Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,899cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,600GitHub PoC 14,322VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
S9Y Serendipity 0.x - 'exit.php' HTTP Response Splitting
CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting att
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache 1.3.31 mod_include - Local Buffer Overflow
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows (x86) - Metafile '.emf' Heap Overflow (MS04-032)
Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Serv
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.x - Valid File Drag and Drop Embedded Code (MS04-038)
Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft IIS - WebDAV XML Denial of Service (MS04-030)
The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a
45RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Lotus Domino 6.x - Cross-Site Scripting / HTML Injection
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Do
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache 1.3.x mod_include - Local Buffer Overflow
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI
23RISK
open ↗Exploit-DB✓ VexDay Proof
YahooPOPs 1.6 - SMTP Remote Buffer Overflow
Multiple stack-based buffer overflows in YPOPs! (aka YahooPOPS) 0.4 through 0.6 allow remote attackers to cause a denial
60RISK
open ↗Exploit-DB✓ VexDay Proof
best software SalesLogix 2000.0 - Multiple Vulnerabilities
Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot)
23RISK
open ↗Exploit-DB✓ VexDay Proof
SLX Server 6.1 - Arbitrary File Creation
Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot)
23RISK
open ↗Exploit-DB✓ VexDay Proof
ProFTPd 1.2.10 - Remote Users Enumeration
ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which al
50RISK
open ↗Exploit-DB✓ VexDay Proof
Monit 4.2 - Basic Authentication Remote Code Execution
Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute
28RISK
open ↗Exploit-DB✓ VexDay Proof
CoolPHP 1.0 - Multiple Remote Input Validation Vulnerabilities
Directory traversal vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to access arbitrary files a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NNTP Service (XPAT) - Denial of Service (MS04-036)
The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Ser
35RISK
open ↗Exploit-DB✓ VexDay Proof
Yak! Chat Client 2.x - FTP Server Directory Traversal
Directory traversal vulnerability in Digicraft Yak! server 2.0 through 2.1.2 allows remote attackers to read or write ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
YahooPOPs 1.6 - SMTP Port Buffer Overflow
Multiple stack-based buffer overflows in YPOPs! (aka YahooPOPS) 0.4 through 0.6 allow remote attackers to cause a denial
60RISK
open ↗Exploit-DB✓ VexDay Proof
ocPortal 1.0.3 - Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in ocPortal 1.0.3 and earlier allows remote attackers to execute ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
3Com 3CRADSL72 ADSL Wireless Router - Information Disclosure / Authentication Bypass
The 3COM Wireless router 3CRADSL72 running Boot Code 1.3d allows remote attackers to gain sensitive information such as
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP - Weak Default Configuration
The Internet Connection Firewall (ICF) in Microsoft Windows XP SP2 is configured by default to trust sessmgr.exe, which
23RISK
open ↗Exploit-DB✓ VexDay Proof
Icecast 2.0.1 (Win32) - Remote Code Execution (2)
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RISK
open ↗Exploit-DB✓ VexDay Proof
DUclassmate 1.x - 'account.asp?MM-recordId' Arbitrary Password Modification
account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by
23RISK
open ↗Exploit-DB✓ VexDay Proof
DUforum 3.x - 'messageDetail.asp?MSG_ID' SQL Injection
SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
DUforum 3.x - Login Form 'Password' SQL Injection
SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
DUclassified 4.x - 'adDetail.asp' Multiple SQL Injections
Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authenti
23RISK
open ↗Exploit-DB✓ VexDay Proof
DUforum 3.x - 'messages.asp?FOR_ID' SQL Injection
SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
Monolith Games - Local Buffer Overflow (PoC)
Buffer overflow in Monolith games including (1) Alien versus Predator 2 1.0.9.6 and earlier, (2) Blood 2 2.1 and earlier
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Core 1.2 - HTTP Splitting
CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting
28RISK
open ↗Exploit-DB✓ VexDay Proof
MySQL 3.x/4.x - ALTER TABLE/RENAME Forces Old Permission Checks
MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights o
28RISK
open ↗Exploit-DB✓ VexDay Proof
DCP-Portal 3.7/4.x/5.x - 'announcement.php?cid' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and earlier allow remote attackers to inject arb
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft ASP.NET 1.x - URI Canonicalization Unauthorized Web Access
The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .asp
45RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.