Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,523GitHub PoC 14,289VulnCheck XDB 8,710Nuclei 4,319Metasploit 3,476✓ verified onlyrecentpopularrisk
24,455 exploits
Exploit-DB✓ VexDay Proof
Adobe Version Cue 1.0/1.0.1 (OSX) - '-lib' Local Privilege Escalation
VCNative for Adobe Version Cue 1.0 and 1.0.1, as used in Creative Suite 1.0 and 1.3, and when running on Mac OS X with V
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Fusion 4.0/5.0/6.0 - BBCode URL Tag Script Injection
Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
Land Down Under 700/701/800/801 - 'index.php?c' SQL Injection
Multiple SQL injection vulnerabilities in Land Down Under (LDU) 801 and earlier allow remote attackers to execute arbitr
23RISK
open ↗Exploit-DB✓ VexDay Proof
bfcommand & control server 1.22/2.0/2.14 manager - Multiple Vulnerabilities
BFCommand & Control Server Manager BFCC 1.22_A and earlier, and BFVCC 2.14_B and earlier, allows remote attackers to cau
23RISK
open ↗Exploit-DB✓ VexDay Proof
SqWebMail 5.0.4 - HTML Email IMG Tag Script Injection
Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 and possibly other versions allows remote attackers to injec
23RISK
open ↗Exploit-DB✓ VexDay Proof
Land Down Under 700/701/800/801 - 'events.php?c' SQL Injection
Multiple SQL injection vulnerabilities in Land Down Under (LDU) 801 and earlier allow remote attackers to execute arbitr
23RISK
open ↗Exploit-DB✓ VexDay Proof
Land Down Under 700/701/800/801 - 'list.php' Multiple SQL Injections
Note: the vendor has disputed this issue. Multiple SQL injection vulnerabilities in Land Down Under (LDU) 800 allow remo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Battlefield (BFCC < 1.22_A /BFVCC < 2.14_B / BF2CC) - Authentication Bypass / Password Stealer / Denial of Service
Battlefield 1942 1.6.19 and earlier, and Battlefield Vietnam 1.2 and earlier, allows a remote master server to cause a d
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHPWebNotes 2.0 - 'Api.php' Remote File Inclusion
php_api.php in phpWebNotes 2.0.0 uses the extract function to modify key variables such as $t_path_core, which leads to
23RISK
open ↗Exploit-DB✓ VexDay Proof
Autolinks 2.1 Pro - 'Al_initialize.php' Remote File Inclusion
PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 2.x - 'error.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrar
23RISK
open ↗Exploit-DB✓ VexDay Proof
Looking Glass 20040427 - Remote Command Execution
Looking Glass 20040427 allows remote attackers to execute arbitrary commands via shell metacharacters in the DNS lookup
28RISK
open ↗Exploit-DB✓ VexDay Proof
Astaro Security Linux 6.0 01 - HTTP CONNECT Unauthorized Access
The HTTP proxy in Astaro Security Linux 6.0 does not properly filter HTTP CONNECT requests to localhost, which allows re
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Plug-and-Play Service - Remote Universal (Spanish) (MS05-039)
Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1
60RISK
open ↗Exploit-DB✓ VexDay Proof
LeapFTP Client 2.7.3/2.7.4 - '.LSQ' File Remote Buffer Overflow (PoC)
Buffer overflow in LeapFTP allows remote attackers to execute arbitrary code via a long Host string in a Site Queue (.ls
23RISK
open ↗Exploit-DB✓ VexDay Proof
Foojan PHPWeblog - Html Injection
Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) admin.php in Foojan PHP Weblog allow remote
23RISK
open ↗Exploit-DB✓ VexDay Proof
QNX RTOS 6.1/6.3 - InputTrap Local Arbitrary File Disclosure
The inputtrap utility in QNX RTOS 6.1.0, 6.3, and possibly earlier versions does not properly check permissions when the
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ventrilo 2.3.0 (All Platforms) - Remote Denial of Service
Ventrilo 2.1.2 through 2.3.0 allows remote attackers to cause a denial of service (application crash) via a status packe
23RISK
open ↗Exploit-DB✓ VexDay Proof
PostNuke 0.76 RC4b Comments Module - 'moderate' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.760-RC4b allows remote attackers to inject arbitrary w
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.2.3 for Mac OS - Denial of Service
Microsoft Internet Explorer 5.2.3 for Mac OS allows remote attackers to cause a denial of service (crash) via a web page
28RISK
open ↗Exploit-DB✓ VexDay Proof
ZipTorrent 1.3.7.3 - Local Proxy Password Disclosure
ZipTorrent 1.3.7.3 stores sensitive information in plaintext in the pref.txt file, which allows local users to obtain se
23RISK
open ↗Exploit-DB✓ VexDay Proof
PostNuke 0.76 RC4b - 'user.php?htmltext' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.760-RC4b allows remote attackers to inject arbitrary w
23RISK
open ↗Exploit-DB✓ VexDay Proof
MyBulletinBoard (MyBB) 1.00 RC4 - 'search.php' SQL Injection
SQL injection vulnerability in search.php for MyBulletinBoard (MyBB) 1.00 Release Candidate 1 through 4 allows remote at
23RISK
open ↗Exploit-DB✓ VexDay Proof
PostNuke 0.75/0.76 DL - 'viewdownload.php' SQL Injection
SQL injection vulnerability in the Downloads module in PostNuke 0.760-RC4b allows PostNuke administrators to execute arb
23RISK
open ↗Exploit-DB✓ VexDay Proof
Elm < 2.5.8 - Expires Header Remote Buffer Overflow
Stack-based buffer overflow in expires.c in Elm 2.5 PL5 through PL7, and possibly other versions, allows remote attacker
28RISK
open ↗Exploit-DB✓ VexDay Proof
Mercora IMRadio 4.0.0.0 - Local Password Disclosure
Mercora IMRadio 4.0.0.0 stores usernames and passwords in plaintext in the MercoraClient\Profiles registry key, which al
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHPKit 1.6.1 - 'member.php' SQL Injection
Multiple SQL injection vulnerabilities in PHPKit 1.6.1 allow remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Exploit-DB✓ VexDay Proof
jPORTAL 2.2.1/2.3.1 - 'download.php' SQL Injection
SQL injection vulnerability in module/down.inc.php in jportal 2.3.1 allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mall23 - 'AddItem.asp' SQL Injection
SQL injection vulnerability in AddItem.asp in Mall23 eCommerce allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
Land Down Under 800 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
Note: the vendor has disputed this issue. Multiple cross-site scripting (XSS) vulnerabilities in Land Down Under (LDU) 8
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.