Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,429GitHub PoC 14,270VulnCheck XDB 8,693Nuclei 4,299Metasploit 3,474✓ verified onlyrecentpopularrisk
24,455 exploits
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - HTML Tag Memory Corruption (MS06-013)
Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamicall
35RISK
open ↗Exploit-DB✓ VexDay Proof
Easy-Content Forums 1.0 - Multiple SQL Injection / Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerabilities in Easy-Content Forums 1.0 allow remote attackers to inject arbitrary web scr
23RISK
open ↗Exploit-DB✓ VexDay Proof
Plume CMS 1.0.3 - 'manager_path' Remote File Inclusion
PHP remote file inclusion vulnerability in prepend.php in Plume CMS 1.0.2, when register_globals is enabled, allows remo
23RISK
open ↗Exploit-DB✓ VexDay Proof
qjForum - 'member.asp' SQL Injection
SQL injection vulnerability in member.asp in qjForum allows remote attackers to execute arbitrary SQL commands via the u
23RISK
open ↗Exploit-DB✓ VexDay Proof
tiffsplit (libtiff 3.8.2) - Local Stack Buffer Overflow
Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute
28RISK
open ↗Exploit-DB✓ VexDay Proof
Plume CMS 1.0.3 - 'manager_path' Remote File Inclusion
PHP remote file inclusion vulnerability in manager/frontinc/prepend.php for Plume 1.0.3 allows remote attackers to execu
23RISK
open ↗Exploit-DB✓ VexDay Proof
Easy-Content Forums 1.0 - Multiple SQL Injection / Cross-Site Scripting Vulnerabilities
Multiple SQL injection vulnerabilities in Easy-Content Forums 1.0 allow remote attackers to execute arbitrary SQL comman
23RISK
open ↗Exploit-DB✓ VexDay Proof
Socketmail 2.2.6 - 'site_path' Remote File Inclusion
PHP remote file inclusion vulnerability in SocketMail Lite and Pro 2.2.6 and earlier, when register_globals and magic_qu
23RISK
open ↗Exploit-DB✓ VexDay Proof
Invision Power Board 2.0/2.1 - 'index.php?CK' SQL Injection
SQL injection vulnerability in lib/func_taskmanager.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 al
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Core 2.0.2 - 'cache' Remote Shell Injection
Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary c
28RISK
open ↗Exploit-DB✓ VexDay Proof
Dia 0.8x/0.9x - Filename Remote Format String
Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly
23RISK
open ↗Exploit-DB✓ VexDay Proof
PunkBuster < 1.229 - WebTool Service Remote Buffer Overflow (Denial of Service) (PoC)
Buffer overflow in the WebTool HTTP server component in (1) PunkBuster before 1.229, as used by multiple products includ
23RISK
open ↗Exploit-DB✓ VexDay Proof
Docebo 3.0.3 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow
23RISK
open ↗Exploit-DB✓ VexDay Proof
Nucleus CMS 3.22 - 'DIR_LIBS' Remote File Inclusion
PHP remote file inclusion vulnerability in nucleus/libs/PLUGINADMIN.php in Nucleus 3.22 and earlier allows remote attack
23RISK
open ↗Exploit-DB✓ VexDay Proof
AZ Photo Album Script Pro - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in AZ Photo Album Script Pro allows remote attackers to inject arb
23RISK
open ↗Exploit-DB✓ VexDay Proof
netPanzer 0.8 rev 952 - 'frameNum' Server Terminiation
The setFrame function in Lib/2D/Surface.hpp for NetPanzer 0.8 and earlier allows remote attackers to cause a denial of s
23RISK
open ↗Exploit-DB✓ VexDay Proof
Prodder 0.4 - Arbitrary Shell Command Execution
Prodder before 0.5, and perlpodder before 0.5, allows remote attackers to execute arbitrary code via shell metacharacter
28RISK
open ↗Exploit-DB✓ VexDay Proof
Cyrus IMAPD 2.3.2 - 'pop3d' Remote Buffer Overflow (1)
Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allow
50RISK
open ↗Exploit-DB✓ VexDay Proof
JemWeb DownloadControl 1.0 - 'DC.php' SQL Injection
Jemscripts DownloadControl 1.0 allows remote attackers to obtain sensitive information via an invalid dcid parameter to
23RISK
open ↗Exploit-DB✓ VexDay Proof
Artmedic NewsLetter 4.1 - 'Log.php' Remote Script Execution
artmedic newsletter 4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to modify
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpBazar 2.1.0 - Remote File Inclusion / Authentication Bypass
PHP remote file inclusion vulnerability in classified_right.php in phpBazar 2.1.0 and earlier allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpBazar 2.1.0 - Remote File Inclusion / Authentication Bypass
Admin/admin.php in phpBazar 2.1.0 and earlier allows remote attackers to bypass the authentication process and gain unau
23RISK
open ↗Exploit-DB✓ VexDay Proof
CodeAvalanche News 1.2 - 'default.asp' SQL Injection
SQL injection vulnerability in default.asp in CodeAvalanche News (CANews) 1.2 allows remote attackers to execute arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cosmoshop 8.10.78/8.11.106 - 'Lshop.cgi' SQL Injection
SQL injection vulnerability in lshop.cgi in Cosmoshop 8.11.106 and earlier allows remote attackers to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
ASPBB 0.5.2 - 'profile.asp?get' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in AspBB 0.5.2 allow remote attackers to inject arbitrary web script
23RISK
open ↗Exploit-DB✓ VexDay Proof
ASPBB 0.5.2 - 'default.asp?action' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in AspBB 0.5.2 allow remote attackers to inject arbitrary web script
23RISK
open ↗Exploit-DB✓ VexDay Proof
obotix IP Camera M1 1.9.4 .7/M10 2.0.5.2 - 'eventplayer?get_image_info_abspath' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Mobotix IP Network Cameras M1 1.9.4.7 and M10 2.0.5.2, and other
23RISK
open ↗Exploit-DB✓ VexDay Proof
BoastMachine 3.1 - 'admin.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in (1) index.php and (2) bmc/admin.php in BoastMachine (bMachine) 3.1 and earli
23RISK
open ↗Exploit-DB✓ VexDay Proof
Open Wiki 0.78 - 'ow.asp' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in ow.asp in OpenWiki 0.78 allows remote attackers to inject arbitrary web scri
23RISK
open ↗Exploit-DB✓ VexDay Proof
obotix IP Camera M1 1.9.4 .7/M10 2.0.5.2 - 'events.tar?source_ip' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Mobotix IP Network Cameras M1 1.9.4.7 and M10 2.0.5.2, and other
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.