Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,492GitHub PoC 14,286VulnCheck XDB 8,703Nuclei 4,314Metasploit 3,474✓ verified onlyrecentpopularrisk
24,455 exploits
Exploit-DB✓ VexDay Proof
Sun ONE Directory Server 5.2 - Remote Denial of Service
LDAP service in Sun Java System Directory Server 5.2, running on Linux and possibly other platforms, allows remote attac
23RISK
open ↗Exploit-DB✓ VexDay Proof
QNX Neutrino 6.2.1 - 'phfont' Race Condition Privilege Escalation
Race condition in phfont in QNX Neutrino RTOS 6.2.1 allows local users to execute arbitrary code via unspecified manipul
23RISK
open ↗Exploit-DB✓ VexDay Proof
CPAINT 1.3/2.0.2 - 'TYPE.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in cpaint2.inc.php in the CPAINT library before 2.0.3, as used in multiple scri
23RISK
open ↗Exploit-DB✓ VexDay Proof
CPGNuke Dragonfly 9.0.6.1 - Remote Command Execution
Multiple directory traversal vulnerabilities in install.php in CPG-Nuke Dragonfly CMS (aka CPG Dragonfly CMS) 9.0.6.1 al
23RISK
open ↗Exploit-DB✓ VexDay Proof
QNX RTOS 6.3.0 - Insecure 'rc.local' Permissions System Crash / Privilege Escalation
QNX Neutrino RTOS 6.3.0 ships /etc/rc.d/rc.local with world-writable permissions, which allows local users to modify the
23RISK
open ↗Exploit-DB✓ VexDay Proof
QNX 6.2/6.3 - Multiple Privilege Escalation / Denial of Service Vulnerabilities
Untrusted search path vulnerability in the crttrap command in QNX Neutrino RTOS 6.2.1 allows local users to load arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 7.0 Beta 2 - 'urlmon.dll' Denial of Service
urlmon.dll in Microsoft Internet Explorer 7.0 beta 2 (aka 7.0.5296.0) allows remote attackers to cause a denial of servi
28RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox 1.5 (Linux) - 'location.QueryInterface()' Code Execution (Metasploit)
Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attac
60RISK
open ↗Exploit-DB✓ VexDay Proof
GA's Forum Light - 'Archive.asp' SQL Injection
Multiple SQL injection vulnerabilities in archive.asp in GA's Forum Light allow remote attackers to execute arbitrary SQ
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sony/Ericsson Bluetooth - Reset Display Denial of Service
Buffer overflow in Sony Ericsson K600i, V600i, W800i, and T68i cell phone allows remote attackers to cause a denial of s
23RISK
open ↗Exploit-DB✓ VexDay Proof
MyQuiz 1.01 - 'PATH_INFO' Arbitrary Command Execution
myquiz.pl in Dale Ray MyQuiz 1.01 allows remote attackers to execute arbitrary commands via shell metacharacters in the
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft HTML Help Workshop - '.hhp' Local Buffer Overflow (1)
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft HTML Help Workshop - '.hhp' Local Buffer Overflow (1)
Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary
50RISK
open ↗Exploit-DB✓ VexDay Proof
Clever Copy 3.0 - Admin Auth Details / SQL Injection
SQL injection vulnerability in mailarticle.php in Clever Copy 3.0 and earlier allows remote attackers to execute arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Tivoli Access Manager Plugin - Directory Traversal
Directory traversal vulnerability in pkmslogout in Tivoli Web Server Plug-in 5.1.0.10 in Tivoli Access Manager (TAM) 5.1
23RISK
open ↗Exploit-DB✓ VexDay Proof
LoudBlog 0.4 - Remote File Inclusion
PHP remote file include vulnerability in inc/backend_settings.php in Loudblog 0.4 and earlier allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
SoftMaker Shop - Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in resultat.asp in SoftMaker Shop allows remote attackers to inject arbitrary w
23RISK
open ↗Exploit-DB✓ VexDay Proof
CyberShop Ultimate E-Commerce - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in default.asp in CyberShop Ultimate E-commerce allow remote attacke
23RISK
open ↗Exploit-DB✓ VexDay Proof
Arescom NetDSL-1000 - 'TelnetD' Remote Denial of Service
The telnet port in Arescom NetDSL 1000 router allows remote attackers to cause a denial of service via a series of conne
23RISK
open ↗Exploit-DB✓ VexDay Proof
SZUserMgnt 1.4 - 'Username' SQL Injection
SQL injection vulnerability in SZUserMgnt.class.php in SZUserMgnt 1.4 allows remote attackers to execute arbitrary SQL c
23RISK
open ↗Exploit-DB✓ VexDay Proof
Fcron 3.0 - Convert-FCronTab Local Buffer Overflow
The convert-fcrontab program in fcron 3.0.0 might allow local users to gain privileges via a long command-line argument,
23RISK
open ↗Exploit-DB✓ VexDay Proof
SoftiaCom wMailServer 1.0 - SMTP Remote Buffer Overflow (Metasploit)
SoftiaCom wMailServer 1.0 and 2.0 allows remote attackers to cause a denial of service (application crash) via a large T
50RISK
open ↗Exploit-DB✓ VexDay Proof
SPIP 1.8/1.9 - 'index.php3' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier al
23RISK
open ↗Exploit-DB✓ VexDay Proof
Farsinews 2.1 - 'Loginout.php' Remote File Inclusion
PHP remote file inclusion vulnerability in loginout.php in FarsiNews 2.1 Beta 2 and earlier, with register_globals enabl
23RISK
open ↗Exploit-DB✓ VexDay Proof
Invision Power Board Dragoran Portal Mod 1.3 - SQL Injection
SQL injection vulnerability index.php in Dragoran Portal module 1.3 for Invision Power Board (IPB) allows remote attacke
23RISK
open ↗Exploit-DB✓ VexDay Proof
Winamp 5.12 - '.pls' Remote Buffer Overflow (Metasploit)
Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with
60RISK
open ↗Exploit-DB✓ VexDay Proof
MyBB 1.0/1.1 - 'index.php' Referrer Cookie SQL Injection
SQL injection vulnerability in index.php in MyBB (MyBulletinBoard) before 1.04 allows remote attackers to execute arbitr
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cerberus Helpdesk 2.7 - 'Clients.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in clients.php in Cerberus Helpdesk, possibly 2.7, allow remote atta
23RISK
open ↗Exploit-DB✓ VexDay Proof
KarjaSoft Sami FTP Server 2.0.1 - Remote Buffer Overflow (cpp)
Stack-based buffer overflow in Sami FTP Server 2.0.1 allows remote attackers to execute arbitrary code via a long USER c
60RISK
open ↗Exploit-DB✓ VexDay Proof
PmWiki 2.1 - Multiple Input Validation Vulnerabilities
pmwiki.php in PmWiki 2.1 beta 20, with register_globals enabled, allows remote attackers to bypass protection mechanisms
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.