit-DB✓ VexDay Proof
D-Link Routers - UPNP Buffer Overflow
Stack-based buffer overflow in the Universal Plug and Play (UPnP) service in D-Link DI-524, DI-604 Broadband Router, DI-
28RISK
open ↗Exploit-DB✓ VexDay Proof
FlushCMS 1.0.0-pre2 - 'class.rich.php' Remote File Inclusion
PHP remote file inclusion vulnerability in Include/editor/class.rich.php in FlushCMS 1.0.0-pre2 and earlier allows remot
23RISK
open ↗Exploit-DB✓ VexDay Proof
MyBulletinBoard (MyBB) 1.1.5 - 'CLIENT-IP' SQL Injection
Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 a
50RISK
open ↗Exploit-DB✓ VexDay Proof
MyBulletinBoard (MyBB) 1.1.5 - 'CLIENT-IP' SQL Injection
Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger ha
60RISK
open ↗Exploit-DB✓ VexDay Proof
Rocks Clusters 4.1 - 'umount-loop' Local Privilege Escalation
Rocks Clusters 4.1 and earlier allows local users to gain privileges via commands enclosed with escaped backticks (\`) i
23RISK
open ↗Exploit-DB✓ VexDay Proof
MyBulletinBoard (MyBB) 1.1.5 - 'CLIENT-IP' SQL Injection
PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions pre
60RISK
open ↗Exploit-DB✓ VexDay Proof
Rocks Clusters 4.1 - 'mount-loop' Local Privilege Escalation
Rocks Clusters 4.1 and earlier allows local users to gain privileges via commands enclosed with escaped backticks (\`) i
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sunbelt Kerio Personal Firewall 4.3.426 - CreateRemoteThread Denial of Service
kpf4ss.exe in Sunbelt Kerio Personal Firewall 4.3.x before 4.3.268 does not properly hook the CreateRemoteThread API fun
23RISK
open ↗Exploit-DB✓ VexDay Proof
MyBulletinBoard (MyBB) 1.1.5 - 'CLIENT-IP' SQL Injection
SQL injection vulnerability in the init function in class_session.php in MyBB (aka MyBulletinBoard) 1.1.5 allows remote
23RISK
open ↗Exploit-DB✓ VexDay Proof
Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RISK
open ↗Exploit-DB✓ VexDay Proof
MyBulletinBoard (MyBB) 1.1.5 - 'CLIENT-IP' SQL Injection
Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without r
60RISK
open ↗Exploit-DB✓ VexDay Proof
KDE Konqueror 3.5.x - ReplaceChild Denial of Service
KDE Konqueror 3.5.1 and earlier allows remote attackers to cause a denial of service (application crash) by calling the
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft PowerPoint 2003 - '.ppt' File Closure Memory Corruption
Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a c
28RISK
open ↗Exploit-DB✓ VexDay Proof
Subberz Lite - UserFunc Remote File Inclusion
PHP remote file inclusion vulnerability in user-func.php in Codeworks Gnomedia SubberZ[Lite] allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft PowerPoint 2003 - 'powerpnt.exe' Remote Overflow
Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to po
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft PowerPoint 2003 - 'mso.dll' '.PPT' Processing Code Execution
Unspecified vulnerability in mso.dll in Microsoft PowerPoint 2003 allows user-assisted attackers to execute arbitrary co
28RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.13 < 2.6.17.4 - 'sys_prctl()' Local Privilege Escalation (4)
The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a l
23RISK
open ↗Exploit-DB✓ VexDay Proof
FlatNuke 2.5.7 - 'index.php' Remote File Inclusion
The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the
23RISK
open ↗Exploit-DB✓ VexDay Proof
Dream4 Koobi Pro 5.6 - 'showtopic' SQL Injection
SQL injection vulnerability in the showtopic module in Koobi Pro CMS 5.6 allows remote attackers to execute arbitrary SQ
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.13 < 2.6.17.4 - 'sys_prctl()' Local Privilege Escalation (3)
The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a l
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.