Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,523GitHub PoC 14,289VulnCheck XDB 8,710Nuclei 4,319Metasploit 3,476✓ verified onlyrecentpopularrisk
24,455 exploits
Exploit-DB✓ VexDay Proof
OTRS 2.0 - 'index.pl' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mambo 4.5.2 - Globals Overwrite / Remote Command Execution
globals.php in Mambo Site Server 4.0.14 and earlier, when register_globals is disabled, allows remote attackers to overw
23RISK
open ↗Exploit-DB✓ VexDay Proof
PmWiki 2.0.x - Search Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Search module in PmWiki up to 2.0.12 allows remote attackers to inject a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Virtual Hosting Control System 2.2/2.4 - Error Message Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in gui/errordocs/index.php in Virtual Hosting Control System (VHCS) 2.2.0 throu
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache Struts 1.2.7 - Error Response Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to
28RISK
open ↗Exploit-DB✓ VexDay Proof
PHP Download Manager 1.1.x - 'files.php' SQL Injection
SQL injection vulnerability in files.php in PHP Download Manager 1.1.3 and earlier allows remote attackers to execute ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHPPost 1.0 - 'mail.php?user' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Post (PHPp) 1.0 allow remote attackers to inject arbitrary we
23RISK
open ↗Exploit-DB✓ VexDay Proof
SimplePoll - 'results.php' SQL Injection
SQL injection vulnerability in results.php in SimplePoll allows remote attackers to execute arbitrary SQL commands via t
23RISK
open ↗Exploit-DB✓ VexDay Proof
Tru-Zone Nuke ET 3.x - Search Module SQL Injection
SQL injection vulnerability in the Search module in Tru-Zone Nuke ET 3.2, and possibly earlier versions, allows remote a
23RISK
open ↗Exploit-DB✓ VexDay Proof
APBoard - 'thread.php' SQL Injection
SQL injection vulnerability in thread.php in APBoard allows remote attackers to execute arbitrary SQL commands via the s
23RISK
open ↗Exploit-DB✓ VexDay Proof
FileZilla Server Terminal 0.9.4d - Buffer Overflow (PoC)
Buffer overflow in FileZilla Server Terminal 0.9.4d may allow remote attackers to cause a denial of service (terminal cr
50RISK
open ↗Exploit-DB✓ VexDay Proof
Advanced Poll 2.0.2/2.0.3 - 'popup.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in popup.php in Advanced Poll 2.0.3 and earlier allows remote attackers to inje
23RISK
open ↗Exploit-DB✓ VexDay Proof
Inkscape 0.41/0.42 - '.SVG' Image Buffer Overflow
Buffer overflow in the SVG importer (style.cpp) of inkscape 0.41 through 0.42.2 might allow remote attackers to execute
28RISK
open ↗Exploit-DB✓ VexDay Proof
PHPPost 1.0 - 'profile.php?user' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Post (PHPp) 1.0 allow remote attackers to inject arbitrary we
23RISK
open ↗Exploit-DB✓ VexDay Proof
MailEnable 1.54 Pro - Universal IMAPD W3C Logging Buffer Overflow (Metasploit)
Buffer overflow in the W3C logging for MailEnable Enterprise 1.1 and Professional 1.6 allows remote attackers to execute
50RISK
open ↗Exploit-DB✓ VexDay Proof
Google Search Appliance - proxystylesheet XSLT Java Code Execution (Metasploit)
The Saxon XSLT parser in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to
50RISK
open ↗Exploit-DB✓ VexDay Proof
Macromedia Flash Plugin 7.0.19.0 - 'action' Denial of Service
Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) al
28RISK
open ↗Exploit-DB✓ VexDay Proof
freeFTPd 1.0.8 - 'USER' Remote Buffer Overflow
Multiple buffer overflows in freeFTPd 1.0.8, without logging enabled, allow remote authenticated attackers to cause a de
28RISK
open ↗Exploit-DB✓ VexDay Proof
Revize CMS - 'Query_results.jsp' SQL Injection
SQL injection vulnerability in debug/query_results.jsp in Idetix Software Systems Revize CMS allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
VP-ASP Shopping Cart - 'Shopadmin.asp' HTML Injection
Cross-site scripting (XSS) vulnerability in shopadmin.asp in VP-ASP Shopping Cart 5.50 allows remote attackers to inject
23RISK
open ↗Exploit-DB✓ VexDay Proof
Litespeed 2.1.5 - 'ConfMgr.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admin/config/confMgr.php in LiteSpeed Web Server 2.1.5 allows remote attacke
23RISK
open ↗Exploit-DB✓ VexDay Proof
Revize CMS - 'Revize.XML' Information Disclosure
Idetix Software Systems Revize CMS stores conf/revize.xml under the web document root with insufficient access control,
23RISK
open ↗Exploit-DB✓ VexDay Proof
Revize CMS HTTPTranslatorServlet - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in HTTPTranslatorServlet in Idetix Software Systems Revize CMS allow
23RISK
open ↗Exploit-DB✓ VexDay Proof
Qualcomm WorldMail Server 3.0 - Directory Traversal
Directory traversal vulnerability in Qualcomm WorldMail IMAP Server allows remote attackers to read arbitrary email mess
23RISK
open ↗Exploit-DB✓ VexDay Proof
freeFTPd 1.0.8 - 'USER' Remote Buffer Overflow
Stack-based buffer overflow in freeFTPd before 1.0.9 with Logging enabled, allows remote attackers to cause a denial of
60RISK
open ↗Exploit-DB✓ VexDay Proof
PHPWebThings 1.4 - 'forum' SQL Injection
SQL injection vulnerability in forum.php in PHPWebThings 1.4 allows remote attackers to execute arbitrary SQL commands v
23RISK
open ↗Exploit-DB✓ VexDay Proof
FTGate4 Groupware Mail Server 4.1 - imapd Remote Buffer Overflow (PoC)
Multiple buffer overflows in the IMAP Groupware Mail server of Floosietek FTGate (FTGate4) 4.1 allow remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHPWebThings 1.4 - 'msg'/'forum' SQL Injection
Multiple "potential" SQL injection vulnerabilities in phpWebThings 1.4 Patched might allow remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 7.8 Search Module - SQL Injection
Multiple SQL injection vulnerabilities in the Search module in PHP-Nuke 7.8, and possibly other versions before 7.9 with
35RISK
open ↗Exploit-DB✓ VexDay Proof
PHPWebThings 1.4 - 'forum' SQL Injection
Multiple "potential" SQL injection vulnerabilities in phpWebThings 1.4 Patched might allow remote attackers to execute a
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.