Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,866cataloged exploits
35,812CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,573GitHub PoC 14,316VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
Icecast 2.x - XSL Parser Multiple Vulnerabilities
Multiple buffer overflows in the XSL parser for IceCast 2.20 may allow attackers to cause a denial of service and possib
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHPOpenChat 3.0.1 - Multiple HTML Injection Vulnerabilities
Cross-site scripting (XSS) vulnerability in PHPOpenChat v3.x allows remote attackers to inject arbitrary web script or H
23RISK
open ↗Exploit-DB✓ VexDay Proof
RunCMS 1.1 - Database Configuration Information Disclosure
highlight.php in (1) RUNCMS 1.1A, (2) CIAMOS 0.9.2 RC1, (3) e-Xoops 1.05 Rev3, and possibly other products based on e-Xo
23RISK
open ↗Exploit-DB✓ VexDay Proof
ACS Blog 0.8/0.9/1.0/1.1 - 'search.asp' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.asp in ACS Blog 0.8 through 1.1b allows remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000/2003 - Graphical Device Interface Library Denial of Service
The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (
35RISK
open ↗Exploit-DB✓ VexDay Proof
McNews 1.x - 'install.php' Arbitrary File Inclusion
PHP remote file inclusion vulnerability in install.php in mcNews 1.3 and earlier allows remote attackers to execute arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
MailEnable 1.8 - Remote Format String Denial of Service
Format string vulnerability in MailEnable 1.8 allows remote attackers to cause a denial of service (application crash) v
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.4.x/2.6.x - Multiple ISO9660 Filesystem Handling Vulnerabilities
Multiple "range checking flaws" in the ISO9660 filesystem handler in Linux 2.6.11 and earlier may allow attackers to cau
28RISK
open ↗Exploit-DB✓ VexDay Proof
iPool 1.6.81 - Local Password Disclosure
ThePoolClub (1) iPool and (2) iSnooker 1.6.81 and earlier stores usernames and passwords in cleartext in the MyDetails.t
23RISK
open ↗Exploit-DB✓ VexDay Proof
iSnooker 1.6.8 - Local Password Disclosure
ThePoolClub (1) iPool and (2) iSnooker 1.6.81 and earlier stores usernames and passwords in cleartext in the MyDetails.t
23RISK
open ↗Exploit-DB✓ VexDay Proof
PunBB 1.2.3 - Multiple HTML Injection Vulnerabilities
Cross-site scripting (XSS) vulnerability in PunBB 1.2.3 allows remote attackers to inject arbitrary web script or HTML v
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHPOpenChat 2.3.4/3.0.1 - 'ENGLISH_poc.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in PHPOpenChat 3.0.1 and earlier allow remote attackers to execute ar
28RISK
open ↗Exploit-DB✓ VexDay Proof
PHPOpenChat 2.3.4/3.0.1 - 'poc.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in PHPOpenChat 3.0.1 and earlier allow remote attackers to execute ar
28RISK
open ↗Exploit-DB✓ VexDay Proof
PHPOpenChat 2.3.4/3.0.1 - 'poc_loginform.php?phpbb_root_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in PHPOpenChat 3.0.1 and earlier allow remote attackers to execute ar
28RISK
open ↗Exploit-DB✓ VexDay Proof
ZPanel 2.5 - SQL Injection
SQL injection vulnerability in ZPanel 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) uname pa
23RISK
open ↗Exploit-DB✓ VexDay Proof
GoodTech Telnet Server < 5.0.7 - Buffer Overflow Crash
Buffer overflow in the administration web server for GoodTech Telnet Server 4.0 and 5.0, and possibly all versions befor
50RISK
open ↗Exploit-DB✓ VexDay Proof
PaX - Double-Mirrored VMA munmap Privilege Escalation
Unknown vulnerability in PaX from the September 2003 release to 2.2 before 2005.03.05, related to SEGMEXEC or RANDEXEC a
23RISK
open ↗Exploit-DB✓ VexDay Proof
LimeWire 4.1.2 < 4.5.6 - 'GET' Remote File Read
LimeWire 4.1.2 through 4.5.6 allows remote attackers to read arbitrary files by specifying the full pathname in a Gnutel
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHPAdsNew 2.0.4 - 'AdFrame.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in adframe.php in phpAdsNew 2.0.4-pr1, when register_globals is enabled, allows
23RISK
open ↗Exploit-DB✓ VexDay Proof
Frank McIngvale LuxMan 0.41 - Local Buffer Overflow
Buffer overflow in luxman before 0.41, if used with certain insecure svgalib libraries, allows local users to execute ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
SimpGB 1.0 - 'Guestbook.php' SQL Injection
SQL injection vulnerability in gb_new.inc in SimpGB allows remote attackers to execute arbitrary SQL commands via the qu
23RISK
open ↗Exploit-DB✓ VexDay Proof
Phorum 5.0.14 - Multiple Subject and Attachment HTML Injection Vulnerabilities
Cross-site scripting (XSS) vulnerability in Phorum before 5.0.14a allows remote attackers to inject arbitrary web script
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Suite/Firefox/Thunderbird - Nested Anchor Tag Status Bar Spoofing
Mozilla Firefox 1.0.1 and possibly other versions, including Mozilla and Thunderbird, allows remote attackers to spoof t
23RISK
open ↗Exploit-DB✓ VexDay Proof
HolaCMS 1.2.x/1.4.x Voting Module - Directory Traversal Remote File Corruption
Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sentinel LM 7.x - UDP License Service Remote Buffer Overflow
Buffer overflow in the Sentinel LM (Lservnt) service in the Sentinel License Manager 7.2.0.2 allows remote attackers to
60RISK
open ↗Exploit-DB✓ VexDay Proof
PAFileDB 1.1.3/2.1.1/3.0/3.1 - 'category.php?start' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows rem
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ethereal 0.10.9 (Windows) - '3G-A11' Remote Buffer Overflow
The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting st
23RISK
open ↗Exploit-DB✓ VexDay Proof
HolaCMS 1.2/1.4.x Voting Module - Remote File Corruption
HolaCMS 1.4.9 does not restrict file access to the holaDB/votes directory, which allows remote attackers to overwrite ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
PAFileDB 1.1.3/2.1.1/3.0/3.1 - 'viewall.php?start' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows rem
23RISK
open ↗Exploit-DB✓ VexDay Proof
PAFileDB 1.1.3/2.1.1/3.0/3.1 - 'category.php?start' SQL Injection
SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.