Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,429GitHub PoC 14,270VulnCheck XDB 8,693Nuclei 4,299Metasploit 3,474✓ verified onlyrecentpopularrisk
24,455 exploits
Exploit-DB✓ VexDay Proof
WinSCP 3.8.1 - URI Handler Arbitrary File Access
Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or download arbitrary files
23RISK
open ↗Exploit-DB✓ VexDay Proof
Five Star Review Script - 'index2.php?sort' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in 5 Star Review allow remote attackers to inject arbitrary web scri
23RISK
open ↗Exploit-DB✓ VexDay Proof
SixCMS 6.0 - 'list.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in list.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote
23RISK
open ↗Exploit-DB✓ VexDay Proof
Content-Builder (CMS) 0.7.5 - Multiple Include Vulnerabilities
Multiple PHP remote file inclusion vulnerabilities in Content*Builder 0.7.5 allow remote attackers to execute arbitrary
28RISK
open ↗Exploit-DB✓ VexDay Proof
FlexWATCH Network Camera - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in FlexWATCH Network Camera 3.0 and earlier allows remote attacker
23RISK
open ↗Exploit-DB✓ VexDay Proof
KAPhotoservice 7.5 - 'album.asp?cat' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice 7.5 and earlier allow remote attackers to inject a
23RISK
open ↗Exploit-DB✓ VexDay Proof
0verkill 0.16 - ASCII-ART Game Remote Integer Overflow Crash (PoC)
Integer overflow in the recv_packet function in 0verkill 0.16 allows remote attackers to cause a denial of service (daem
23RISK
open ↗Exploit-DB✓ VexDay Proof
Baby Katie Media VSReal and VScal 1.0 - 'index.php?lid' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Baby Katie Media (a) very Simple Car Lister (vSCAL) 1.0 and (b) v
23RISK
open ↗Exploit-DB✓ VexDay Proof
KAPhotoservice 7.5 - 'albums.asp?albumid' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice 7.5 and earlier allow remote attackers to inject a
23RISK
open ↗Exploit-DB✓ VexDay Proof
KAPhotoservice 7.5 - 'edtalbum.asp' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice 7.5 and earlier allow remote attackers to inject a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Baby Katie Media VSReal and VScal 1.0 - 'myslideshow.php?title' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Baby Katie Media (a) very Simple Car Lister (vSCAL) 1.0 and (b) v
23RISK
open ↗Exploit-DB✓ VexDay Proof
FreeType - '.TTF' File Remote Denial of Service
ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file tha
28RISK
open ↗Exploit-DB✓ VexDay Proof
CMS-Bandits 2.5 - 'spaw_root' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in CMS-Bandits 2.5 and earlier, when register_globals is enabled, all
23RISK
open ↗Exploit-DB✓ VexDay Proof
FreeType - '.TTF' File Remote Buffer Overflow
Integer underflow in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a font file wi
28RISK
open ↗Exploit-DB✓ VexDay Proof
D-Link DWL Series Access-Point 2.10na - Config Disclosure
The web server for D-Link Wireless Access-Point (DWL-2100ap) firmware 2.10na and earlier allows remote attackers to obta
23RISK
open ↗Exploit-DB✓ VexDay Proof
MiraksGalerie 2.62 - 'galimage.lib.php?listconfigfile[0]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in MiraksGalerie 2.62 allow remote attackers to execute arbitrary PHP
23RISK
open ↗Exploit-DB✓ VexDay Proof
Open Business Management 1.0.3 pl1 - 'publication_index.php?tf_lang' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers t
23RISK
open ↗Exploit-DB✓ VexDay Proof
Calendar Express 2.2 - 'month.php' SQL Injection
Multiple SQL injection vulnerabilities in month.php in PHP Lite Calendar Express 2.2 allow remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Open Business Management 1.0.3 pl1 - 'company_index.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers t
23RISK
open ↗Exploit-DB✓ VexDay Proof
Open Business Management 1.0.3 pl1 - 'user_index.php?tf_lastname' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers t
23RISK
open ↗Exploit-DB✓ VexDay Proof
Open Business Management 1.0.3 pl1 - 'list_index.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers t
23RISK
open ↗Exploit-DB✓ VexDay Proof
Open Business Management 1.0.3 pl1 - 'group_index.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers t
23RISK
open ↗Exploit-DB✓ VexDay Proof
QBik WinGate WWW Proxy Server 6.1.1.1077 - 'POST' Remote Buffer Overflow
Stack-based buffer overflow in the WWW Proxy Server of Qbik WinGate 6.1.1.1077 allows remote attackers to cause a denial
60RISK
open ↗Exploit-DB✓ VexDay Proof
MiraksGalerie 2.62 - 'galsecurity.lib.php?listconfigfile[0]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in MiraksGalerie 2.62 allow remote attackers to execute arbitrary PHP
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.5/6.0/7.0 - JavaScript Key Filtering
Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox 1.x - JavaScript Key Filtering
Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1
23RISK
open ↗Exploit-DB✓ VexDay Proof
GD Graphics Library 2.0.33 - Remote Denial of Service
The LZW decoding in the gdImageCreateFromGifPtr function in the Thomas Boutell graphics draw (GD) library (aka libgd) 2.
28RISK
open ↗Exploit-DB✓ VexDay Proof
SpamAssassin spamd 3.1.3 - Command Injection (Metasploit)
SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute a
60RISK
open ↗Exploit-DB✓ VexDay Proof
GANTTy 1.0.3 - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in GANTTy 1.0.3 allows remote attackers to inject arbitrary HTML a
23RISK
open ↗Exploit-DB✓ VexDay Proof
myNewsletter 1.1.2 - 'adminLogin.asp' Authentication Bypass
Multiple SQL injection vulnerabilities in myNewsletter 1.1.2 and earlier allow remote attackers to execute arbitrary SQL
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.