Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,866cataloged exploits
35,812CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,573GitHub PoC 14,316VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
PAFileDB 1.1.3/2.1.1/3.0/3.1 - 'category.php?start' SQL Injection
SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
UBBCentral UBB.Threads 6.0 - 'Printthread.php' SQL Injection
SQL injection vulnerability in printthread.php in UBB.Threads allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpBB 2.0.12 - Session Handling Authentication Bypass
sessions.php in phpBB 2.0.12 and earlier allows remote attackers to gain administrator privileges via the autologinid va
23RISK
open ↗Exploit-DB✓ VexDay Proof
MySQL 4.x - CREATE FUNCTION Arbitrary libc Code Execution
MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to
28RISK
open ↗Exploit-DB✓ VexDay Proof
SocialMPN - Arbitrary File Injection
PHP remote file inclusion vulnerability in article mode for modules.php in SocialMPN allows remote attackers to execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
MySQL 4.x - CREATE FUNCTION mysql.func Table Arbitrary Library Injection
MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to
28RISK
open ↗Exploit-DB✓ VexDay Proof
PY Software Active Webcam 4.3/5.5 - WebServer Multiple Vulnerabilities
PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service (CPU consumpti
23RISK
open ↗Exploit-DB✓ VexDay Proof
All Enthusiast PhotoPost PHP Pro 5.0 - 'adm-photo.php' Arbitrary Image Manipulation
adm-photo.php in PhotoPost PHP 5.0 RC3 does not properly verify administrative privileges before manipulating photos, wh
23RISK
open ↗Exploit-DB✓ VexDay Proof
Download Center Lite (DCL) 1.5 - Remote File Inclusion
PHP remote file inclusion vulnerability in download_center_lite.inc.php for Download Center Lite 1.6 allows remote attac
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - 'SYS_EPoll_Wait' Local Integer Overflow / Local Privilege Escalation (1)
Integer overflow in sys_epoll_wait in eventpoll.c for Linux kernel 2.6 to 2.6.11 allows local users to overwrite kernel
23RISK
open ↗Exploit-DB✓ VexDay Proof
Yahoo! Messenger 5.x/6.0 - Offline Mode Status Remote Buffer Overflow
Buffer overflow in Yahoo! Messenger allows remote attackers to execute arbitrary code via the offline mode.
23RISK
open ↗Exploit-DB✓ VexDay Proof
YaBB 2.0 - Remote UsersRecentPosts Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web scr
23RISK
open ↗Exploit-DB✓ VexDay Proof
paNews 2.0b4 - Remote Admin Creation SQL Injection
admin_setup.php in paNews 2.0.4b allows remote attackers to inject arbitrary PHP code via the (1) $form[comments] or (2)
23RISK
open ↗Exploit-DB✓ VexDay Proof
Newsscript - Access Validation
newsscript.pl for NewsScript allows remote attackers to gain privileges by setting the mode parameter to admin.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Aztek Forum 4.0 - 'myadmin.php' Database Dumper
The export_index action in myadmin.php for Aztek Forum 4.0 allows remote attackers to obtain database files, possibly by
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2003 - Remote Denial of Service
The IPv6 support in Windows XP SP2, 2003 Server SP1, and Longhorn, with Windows Firewall turned off, allows remote attac
28RISK
open ↗Exploit-DB✓ VexDay Proof
The Includer CGI 1.0 - Remote Command Execution (1)
includer.cgi in The Includer allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the U
23RISK
open ↗Exploit-DB✓ VexDay Proof
RealNetworks RealPlayer 10 - '.smil' Local Buffer Overflow
Stack-based buffer overflow in the CSmil1Parser::testAttributeFailed function in smlparse.cpp for RealNetworks RealPlaye
50RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2003 - Remote Denial of Service
Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (
35RISK
open ↗Exploit-DB✓ VexDay Proof
phpWebLog 0.5.3 - Arbitrary File Inclusion
PHP remote file inclusion vulnerability in PHPWebLog 0.5.3 and earlier allows remote attackers to execute arbitrary PHP
23RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Database 8i/9i - Multiple Directory Traversal Vulnerabilities
Directory traversal vulnerability in Oracle Database Server 8i and 9i allows remote attackers to read or rename arbitrar
28RISK
open ↗Exploit-DB✓ VexDay Proof
PHP mcNews 1.3 - 'skinfile' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/header.php in PHP mcNews 1.3 allows remote attackers to execute arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
CA License Server - 'GETCONFIG' Remote Buffer Overflow
Buffer overflow in Computer Associates (CA) License Client 0.1.0.15 allows remote attackers to execute arbitrary code vi
35RISK
open ↗Exploit-DB✓ VexDay Proof
CA License Server - 'GETCONFIG' Remote Buffer Overflow
Multiple buffer overflows in Computer Associates (CA) License Client and Server 0.1.0.15 allow remote attackers to execu
50RISK
open ↗Exploit-DB✓ VexDay Proof
PlatinumFTPServer 1.0.18 - Multiple Malformed User Name Connection Denial of Service Vulnerabilities
PlatinumFTP 1.0.18, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) v
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP Form Mail 2.3 - Arbitrary File Inclusion
PHP remote file inclusion vulnerability in formmail.inc.php for Form Mail Script 2.3 and earlier allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache 2.0.52 - GET Denial of Service
Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP G
35RISK
open ↗Exploit-DB✓ VexDay Proof
ca3de - Multiple Vulnerabilities
Format string vulnerability in Carsten's 3D Engine (Ca3DE), March 2004 version and earlier, allows remote attackers to e
23RISK
open ↗Exploit-DB✓ VexDay Proof
AWStats 5.7 < 6.2 - Multiple Remote s
awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter
23RISK
open ↗Exploit-DB✓ VexDay Proof
Foxmail 1.1.0.1 - POP3 Temp Dir Stack Overflow
Buffer overflow in Foxmail Server 2.0 allows remote attackers to execute arbitrary code via a long USER command.
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.