Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,866cataloged exploits
35,812CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,573GitHub PoC 14,316VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
PostgreSQL 7.x - Multiple Vulnerabilities
Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large num
28RISK
open ↗Exploit-DB✓ VexDay Proof
CitrusDB 0.1/0.2/0.3 Credit Card Data - Remote Information Disclosure
CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
Xpand Rally 1.0.0.0 (Server/Clients) - Crash
Xpand Rally 1.0.0.0 allows remote attackers or remote malicious game servers to cause a denial of service (application c
23RISK
open ↗Exploit-DB✓ VexDay Proof
ncpfs < 2.2.6 (Gentoo / Linux) - Local Privilege Escalation
ncpfs 2.2.6 allows local users to cause a denial of service, obtain sensitive information, or possibly gain privileges v
23RISK
open ↗Exploit-DB✓ VexDay Proof
Vim - 'mch_expand_wildcards()' Heap Buffer Overflow
Heap-based buffer overflow in the mch_expand_wildcards function in os_unix.c in Vim 6.2 and 6.3 allows user-assisted att
23RISK
open ↗Exploit-DB✓ VexDay Proof
ngIRCd 0.6/0.7/0.8 - Remote Buffer Overflow
Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a
28RISK
open ↗Exploit-DB✓ VexDay Proof
IceWarp Web Mail 5.3 - login.html 'Username' Cross-Site Scripting
Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attack
23RISK
open ↗Exploit-DB✓ VexDay Proof
IceWarp Web Mail 5.3 - 'accountsettings_add.html?accountid' Cross-Site Scripting
Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attack
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebWasher Classic 2.2/2.3 - HTTP CONNECT Unauthorized Access
WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost f
23RISK
open ↗Exploit-DB✓ VexDay Proof
Magic Winmail Server 4.0 (Build 1112) - 'download.php' Traversal Arbitrary File Access
Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload
23RISK
open ↗Exploit-DB✓ VexDay Proof
War FTP Daemon 1.8 - Remote Denial of Service
WarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access
23RISK
open ↗Exploit-DB✓ VexDay Proof
Magic Winmail Server 4.0 (Build 1112) - 'upload.php' Traversal Arbitrary File Upload
Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.4 - 'uselib()' Local Privilege Escalation (2)
Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.4
23RISK
open ↗Exploit-DB✓ VexDay Proof
Berlios GPSD 2.7.x - Remote Format String
Format string vulnerability in the gpsd_report function for BerliOS GPD daemon (gpsd, formerly pygps) 1.9.0 through 2.7
50RISK
open ↗Exploit-DB✓ VexDay Proof
AWStats 6.0 < 6.2 - 'configdir' Remote Command Execution
AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacte
60RISK
open ↗Exploit-DB✓ VexDay Proof
AWStats 6.0 < 6.2 - 'configdir' Remote Command Execution
AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacte
60RISK
open ↗Exploit-DB✓ VexDay Proof
MercuryBoard 1.1 - Multiple Input Validation Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in index.php in MercuryBoard 1.1.1 allow remote attackers to inject
23RISK
open ↗Exploit-DB✓ VexDay Proof
NullSoft Winamp 5.0.x - Variant 'IN_CDDA.dll' Remote Buffer Overflow (PoC)
Stack-based buffer overflow in the in_cdda.dll plugin for Winamp 5.0 through 5.08c allows attackers to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - '.ANI' Downloader (MS05-002)
The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Window
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - '.ANI' Universal (MS05-002)
The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Window
35RISK
open ↗Exploit-DB✓ VexDay Proof
Golden FTP Server 2.02b - Remote Buffer Overflow
Buffer overflow in Golden FTP Server Pro (goldenftpd) 2.x allows remote attackers to execute arbitrary code via a long R
28RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.3.7 - 'mRouter' Local Privilege Escalation
Buffer overflow in the (1) -v and (2) -a switches in mRouter in iSync 1.5 in Mac OS X 10.3.7 and earlier allows local us
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.3.7 - Input Validation Flaw 'parse_machfile()' Denial of Service
20RISK
open ↗Exploit-DB✓ VexDay Proof
Siteman 1.1 - User Database Privilege Escalation (2)
CRLF injection vulnerability in users.php in Siteman 1.1.10 and earlier allows remote attackers to add arbitrary users a
23RISK
open ↗Exploit-DB✓ VexDay Proof
konversation irc client 0.15 - Multiple Vulnerabilities
The Quick Buttons feature in Konversation 0.15 allows remote attackers to execute certain IRC commands via a channel nam
28RISK
open ↗Exploit-DB✓ VexDay Proof
Siteman 1.1 - User Database Privilege Escalation (1)
CRLF injection vulnerability in users.php in Siteman 1.1.10 and earlier allows remote attackers to add arbitrary users a
23RISK
open ↗Exploit-DB✓ VexDay Proof
NodeManager Professional 2.00 - Remote Buffer Overflow
Stack-based buffer overflow in NodeManager Professional 2.00 allows remote attackers to execute arbitrary commands via a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple iTunes - Playlist Parsing Local Buffer Overflow
Buffer overflow in Apple iTunes 4.7 allows remote attackers to execute arbitrary code via a long URL in (1) .m3u or (2)
50RISK
open ↗Exploit-DB✓ VexDay Proof
GeoBlog 1.0 - 'viewcat.php' SQL Injection
SQL injection vulnerability in viewcat.php in BitDamaged geoBlog MOD_1.0 allows remote attackers to execute arbitrary SQ
23RISK
open ↗Exploit-DB✓ VexDay Proof
Exim 4.41 - 'dns_build_reverse' Local Buffer Overflow
Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.