Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,600GitHub PoC 14,323VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
Lexmark Multiple HTTP Servers - Denial of Service
The HTTP server in Lexmark T522 and possibly other models allows remote attackers to cause a denial of service (server c
23RISK
open ↗Exploit-DB✓ VexDay Proof
Samba 3.0.4 - SWAT Authorisation Buffer Overflow
Buffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute a
28RISK
open ↗Exploit-DB✓ VexDay Proof
Layton Technology HelpBox 3.0.1 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Layton HelpBox 3.0.1 allow remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
Serena TeamTrack 6.1.1 - Remote Authentication Bypass
Serena TeamTrack 6.1.1 allows remote attackers to obtain sensitive information such as user names, versions, and databas
23RISK
open ↗Exploit-DB✓ VexDay Proof
Polar Helpdesk 3.0 - Cookie Based Authentication Bypass
Polar HelpDesk 3.0 allows remote attackers to bypass authentication by setting the UserId and UserType values in a cooki
23RISK
open ↗Exploit-DB✓ VexDay Proof
Internet Software Sciences Web+Center 4.0.1 - Cookie Object SQL Injection
Multiple SQL injection vulnerabilities in Internet Software Sciences Web+Center 4.0.1 allow remote attackers to execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
NetSupport DNA HelpDesk 1.0 Problist Script - SQL Injection
SQL injection vulnerability in problist.asp in NetSupport DNA HelpDesk 1.01 allows remote attackers to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
Leigh Business Enterprises Web HelpDesk 4.0 - SQL Injection
SQL injection vulnerability in jobedit.asp in Leigh Business Enterprises (LBE) Web Helpdesk before 4.0.0.81 allows remot
23RISK
open ↗Exploit-DB✓ VexDay Proof
Medal of Honor - Remote Buffer Overflow (PoC)
Buffer overflow in Medal of Honor (1) Allied Assault 1.11v9 and earlier, (2) Breakthrough 2.40b and earlier, and (3) Spe
50RISK
open ↗Exploit-DB✓ VexDay Proof
SCI Photo Chat 3.4.9 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in SCI Photo Chat Server 3.4.9 allows remote attackers to execute arbitrary web
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - Utility Manager All-in-One (MS04-019)
Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which all
28RISK
open ↗Exploit-DB✓ VexDay Proof
British National Corpus SARA - Remote Buffer Overflow
Buffer overflow in British National Corpus SARA (sarad) allows remote attackers to execute arbitrary code by calling the
23RISK
open ↗Exploit-DB✓ VexDay Proof
SCO Multi-channel Memorandum Distribution Facility - Multiple Vulnerabilities
Multiple unknown vulnerabilities in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow
23RISK
open ↗Exploit-DB✓ VexDay Proof
CuteNews 1.3 - Comment HTML Injection
Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in Cu
23RISK
open ↗Exploit-DB✓ VexDay Proof
Outblaze Webmail - HTML Injection
Cross-site scripting (XSS) vulnerability in Outblaze Email allows remote attackers to inject arbitrary web script or HTM
23RISK
open ↗Exploit-DB✓ VexDay Proof
Unreal Tournament 2004 - 'Secure' Remote Overflow (Metasploit)
The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier,
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Task Scheduler (XP/2000) - '.job' (MS04-022)
Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, al
35RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Fusion Database Backup - Information Disclosure
The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups direct
23RISK
open ↗Exploit-DB✓ VexDay Proof
Gallery 1.4.4 - Remote Server-Side Script Execution
The set_time_limit function in Gallery before 1.4.4_p2 deletes non-image files in a temporary directory every 30 seconds
23RISK
open ↗Exploit-DB✓ VexDay Proof
Merak Mail Server 7.4.5 - 'address.html' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
Merak Mail Server 7.4.5 - 'attachment.html?attachmentpage_text_error' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
Merak Mail Server 7.4.5 - 'calendar.html?schedule' SQL Injection
SQL injection vulnerability in calendar.html in Merak Mail Server 5.2.7 allows remote attackers to execute arbitrary SQL
23RISK
open ↗Exploit-DB✓ VexDay Proof
Merak Mail Server 7.4.5 - HTML Message Body Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
Merak Mail Server 7.4.5 - address.html Full Path Disclosure
The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sens
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - Universal Language Utility Manager (MS04-019)
Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which all
28RISK
open ↗Exploit-DB✓ VexDay Proof
Merak Mail Server 7.4.5 - 'settings.html' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - POSIX Subsystem Privilege Escalation (MS04-020)
Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which all
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT 4.0/2000 - POSIX Subsystem Local Buffer Overflow / Local Privilege Escalation (MS04-020)
The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain pa
71RISK
open ↗Exploit-DB✓ VexDay Proof
CuteNews 1.3.1 - 'show_archives.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in Cu
23RISK
open ↗Exploit-DB✓ VexDay Proof
RaXnet Cacti 0.6.x/0.8.x - 'Auth_Login.php' SQL Injection
SQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.