Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,523GitHub PoC 14,289VulnCheck XDB 8,710Nuclei 4,319Metasploit 3,476✓ verified onlyrecentpopularrisk
24,455 exploits
Exploit-DB✓ VexDay Proof
Nuked-klaN 1.7 Links Module - 'link_id' SQL Injection
Multiple SQL injection vulnerabilities in Nuked Klan 1.7 allow remote attackers to execute arbitrary SQL commands via th
23RISK
open ↗Exploit-DB✓ VexDay Proof
FlatNuke 2.5.x - 'index.php' Multiple Remote File Inclusions
Directory traversal vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to read arbitrary files via ".
23RISK
open ↗Exploit-DB✓ VexDay Proof
Zomplog 3.3/3.4 - 'detail.php' HTML Injection
Multiple cross-site scripting (XSS) vulnerabilities in Zomplog 3.4 allow remote attackers to inject arbitrary web script
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Plug-and-Play - 'Umpnpmgr.dll' Denial of Service (MS05-047) (1)
Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1
50RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - IPv6 Local Denial of Service
The udp_v6_get_port function in udp.c in Linux 2.6 before 2.6.14-rc5, when running IPv6, allows local users to cause a d
23RISK
open ↗Exploit-DB✓ VexDay Proof
Chipmunk Forum - 'newtopic.php?forumID' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Forum script allow remote attackers to inject arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
Chipmunk Forum - 'quote.php?forumID' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Forum script allow remote attackers to inject arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
XMail 1.21 - '-t' Command Line Option Local Buffer Overflow / Local Privilege Escalation
Stack-based buffer overflow in sendmail in XMail before 1.22 allows remote attackers to execute arbitrary code via a lon
28RISK
open ↗Exploit-DB✓ VexDay Proof
Ethereal 0.9.1 < 0.10.12 SLIMP3 - Remote Buffer Overflow (PoC)
Multiple buffer overflows in Ethereal 0.10.12 and earlier might allow remote attackers to execute arbitrary code via unk
28RISK
open ↗Exploit-DB✓ VexDay Proof
Veritas NetBackup 6.0 (Linux) - 'bpjava-msvc' Remote Command Execution
Format string vulnerability in the Java user interface service (bpjava-msvc) daemon for VERITAS NetBackup Data and Busin
35RISK
open ↗Exploit-DB✓ VexDay Proof
Veritas NetBackup 6.0 (OSX) - 'bpjava-msvc' Remote Command Execution
Format string vulnerability in the Java user interface service (bpjava-msvc) daemon for VERITAS NetBackup Data and Busin
35RISK
open ↗Exploit-DB✓ VexDay Proof
Chipmunk Forum - 'recommend.php?ID' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk Topsites script allows remote attackers to inject
23RISK
open ↗Exploit-DB✓ VexDay Proof
Veritas NetBackup 6.0 (Windows x86) - 'bpjava-msvc' Remote Command Execution
Format string vulnerability in the Java user interface service (bpjava-msvc) daemon for VERITAS NetBackup Data and Busin
35RISK
open ↗Exploit-DB✓ VexDay Proof
Chipmunk Directory - 'recommend.php?entryID' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk Directory script allows remote attackers to inject
23RISK
open ↗Exploit-DB✓ VexDay Proof
HP-UX 11.11 - lpd Remote Command Execution (Metasploit)
The LPD service in HP-UX 10.20 11.11 (11i) and earlier allows remote attackers to execute arbitrary code via shell metac
28RISK
open ↗Exploit-DB✓ VexDay Proof
Xerver 4.17 Server - URI Null Character Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Xerver 4.17 allows remote attackers to inject arbitrary web script or HTML a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Xerver 4.17 - Single Dot File Request Source Disclosure
Xerver 4.17 allows remote attackers to (1) obtain source code of scripts via a request with a trailing "." (dot) or (2)
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.4.30/2.6.11.5 - BlueTooth 'bluez_sock_create' Local Privilege Escalation
The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5
23RISK
open ↗Exploit-DB✓ VexDay Proof
Xerver 4.17 - Forced Directory Listing
Xerver 4.17 allows remote attackers to (1) obtain source code of scripts via a request with a trailing "." (dot) or (2)
23RISK
open ↗Exploit-DB✓ VexDay Proof
MySource 2.14 - 'edit_table_props.php?bgcolor' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web sc
23RISK
open ↗Exploit-DB✓ VexDay Proof
MySource 2.14 - 'init_mysource.php?INCLUDE_PATH' Remote File Inclusion
Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and
23RISK
open ↗Exploit-DB✓ VexDay Proof
Snort 2.4.0 < 2.4.3 - Back Orifice Pre-Preprocessor Remote (Metasploit)
Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to exec
60RISK
open ↗Exploit-DB✓ VexDay Proof
MySource 2.14 - 'new_upgrade_functions.php' Multiple Remote File Inclusions
Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and
23RISK
open ↗Exploit-DB✓ VexDay Proof
MySource 2.14 - 'Span.php?PEAR_PATH' Remote File Inclusion
Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and
23RISK
open ↗Exploit-DB✓ VexDay Proof
NetFlow Analyzer 4 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.jsp in ManageEngine Netflow Analyzer 4.0.2 allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
MySource 2.14 - 'header.php?bgcolor' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web sc
23RISK
open ↗Exploit-DB✓ VexDay Proof
MySource 2.14 - 'mime.php?PEAR_PATH' Remote File Inclusion
Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and
23RISK
open ↗Exploit-DB✓ VexDay Proof
MySource 2.14 - 'mimeDecode.php?PEAR_PATH' Remote File Inclusion
Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and
23RISK
open ↗Exploit-DB✓ VexDay Proof
MySource 2.14 - 'Socket.php?PEAR_PATH' Remote File Inclusion
Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and
23RISK
open ↗Exploit-DB✓ VexDay Proof
MySource 2.14 - 'Request.php?PEAR_PATH' Remote File Inclusion
Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.