Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,549GitHub PoC 14,290VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
24,455 exploits
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1 - '.JPEG' Image Rendering CMP Fencepost Denial of Service
The JPEG decoder in Microsoft Internet Explorer allows remote attackers to cause a denial of service (CPU consumption or
28RISK
open ↗Exploit-DB✓ VexDay Proof
Novell Groupwise 6.5 Webaccess - HTML Injection
Cross-site scripting (XSS) vulnerability in Novell Groupwise WebAccess 6.5 before July 11, 2005 allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
NullSoft Winamp 5.0 - Malformed ID3v2 Tag Buffer Overflow
Buffer overflow in Winamp 5.03a, 5.09 and 5.091, and other versions before 5.094, allows remote attackers to execute arb
28RISK
open ↗Exploit-DB✓ VexDay Proof
netPanzer 0.8 - Remote Denial of Service
NetPanzer 0.8 and earlier allows remote attackers to cause a denial of service (infinite loop) via a packet with a zero
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Netman Service Local Denial of Service
netman.dll in Microsoft Windows Connections Manager Library allows local users to cause a denial of service (Network Con
28RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Suite/Firefox < 1.0.5 - compareTo Code Execution (Metasploit)
Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of serv
50RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox 1.0.4 - 'Set As Wallpaper' Code Execution
Firefox 1.0.3 and 1.0.4, and Netscape 8.0.2, allows remote attackers to execute arbitrary code by tricking the user into
23RISK
open ↗Exploit-DB✓ VexDay Proof
Nokia Affix 2.0/2.1/3.x - BTSRV/BTOBEX Remote Command Execution
Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via sh
28RISK
open ↗Exploit-DB✓ VexDay Proof
SoftiaCom wMailServer 1.0 - Remote Denial of Service
SoftiaCom wMailServer 1.0 and 2.0 allows remote attackers to cause a denial of service (application crash) via a large T
50RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco CallManager 1.0/2.0/3.x/4.0 - CTI Manager Remote Denial of Service
Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows
23RISK
open ↗Exploit-DB✓ VexDay Proof
DVBBS 7.1 - 'ShowErr.asp' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in showerr.asp in DVBBS 7.1 SP2 allows remote attackers to inject arbitrary web
23RISK
open ↗Exploit-DB✓ VexDay Proof
BlogTorrent 0.92 - Remote Password Disclosure
Blog Torrent 0.92 and earlier stores sensitive files under the web document root in the (1) data or (2) torrents directo
23RISK
open ↗Exploit-DB✓ VexDay Proof
PPA 0.5.6 - 'ppa_root_path' File Inclusion
PHP remote file inclusion vulnerability in inc/functions.inc.php in PPA web photo gallery 0.5.6 allows remote attackers
28RISK
open ↗Exploit-DB✓ VexDay Proof
Hosting Controller 0.6.1 HotFix 2.1 - Change Credit Limit
Hosting Controller 6.1 Hotfix 2.1 allows remote authenticated users to perform unauthorized actions, such as modifying t
23RISK
open ↗Exploit-DB✓ VexDay Proof
PrivaShare 1.3 - Denial of Service
PrivaShare 1.1b allows remote attackers to cause a denial of service (crash) via a malformed message.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Novell NetMail 3.x - Automatic Script Execution
Novell NetMail automatically processes HTML in an attachment without prompting the user to save or open it, which makes
23RISK
open ↗Exploit-DB✓ VexDay Proof
TCP Chat (TCPX) 1.0 - Denial of Service
TCP Chat 1.0 allows remote attackers to cause a denial of service (crash) via a long string to the chat service, possibl
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Lotus Domino Notes 6.0/6.5 - Mail Template Automatic Script Execution
The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save
23RISK
open ↗Exploit-DB✓ VexDay Proof
Internet Download Manager 4.0.5 - Input URL Stack Overflow
Stack-based buffer overflow in Internet Download Manager 4.05 allows remote attackers to execute arbitrary code via a lo
23RISK
open ↗Exploit-DB✓ VexDay Proof
OFTPD 0.3.x - User Command Buffer Overflow
oftpd 0.3.7 allows remote attackers to cause a denial of service via a USER command with a large number of null (\0) cha
23RISK
open ↗Exploit-DB✓ VexDay Proof
MyGuestbook 0.6.1 - 'Form.Inc.php3' Remote File Inclusion
PHP remote file inclusion vulnerability in form.inc.php3 in MyGuestbook 0.6.1 allows remote attackers to execute arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpPgAdmin 3.x - Login Form Directory Traversal
Encoded directory traversal vulnerability in phpPgAdmin 3.1 to 3.5.3 allows remote attackers to access arbitrary files v
23RISK
open ↗Exploit-DB✓ VexDay Proof
AutoIndex PHP Script 1.5.2 - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in AutoIndex PHP Script 1.5.2 allows remote attackers to inject ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - 'javaprxy.dll' COM Object Remote Overflow
Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allow
35RISK
open ↗Exploit-DB✓ VexDay Proof
Drupal 4.5.3 < 4.6.1 - Comments PHP Injection
Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP c
23RISK
open ↗Exploit-DB✓ VexDay Proof
EasyPHPCalendar 6.1.5/6.2.x - 'popup.php?serverPath' Remote File Inclusion
PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrar
23RISK
open ↗Exploit-DB✓ VexDay Proof
EasyPHPCalendar 6.1.5/6.2.x - 'setupSQL.php?serverPath' Remote File Inclusion
PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrar
23RISK
open ↗Exploit-DB✓ VexDay Proof
XML-RPC Library 1.3.0 - 'xmlrpc.php' Remote Command Execution (2)
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PH
60RISK
open ↗Exploit-DB✓ VexDay Proof
XOOPS 2.0.11 - 'xmlrpc.php' SQL Injection
SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote att
23RISK
open ↗Exploit-DB✓ VexDay Proof
EasyPHPCalendar 6.1.5/6.2.x - 'header.inc.php?serverPath' Remote File Inclusion
PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrar
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.