Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,492GitHub PoC 14,286VulnCheck XDB 8,703Nuclei 4,314Metasploit 3,474✓ verified onlyrecentpopularrisk
24,455 exploits
Exploit-DB✓ VexDay Proof
AppServ Open Project 2.4.5 - Remote File Inclusion
Unspecified vulnerability in appserv/main.php in AppServ 2.4.5 allows remote attackers to include arbitrary files via th
23RISK
open ↗Exploit-DB✓ VexDay Proof
Magic News Plus 1.0.3 - Admin Pass Change
settings.php in Reamday Enterprises Magic News Plus 1.0.3 allows remote attackers to change the administrator password v
23RISK
open ↗Exploit-DB✓ VexDay Proof
Venom Board - 'Post.php3' Multiple SQL Injections
SQL injection vulnerability in add_post.php3 in Venom Board 1.22 allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Excel 95 < 2004 - Malformed Graphic File Code Execution
Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allo
35RISK
open ↗Exploit-DB✓ VexDay Proof
Sudo 1.6.x - Environment Variable Handling Security Bypass (1)
Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) PERLLIB, (2) PERL5LIB, and (3) PERL5OPT e
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Nuke News Submission Story - Text Field Cross-Site Scripting
Multiple cross-site scripting vulnerabilities in the (1) Pool or (2) News Modules in Php-Nuke allow remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Graphics Rendering Engine Multiple Memory Corruption Vulnerabilities
Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and cause a denial of servic
35RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 7.7 EV Search Module - SQL Injection
SQL injection vulnerability in the search module (modules/Search/index.php) of PHPNuke EV 7.7 -R1 allows remote attacker
23RISK
open ↗Exploit-DB✓ VexDay Proof
Dual DHCP DNS Server 1.0 - DHCP Options Remote Buffer Overflow
Buffer overflow in Dual DHCP DNS Server 1.0 allows remote attackers to cause a denial of service (application crash) and
23RISK
open ↗Exploit-DB✓ VexDay Proof
BlueCoat WinProxy 6.0 R1c - 'Host' Remote Stack Overflow (SEH)
Buffer overflow in BlueCoat (a) WinProxy before 6.1a and (b) the web console access functionality in ProxyAV before 2.4.
50RISK
open ↗Exploit-DB✓ VexDay Proof
BlueCoat WinProxy 6.0 R1c - GET Denial of Service
The listening daemon in Blue Coat Systems Inc. WinProxy before 6.1a allows remote attackers to cause a denial of service
23RISK
open ↗Exploit-DB✓ VexDay Proof
OnePlug CMS - '/products/details.asp?Product_ID' SQL Injection
Multiple SQL injection vulnerabilities in OnePlug Solutions OnePlug CMS allow remote attackers to execute arbitrary SQL
23RISK
open ↗Exploit-DB✓ VexDay Proof
TinyPHPForum 3.6 - Multiple Directory Traversal Vulnerabilities
TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web roo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Foro Domus 2.10 - Multiple Input Validation Vulnerabilities
Cross-site scripting (XSS) vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to inject arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
OnePlug CMS - '/press/details.asp?Press_Release_ID' SQL Injection
Multiple SQL injection vulnerabilities in OnePlug Solutions OnePlug CMS allow remote attackers to execute arbitrary SQL
23RISK
open ↗Exploit-DB✓ VexDay Proof
OnePlug CMS - '/services/details.asp?Service_ID' SQL Injection
Multiple SQL injection vulnerabilities in OnePlug Solutions OnePlug CMS allow remote attackers to execute arbitrary SQL
23RISK
open ↗Exploit-DB✓ VexDay Proof
TheWebForum 1.2.1 - Multiple Input Validation Vulnerabilities
SQL injection vulnerability in login.php in TheWebForum (twf) 1.2.1 allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 Kernel - APC Data-Free Local Escalation (MS05-055)
The thread termination routine in the kernel for Windows NT 4.0 and 2000 (NTOSKRNL.EXE) allows local users to modify ker
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP 4.4.0 - 'mysql_connect function' Local Buffer Overflow
Stack-based buffer overflow in the create_named_pipe function in libmysql.c in PHP 4.3.10 and 4.4.x before 4.4.3 for Win
23RISK
open ↗Exploit-DB✓ VexDay Proof
Hylafax 4.1/4.2 (Multiple Scripts) - Remote Command Execution
Multiple eval injection vulnerabilities in HylaFAX 4.2.3 and earlier allow remote attackers to execute arbitrary command
28RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - SET_MEMPOLICY Local Denial of Service
Linux kernel before 2.6.15 allows local users to cause a denial of service (panic) via a set_mempolicy call with a 0 bit
23RISK
open ↗Exploit-DB✓ VexDay Proof
WinRAR 3.30 - 'Filename' Local Buffer Overflow (1)
Buffer overflow in WinRAR 3.50 and earlier allows local users to execute arbitrary code via a long command-line argument
23RISK
open ↗Exploit-DB✓ VexDay Proof
WinRAR 3.30 - 'Filename' Local Buffer Overflow (2)
Buffer overflow in WinRAR 3.50 and earlier allows local users to execute arbitrary code via a long command-line argument
23RISK
open ↗Exploit-DB✓ VexDay Proof
EFileGo 3.0 - Multiple Input Validation Vulnerabilities
Directory traversal vulnerability in eFileGo 3.01 allows remote attackers to execute arbitrary code, read arbitrary file
23RISK
open ↗Exploit-DB✓ VexDay Proof
SCO OpenServer 5.0.7 - 'termsh' Local Privilege Escalation
Buffer overflow in termsh on SCO OpenServer 5.0.7 allows remote attackers to execute arbitrary code via a long -o comman
23RISK
open ↗Exploit-DB✓ VexDay Proof
ScozNet ScozBook 1.1 - 'AdminName' SQL Injection
SQL injection vulnerability in auth.php in ScozNet ScozBook BETA 1.1 allows remote attackers to execute arbitrary SQL co
23RISK
open ↗Exploit-DB✓ VexDay Proof
DiscusWare Discus 3.10 - Error Message Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in DiscusWare Discus Freeware 3.10.5 and Professional 3.10.4 allows remote atta
23RISK
open ↗Exploit-DB✓ VexDay Proof
aMSN - Remote Denial of Service
aMSN (aka Alvaro's Messenger) allows remote attackers to cause a denial of service (client hang and termination of clien
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM AIX 5.3 - 'GetShell' / 'GetCommand' File Disclosure
Multiple directory traversal vulnerabilities in AIX 5.3 ML03 allow local users to determine the existence of files and r
23RISK
open ↗Exploit-DB✓ VexDay Proof
Chimera Web Portal 0.2 - 'linkcategory.php?id' SQL Injection
SQL injection vulnerability in linkcategory.php in Phanatic Softwares Chimera Web Portal System 0.2 allows remote attack
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.