Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,600GitHub PoC 14,323VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
@lexPHPTeam @lex Guestbook 3.12 - PHP Remote File Inclusion
PHP remote file inclusion vulnerability in livre_include.php in @lex Guestbook allows remote attackers to execute arbitr
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - JPEG GDI+ Bind/Reverse/Admin/File Download
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlu
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - JPEG GDI+ Remote Heap Overflow (MS04-028)
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlu
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - JPEG GDI+ Overflow Download Shellcode (MS04-028)
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlu
35RISK
open ↗Exploit-DB✓ VexDay Proof
PopMessenger 1.60 - Remote Denial of Service
The Base64 function in PopMessenger 1.60 (before 20 Sep 2004) and earlier allows remote attackers to cause a denial of s
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - JPEG GDI+ Overflow Administrator (MS04-028)
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlu
35RISK
open ↗Exploit-DB✓ VexDay Proof
Sophos Anti-Virus 3.x - Reserved MS-DOS Name Scan Evasion
Sophos Small Business Suite 1.00 on Windows does not properly handle files whose names contain reserved MS-DOS device na
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - JPEG GDI+ Overflow Shellcode
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlu
35RISK
open ↗Exploit-DB✓ VexDay Proof
Alt-N MDaemon 6.5.1 - IMAP/SMTP Remote Buffer Overflow
Multiple buffer overflows in MDaemon 6.5.1 allow remote attackers to cause a denial of service (application crash) via a
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - JPEG Processing Buffer Overrun (MS04-028)
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlu
35RISK
open ↗Exploit-DB✓ VexDay Proof
EmuLive Server4 - Authentication Bypass / Denial of Service
EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to bypass authentication for the remote administrati
28RISK
open ↗Exploit-DB✓ VexDay Proof
Emulive Server4 Build 7560 - Remote Denial of Service
EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to cause a denial of service (application crash) via
23RISK
open ↗Exploit-DB✓ VexDay Proof
LaTeX2rtf 1.9.15 - Remote Buffer Overflow
Multiple buffer overflows in LaTeX2rtf 1.9.15, and possibly other versions, allow remote attackers to execute arbitrary
28RISK
open ↗Exploit-DB✓ VexDay Proof
Pinnacle ShowCenter 1.51 - Web Interface Skin Denial of Service
SettingsBase.php in Pinnacle ShowCenter 1.51 allows remote attackers to cause a denial of service (web interface errors)
23RISK
open ↗Exploit-DB✓ VexDay Proof
SudoEdit 1.6.8 - Local Change Permission
sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mambo Open Source 4.5.1 (1.0.9) - 'Function.php' Arbitrary Command Execution
PHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrar
23RISK
open ↗Exploit-DB✓ VexDay Proof
TUTOS - 'app_new.php?t' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to inject arbitrary web script o
23RISK
open ↗Exploit-DB✓ VexDay Proof
TUTOS - 'file_overview.php?link_id' SQL Injection
SQL injection vulnerability in file_overview.php in TUTOS 1.1 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mambo Open Source 4.5.1 (1.0.9) - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Mambo 4.5 (1.0.9) allows remote attackers to inject arbitrary w
23RISK
open ↗Exploit-DB✓ VexDay Proof
Pigeon Server 3.02.0143 - Denial of Service
Pigeon Server 3.02.0143 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumpt
23RISK
open ↗Exploit-DB✓ VexDay Proof
CDRecord's ReadCD - Local Privilege Escalation
cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before execu
23RISK
open ↗Exploit-DB✓ VexDay Proof
Remository - SQL Injection
SQL injection vulnerability in the ReMOSitory Server add-on module to Mambo Portal 4.5.1 (1.09) and earlier allows remot
23RISK
open ↗Exploit-DB✓ VexDay Proof
Google Toolbar 1.1.x - About.HTML HTML Injection
Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web scr
23RISK
open ↗Exploit-DB✓ VexDay Proof
DNS4Me 3.0 - Denial of Service / Cross-Site Scripting
The Web Server in DNS4Me 3.0.0.4 allows remote attackers to cause a denial of service (CPU consumption and crash) via a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Snitz Forums 2000 - 'down.asp' HTTP Response Splitting
CRLF injection vulnerability in down.asp for Snitz Forums 2000 3.4.04 allows remote attackers to perform HTTP Response S
23RISK
open ↗Exploit-DB✓ VexDay Proof
Alt-N MDaemon 6.5.1 SMTP Server - Multiple Command Remote Overflows
Multiple buffer overflows in MDaemon 6.5.1 allow remote attackers to cause a denial of service (application crash) via a
35RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Nuke - SQL Injection Edit/Save Messages
SQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x through 7.2 allows remote attackers to exe
23RISK
open ↗Exploit-DB✓ VexDay Proof
myserver 0.7 - Directory Traversal
Directory traversal vulnerability in myServer 0.7 allows remote attackers to list arbitrary directories via an HTTP GET
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP 4.x/5.0.1 - PHP_Variables Remote Memory Disclosure
php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or
23RISK
open ↗Exploit-DB✓ VexDay Proof
CUPS 1.1.x - UDP Packet Remote Denial of Service
The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of s
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.