Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,492GitHub PoC 14,286VulnCheck XDB 8,703Nuclei 4,314Metasploit 3,474✓ verified onlyrecentpopularrisk
24,455 exploits
Exploit-DB✓ VexDay Proof
Half-Life CSTRIKE Server 1.6 (Non Steam) - Denial of Service
The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.6 and earlier allows remot
23RISK
open ↗Exploit-DB✓ VexDay Proof
HiveMail 1.2.2/1.3 - 'index.php' $_SERVER['PHP_SELF'] Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to inject arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
LinPHA 0.9.x/1.0 - 'forth_stage_install.php' Local File Inclusion
Directory traversal vulnerability in LinPHA 1.0 allows remote attackers to include arbitrary files via .. (dot dot) sequ
23RISK
open ↗Exploit-DB✓ VexDay Proof
LinPHA 0.9.x/1.0 - 'install.php' Local File Inclusion
Directory traversal vulnerability in LinPHA 1.0 allows remote attackers to include arbitrary files via .. (dot dot) sequ
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft HTML Help Workshop - '.hhp' Local Buffer Overflow (2)
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included
60RISK
open ↗Exploit-DB✓ VexDay Proof
ImageVue 0.16.1 - 'dir.php' Folder Permission Disclosure
imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which return
23RISK
open ↗Exploit-DB✓ VexDay Proof
ImageVue 0.16.1 - 'upload.php' Unrestricted Arbitrary File Upload
admin/upload.php in imageVue 16.1 allows remote attackers to upload arbitrary files to certain allowed folders via .. (d
23RISK
open ↗Exploit-DB✓ VexDay Proof
HiveMail 1.2.2/1.3 - 'addressbook.update.php?contactgroupid' Arbitrary PHP Command Execution
Multiple eval injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary PHP code
23RISK
open ↗Exploit-DB✓ VexDay Proof
DocMGR 0.54.2 - 'file_exists' Remote Command Execution
process.php in DocMGR 0.54.2 does not initialize the $siteModInfo variable when a direct request is made, which allows r
23RISK
open ↗Exploit-DB✓ VexDay Proof
ImageVue 0.16.1 - 'readfolder.php?path' Arbitrary Directory Listing
readfolder.php in imageVue 16.1 allows remote attackers to list directories via modified path and ext parameters.
23RISK
open ↗Exploit-DB✓ VexDay Proof
ImageVue 0.16.1 - 'index.php?bgcol' Cross-Site Scripting
Unspecified vulnerability in index.php in imageVue 16.1 has unknown impact, probably a cross-site scripting (XSS) vulner
23RISK
open ↗Exploit-DB✓ VexDay Proof
LinPHA 0.9.x/1.0 - 'sec_stage_install.php' Local File Inclusion
Directory traversal vulnerability in LinPHA 1.0 allows remote attackers to include arbitrary files via .. (dot dot) sequ
23RISK
open ↗Exploit-DB✓ VexDay Proof
Half-Life CSTRIKE Server 1.6 (Non Steam) - Denial of Service
The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.1.1.0 and earlier allows r
23RISK
open ↗Exploit-DB✓ VexDay Proof
HiveMail 1.2.2/1.3 - 'folders.update.php?folderid' Arbitrary PHP Command Execution
Multiple eval injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary PHP code
23RISK
open ↗Exploit-DB✓ VexDay Proof
OpenVMPSd 1.3 - Remote Format String
Format string vulnerability in the vmps_log function in OpenVMPS (VLAN Management Policy Server) 1.3 allows remote attac
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft HTML Help Workshop - '.hhp' Denial of Service
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included
60RISK
open ↗Exploit-DB✓ VexDay Proof
Farsinews 2.1/2.5 - 'show_archives.php?template' Traversal Arbitrary File Access
Multiple directory traversal vulnerabilities in FarsiNews 2.5 and earlier allows remote attackers to (1) read arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Lotus Domino 6.x/7.0 - iNotes JavaScript: Filter Bypass
Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers t
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Lotus Domino 6.x/7.0 iNotes - Email Subject Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers t
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft HTML Help Workshop - '.hhp' Denial of Service
Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary
50RISK
open ↗Exploit-DB✓ VexDay Proof
Power Daemon 2.0.2 - 'WHATIDO' Remote Format String
Format string vulnerability in powerd.c in Power Daemon (powerd) 2.0.2 and earlier allows remote attackers to execute ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
RunCMS 1.2 - 'class.forumposts.php' Remote File Inclusion
Multiple PHP remote file include vulnerabilities in RunCMS 1.2 and earlier, with register_globals and allow_url_fopen en
23RISK
open ↗Exploit-DB✓ VexDay Proof
FCKEditor 2.0 < 2.2 - 'FileManager connector.php' Arbitrary File Upload
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows
23RISK
open ↗Exploit-DB✓ VexDay Proof
PwsPHP 1.2.3 - SQL Injection
SQL injection vulnerability in profil.php in PwsPHP 1.2.3, and possibly earlier versions, allows remote attackers to exe
23RISK
open ↗Exploit-DB✓ VexDay Proof
RunCMS 1.2 - 'class.forumposts.php' Remote File Inclusion
Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPa
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox 1.5 (OSX) - 'location.QueryInterface()' Code Execution (Metasploit)
Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attac
60RISK
open ↗Exploit-DB✓ VexDay Proof
SPIP 1.8.2 - 'Spip_RSS.php' Remote Command Execution
Directory traversal vulnerability in Spip_RSS.PHP in SPIP 1.8.2g and earlier allows remote attackers to read or include
23RISK
open ↗Exploit-DB✓ VexDay Proof
SPIP 1.8.2g - Remote Command Execution
SQL injection vulnerability in spip_acces_doc.php3 in SPIP 1.8.2g and earlier allows remote attackers to execute arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
vwdev - 'index.php' SQL Injection
SQL injection vulnerability in index.php in vwdev allows remote attackers to execute arbitrary SQL commands via the UID
23RISK
open ↗Exploit-DB✓ VexDay Proof
CPAINT 1.3/2.0.2 - 'TYPE.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in cpaint2.inc.php in the CPAINT library before 2.0.3, as used in multiple scri
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.