Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,523GitHub PoC 14,289VulnCheck XDB 8,710Nuclei 4,319Metasploit 3,476✓ verified onlyrecentpopularrisk
24,455 exploits
Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - Sysctl Unregistration Local Denial of Service
The sysctl functionality (sysctl.c) in Linux kernel before 2.6.14.1 allows local users to cause a denial of service (ker
23RISK
open ↗Exploit-DB✓ VexDay Proof
SAP Web Application Server 6.x/7.0 - Error Page Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in SAP Web Application Server (WAS) 6.10 allows remote attackers to inject arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
SAP Web Application Server 6.x/7.0 - Open Redirection
frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log use
43RISK
open ↗Exploit-DB✓ VexDay Proof
SAP Web Application Server 6.x/7.0 - Input Validation
SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary bytes into the HTTP res
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux chfn (SuSE 9.3/10) - Local Privilege Escalation
chfn in pwdutils 3.0.4 and earlier on SuSE Linux, and possibly other operating systems, does not properly check argument
23RISK
open ↗Exploit-DB✓ VexDay Proof
ATutor 1.5.1pl2 - SQL Injection / Command Execution
registration.PHP in ATutor 1.5.1 pl2 allows remote attackers to execute arbitrary SQL commands via an e-mail address tha
23RISK
open ↗Exploit-DB✓ VexDay Proof
Asterisk 0.x/1.0/1.2 Voicemail - Unauthorized Access
Directory traversal vulnerability in vmail.cgi in Asterisk 1.0.9 through 1.2.0-beta1 allows remote attackers to access W
28RISK
open ↗Exploit-DB✓ VexDay Proof
Zone Labs Zone Alarm 6.0 - Advance Program Control Bypass
Zone Labs (1) ZoneAlarm Pro 6.0, (2) ZoneAlarm Internet Security Suite 6.0, (3) ZoneAlarm Anti-Virus 6.0, (4) ZoneAlarm
28RISK
open ↗Exploit-DB✓ VexDay Proof
PHPFM - Arbitrary File Upload
Unrestricted file upload vulnerability in PHPFM before 0.2.3 allows remote authenticated users to execute arbitrary code
23RISK
open ↗Exploit-DB✓ VexDay Proof
Invision Power Board (IP.Board) 2.1 - 'admin.php' Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in Invision Power Board 2.1 allows remote attackers to inject arbitrary web scr
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHPList Mailing List Manager 2.x - '/admin/admin.php?id' SQL Injection
Multiple SQL injection vulnerabilities in PHPlist 2.10.1 and earlier allow authenticated remote attackers with administr
23RISK
open ↗Exploit-DB✓ VexDay Proof
ToendaCMS 0.6.1 - 'admin.php' Directory Traversal
Directory traversal vulnerability in admin.php in toendaCMS before 0.6.2 allows remote attackers to access arbitrary fil
23RISK
open ↗Exploit-DB✓ VexDay Proof
XMB Forum 1.9.3 - 'u2u.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in u2u.php in XMB 1.9.3 allows remote attackers to inject arbitrary web script
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHPList Mailing List Manager 2.x - '/admin/configure.php?id' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in PHPlist 2.10.1 and earlier allow remote attackers to inject arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHPList Mailing List Manager 2.x - '/admin/eventlog.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in PHPlist 2.10.1 and earlier allow remote attackers to inject arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
F-Secure Internet GateKeeper for Linux < 2.15.484 / Gateway < 2.16 - Local Privilege Escalation
Patrice Freydiere ImgSvr (aka ADA Image Server) allows remote attackers to cause a denial of service (daemon crash) via
23RISK
open ↗Exploit-DB✓ VexDay Proof
OSTE 1.0 - Remote File Inclusion
PHP file inclusion vulnerability in index.php in OSTE 1.0 allows remote attackers to execute arbitrary code via the (1)
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHPList Mailing List Manager 2.x - '/admin/users.php?find' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in PHPlist 2.10.1 and earlier allow remote attackers to inject arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
F-Secure Internet GateKeeper for Linux < 2.15.484 / Gateway < 2.16 - Local Privilege Escalation
suid.cgi scripts in F-Secure (1) Internet Gatekeeper for Linux before 2.15.484 and (2) Anti-Virus Linux Gateway before 2
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHPList Mailing List Manager 2.x - '/admin/editattributes.php?id' SQL Injection
Multiple SQL injection vulnerabilities in PHPlist 2.10.1 and earlier allow authenticated remote attackers with administr
23RISK
open ↗Exploit-DB✓ VexDay Proof
ibProArcade 2.x - module 'vBulletin/IPB' SQL Injection
SQL injection vulnerability in index.php of the report module in ibProArcade 2.5.2 and earlier allows remote attackers t
23RISK
open ↗Exploit-DB✓ VexDay Proof
Widget Property 1.1.19 - 'Property.php' SQL Injection
SQL injection vulnerability in Widget Property 1.1.19 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Exploit-DB✓ VexDay Proof
linux-ftpd-ssl 0.17 - 'MKD'/'CWD' Remote Code Execution
Buffer overflow in the SSL-ready version of linux-ftpd (linux-ftpd-ssl) 0.17 allows remote attackers to execute arbitrar
28RISK
open ↗Exploit-DB✓ VexDay Proof
gpsdrive 2.09 (x86) - 'friendsd2' Remote Format String
Format string vulnerability in friendsd2 in GpsDrive allows remote attackers to execute arbitrary code via the dir (dire
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ocean12 ASP Calendar Manager 1.0 - Authentication Bypass
Ocean12 Calendar Manager Pro 1.01 allows remote attackers to bypass authentication and obtain sensitive information via
23RISK
open ↗Exploit-DB✓ VexDay Proof
gpsdrive 2.09 (PPC) - 'friendsd2' Remote Format String
Format string vulnerability in friendsd2 in GpsDrive allows remote attackers to execute arbitrary code via the dir (dire
23RISK
open ↗Exploit-DB✓ VexDay Proof
JPortal Web Portal 2.2.1/2.3.1 - 'news.php' SQL Injection
Multiple SQL injection vulnerabilities in JPortal allow remote attackers to execute arbitrary SQL commands via (1) banne
23RISK
open ↗Exploit-DB✓ VexDay Proof
JPortal Web Portal 2.2.1/2.3.1 - 'comment.php' SQL Injection
Multiple SQL injection vulnerabilities in JPortal allow remote attackers to execute arbitrary SQL commands via (1) banne
23RISK
open ↗Exploit-DB✓ VexDay Proof
WzdFTPD 0.5.4 - 'SITE' Remote Command Execution (Metasploit)
wzdftpd 0.5.4 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the SITE comma
45RISK
open ↗Exploit-DB✓ VexDay Proof
IPSwitch WhatsUp Small Business 2004 Report Service - Directory Traversal
Directory traversal vulnerability in Ipswitch WhatsUp Small Business 2004 allows remote attackers to read arbitrary file
35RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.