Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,600GitHub PoC 14,323VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
Gattaca Server 2003 POP3 - Denial of Service
POP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote authenticated users to cause a denial of service (applicatio
23RISK
open ↗Exploit-DB✓ VexDay Proof
Gattaca Server 2003 - Null Byte Full Path Disclosure
Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00"
23RISK
open ↗Exploit-DB✓ VexDay Proof
BoardPower Forum - 'ICQ.cgi' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in icq.cgi in Board Power 2.04PF allows remote attackers to inject arbitrary we
23RISK
open ↗Exploit-DB✓ VexDay Proof
Gattaca Server 2003 - 'web.tmpl?Language' CPU Consumption (Denial of Service)
Gattaca Server 2003 1.1.10.0 allows remote attackers to cause a denial of service (CPU consumption) via directory specif
23RISK
open ↗Exploit-DB✓ VexDay Proof
Gattaca Server 2003 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in web.tmpl in Gattaca Server 2003 1.1.10.0 allows remote attackers to inject a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Gattaca Server 2003 - 'Language' Path Exposure
Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00"
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP 4.x/5.0 - 'Strip_Tags()' Function Bypass
The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - Utility Manager Privilege Escalation (MS04-019)
Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which all
28RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Lotus Notes 6.0/6.5 - Multiple Java Applet Vulnerabilities
Buffer overflow in IBM Lotus Notes 6.5.x before 6.5.3 and 6.0.x before 6.0.5 allows remote attackers to cause a denial o
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Browser 0.9/1.x Cache File - Multiple Vulnerabilities
Mozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null charact
23RISK
open ↗Exploit-DB✓ VexDay Proof
Moodle Help Script 1.x - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2 and 1.4 dev allows remote attackers to inject arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
IM-Switch - Insecure Temporary File Handling Symbolic Link
im-switch before 11.4-46.1 in Fedora Core 2 allows local users to overwrite arbitrary files via a symlink attack on the
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - Remote Wscript.Shell
The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6,
35RISK
open ↗Exploit-DB✓ VexDay Proof
WebSTAR FTP Server 5.3.2 (OSX) - USER Overflow (Metasploit)
Stack-based buffer overflow in the FTP service for 4D WebSTAR 5.3.2 and earlier allows remote attackers to execute arbit
50RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1 - Popup.show Mouse Event Hijacking
Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.sho
35RISK
open ↗Exploit-DB✓ VexDay Proof
Norton AntiVirus - Denial of Service
Symantec Norton AntiVirus 2002 and 2003 allows remote attackers to cause a denial of service (CPU consumption) via a com
23RISK
open ↗Exploit-DB✓ VexDay Proof
Code-Crafters Ability Mail Server 1.18 - 'errormsg' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in _error in Ability Mail Server 1.18 allows remote attackers to inject arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpBB 2.0.x - 'viewtopic.php' PHP Script Injection
viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrase
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1 - JavaScript Method Assignment Cross-Domain Scripting
Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows
35RISK
open ↗Exploit-DB✓ VexDay Proof
MySQL 4.1/5.0 - Zero-Length Password Authentication Bypass
The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication v
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - Remote Application.Shell
Microsoft Windows Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via an embedded script
28RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla 1.7 - External Protocol Handler
Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitr
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1 - Style Tag Comment Memory Corruption
Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service
35RISK
open ↗Exploit-DB✓ VexDay Proof
Comersus Open Technologies Comersus 5.0 - 'comersus_message.asp' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_customerAuthenticateForm.asp, (2) comersus_backoffic
23RISK
open ↗Exploit-DB✓ VexDay Proof
Comersus Open Technologies Comersus 5.0 - 'comersus_gatewayPayPal.asp' Price Manipulation
comersus_gatewayPayPal.asp in Comersus Cart 5.09, and possibly other versions before 5.098, allows remote attackers to c
23RISK
open ↗Exploit-DB✓ VexDay Proof
Jaws 0.2/0.3 - 'action' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Jaws 0.3 allows remote attackers to inject arbitrary web script
23RISK
open ↗Exploit-DB✓ VexDay Proof
Jaws 0.2/0.3 - Cookie Manipulation Authentication Bypass
Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie se
23RISK
open ↗Exploit-DB✓ VexDay Proof
Jaws 0.2/0.3 - 'gadget' Traversal Arbitrary File Access
Directory traversal vulnerability in index.php in Jaws 0.3 BETA allows remote attackers to view arbitrary files via a ..
23RISK
open ↗Exploit-DB✓ VexDay Proof
Symantec Brightmail Anti-Spam 6.0 - Unauthorized Message Disclosure
Brightmail Spamfilter 6.0 and earlier beta releases allows remote attackers to read mail from other users by modifying t
23RISK
open ↗Exploit-DB✓ VexDay Proof
12Planet Chat Server 2.9 - Cross-Site Scripting
Cross-site scripting (XSS) in one2planet.infolet.InfoServlet in 12Planet Chat Server 2.9 allows remote attackers to exec
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.