Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,549GitHub PoC 14,290VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
24,455 exploits
Exploit-DB✓ VexDay Proof
Microsoft Windows - Malformed IP Options Denial of Service (MS05-019)
Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause
45RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Malformed IP Options Denial of Service (MS05-019)
Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Malformed IP Options Denial of Service (MS05-019)
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial o
45RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Malformed IP Options Denial of Service (MS05-019)
Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Malformed IP Options Denial of Service (MS05-019)
Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via
45RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000 - Internet Protocol Validation Remote Code Execution (2)
Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers
35RISK
open ↗Exploit-DB✓ VexDay Proof
Datenbank Module For phpBB - 'Remote mod.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in mod.php in the datenbank module for phpBB allows remote attackers to inject
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpBB Remote - 'mod.php' SQL Injection
SQL injection vulnerability in mod.php in the datenbank module for phpBB allows remote attackers to execute arbitrary SQ
23RISK
open ↗Exploit-DB✓ VexDay Proof
RSA Security RSA Authentication Agent For Web 5.2 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in IISWebAgentIF.dll in the RSA Authentication Agent for Web 5.2 allows remote
23RISK
open ↗Exploit-DB✓ VexDay Proof
SqWebMail 3.x/4.0 - HTTP Response Splitting
SqWebMail allows remote attackers to inject arbitrary web script or HTML via CRLF sequences in the redirect parameter fo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Libsafe 2.0 - Multi-threaded Process Race Condition Security Bypass
Race condition in libsafe 2.0.16 and earlier, when running in multi-threaded applications, allows attackers to bypass li
23RISK
open ↗Exploit-DB✓ VexDay Proof
All4WWW-HomePageCreator 1.0 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in All4WWW-Homepagecreator 1.0a allows remote attackers to execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
OneWorldStore - 'OWProductDetail.asp' SQL Injection
Multiple SQL injection vulnerabilities in OneWorldStore allow remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Exploit-DB✓ VexDay Proof
SPHPBlog 0.4 - 'search.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.php for Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to i
23RISK
open ↗Exploit-DB✓ VexDay Proof
Yager 5.24 - Multiple Denial of Service Vulnerabilities
Yager 5.24 and earlier allows remote attackers to cause a denial of service (application hang) via a packet with a game
23RISK
open ↗Exploit-DB✓ VexDay Proof
Yager 5.24 - Multiple Denial of Service Vulnerabilities
Yager 5.24 and earlier allows remote attackers to cause a denial of service (application crash) via certain malformed da
23RISK
open ↗Exploit-DB✓ VexDay Proof
OneWorldStore - 'OWAddItem.asp' SQL Injection
Multiple SQL injection vulnerabilities in OneWorldStore allow remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'HTA' Script Execution (MS05-016)
The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server
35RISK
open ↗Exploit-DB✓ VexDay Proof
OneWorldStore - 'OWListProduct.asp' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in OneWorldStore allow remote attackers to inject arbitrary web scri
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sumus 0.2.2 - HTTPd Remote Buffer Overflow
Stack-based buffer overflow in the RespondeHTTPPendiente function in the HTTP server for SUMUS 0.2.2 allows remote attac
23RISK
open ↗Exploit-DB✓ VexDay Proof
OneWorldStore - 'OWContactUs.asp' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in OneWorldStore allow remote attackers to inject arbitrary web scri
23RISK
open ↗Exploit-DB✓ VexDay Proof
OneWorldStore - 'OWListProduct.asp' Multiple SQL Injections
Multiple SQL injection vulnerabilities in OneWorldStore allow remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Exploit-DB✓ VexDay Proof
S9Y Serendipity 0.8beta4 - 'exit.php' SQL Injection
SQL injection vulnerability in exit.php for Serendipity 0.8 and earlier allows remote attackers to execute arbitrary SQL
23RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Database 10.1 - MDSYS.MD2.SDO_CODE_SIZE Buffer Overflow
Buffer overflow in the SDO_CODE_SIZE procedure of the MD2 package (MDSYS.MD2.SDO_CODE_SIZE) in Oracle 10g before 10.1.0.
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Websphere 5.0/5.1/6.0 - Application Server Web Server Root JSP Source Code Disclosure
IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attack
23RISK
open ↗Exploit-DB✓ VexDay Proof
DeluxeFtp 6.x - Local Password Disclosure
Lightspeed DeluxeFTP 6.01 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allow
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpBB 1.x/2.0.x - Knowledge Base Module 'KB.php' SQL Injection
SQL injection vulnerability in kb.php in the Knowledge Base module for phpBB allows remote attackers to obtain sensitive
23RISK
open ↗Exploit-DB✓ VexDay Proof
gld 1.4 - Postfix Greylisting Daemon Remote Format String
Format string vulnerability in the ErrorLog function in cnf.c in Greylisting daemon (GLD) 1.3 and 1.4 allows remote atta
28RISK
open ↗Exploit-DB✓ VexDay Proof
Multiple Vendor ICMP Implementation - Spoofed Source Quench Packet Denial of Service
Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reducti
28RISK
open ↗Exploit-DB✓ VexDay Proof
XAMPP - Insecure Default Password Disclosure
XAMPP 1.4.x has multiple default or null passwords, which allows attackers to gain privileges.
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.