Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,836cataloged exploits
35,811CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,572GitHub PoC 14,290VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
24,455 exploits
Exploit-DB✓ VexDay Proof
PHP-Nuke 7.6 - 'banners.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 7.6 allow remote attackers to inject arbitrary web scrip
23RISK
open ↗Exploit-DB✓ VexDay Proof
Active Auction House - 'default.asp' Multiple SQL Injections
Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 6.x/7.x Your_Account Module - 'Username' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 7.6 allow remote attackers to inject arbitrary web scrip
23RISK
open ↗Exploit-DB✓ VexDay Proof
profitcode software payprocart 3.0 - Directory Traversal
ProfitCode PayProCart 3.0 allows remote attackers to bypass authentication and gain administrative privileges to the adm
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 6.x/7.x 'Downloads' Module - 'Lid' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x through 7.6 allow remote attackers to inject arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
Aeon 0.2a - Local Linux (1)
Buffer overflow in the getConfig function in Aeon 0.2a and earlier allows local users to gain privileges via a long HOME
23RISK
open ↗Exploit-DB✓ VexDay Proof
ProfitCode Software PayProCart 3.0 - 'Usrdetails.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in usrdetails.php in ProfitCode PayProCart 3.0 allows remote attackers to injec
23RISK
open ↗Exploit-DB✓ VexDay Proof
MailEnable Enterprise 1.x - SMTP Remote Denial of Service
The SMTP service in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
Logics Software LOG-FT - Arbitrary File Disclosure
logwebftbs2000.exe in Logics Software File Transfer (LOG-FT) allows remote attackers to read arbitrary files via modifie
23RISK
open ↗Exploit-DB✓ VexDay Proof
Aeon 0.2a - Local Linux (2)
Buffer overflow in the getConfig function in Aeon 0.2a and earlier allows local users to gain privileges via a long HOME
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 6.x/7.x Your_Account Module - Avatarcategory Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 7.6 allow remote attackers to inject arbitrary web scrip
23RISK
open ↗Exploit-DB✓ VexDay Proof
GetDataBack Data Recovery 2.31 - Licence Recover
GetDataBack for NTFS 2.31 stores the username and license key in plaintext in the Name value in the License registry key
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel PPC64/IA64 (AIO) - Local Denial of Service
AIO in the Linux kernel 2.6.11 on the PPC64 or IA64 architectures with CONFIG_HUGETLB_PAGE enabled allows local users to
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Suite/Firefox - JavaScript Lambda Replace Heap Memory Disclosure
The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netsc
28RISK
open ↗Exploit-DB✓ VexDay Proof
SCO OpenServer 5.0.6/5.0.7 - NWPrint Command Line Argument Local Buffer Overflow
Buffer overflow in nwprint in SCO OpenServer 5.0.7 allows local users to execute arbitrary code via a long command line
23RISK
open ↗Exploit-DB✓ VexDay Proof
SonicWALL SOHO 5.1.7 - Web Interface Multiple Remote Input Validation Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in SonicWALL SOHO 5.1.7.0 allow remote attackers to inject arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
Doomsday 1.8/1.9 - Multiple Remote Format String Vulnerabilities
Format string vulnerability in the (1) Con_message and (2) conPrintf functions in con_main.c in Doomsday engine 1.8.6 al
28RISK
open ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 2.x - Convcharset Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin before 2.6.2-rc1 allows remote attackers to inject a
23RISK
open ↗Exploit-DB✓ VexDay Proof
SiteEnable - SQL Injection
SQL injection vulnerability in content.asp in SiteEnable allows remote attackers to execute arbitrary SQL commands via t
23RISK
open ↗Exploit-DB✓ VexDay Proof
Star Wars Jedi Knight: Jedi Academy 1.0.11 - Buffer Overflow (PoC)
Buffer overflow in the G_Printf function in Star Wars Jedi Knight: Jedi Academy 1.011 and earlier allows remote attacker
23RISK
open ↗Exploit-DB✓ VexDay Proof
RUMBA 7.3/7.4 - Profile Handling Multiple Buffer Overflow Vulnerabilities
Multiple buffer overflows in RUMBA 7.3 and earlier allow remote attackers to cause a denial of service and possibly exec
23RISK
open ↗Exploit-DB✓ VexDay Proof
Alstrasoft EPay Pro 2.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in AlstraSoft EPay Pro 2.0 allows remote attackers to execute arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
Alstrasoft EPay Pro 2.0 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft EPay Pro 2.0 allow remote attackers to inject arbitrar
23RISK
open ↗Exploit-DB✓ VexDay Proof
BlueSoleil 1.4 - Object Push Service BlueTooth Arbitrary File Upload / Directory Traversal
Directory traversal vulnerability in the Object Push service in IVT BlueSoleil 1.4 allows remote attackers to upload arb
23RISK
open ↗Exploit-DB✓ VexDay Proof
BakBone NetVault 6.x/7.x - Remote Heap Buffer Overflow (2)
Multiple buffer overflows in BakBone NetVault 6.x and 7.x allow (1) remote attackers to execute arbitrary code via a mod
50RISK
open ↗Exploit-DB✓ VexDay Proof
BakBone NetVault 6.x/7.x - Local Stack Buffer Overflow
Multiple buffer overflows in BakBone NetVault 6.x and 7.x allow (1) remote attackers to execute arbitrary code via a mod
50RISK
open ↗Exploit-DB✓ VexDay Proof
InterAKT Online MX Shop 1.1.1 - SQL Injection
SQL injection vulnerability in InterAKT MX Shop 1.1.1 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Exploit-DB✓ VexDay Proof
ASP-DEV XM Forum RC3 - IMG Tag Script Injection
Cross-site scripting (XSS) vulnerability in posts.asp for ASP-DEv XM Forum RC3 allows remote attackers to inject arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
YepYep MTFTPD 0.2/0.3 - Remote CWD Argument Format String
Buffer overflow in the mt_do_dir function in YepYep mtftpd 0.0.3 may allow attackers to execute arbitrary code via a lon
23RISK
open ↗Exploit-DB✓ VexDay Proof
mtftpd 0.0.3 - Remote Code Execution
Format string vulnerability in the log_do function in log.c for YepYep mtftpd 0.0.3, when the statistics option is enabl
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.