Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,600GitHub PoC 14,323VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
Symantec Brightmail Anti-Spam 6.0 - Unauthorized Message Disclosure
Brightmail Spamfilter 6.0 and earlier beta releases allows remote attackers to read mail from other users by modifying t
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 2.5.7 - Remote code Injection
Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote at
23RISK
open ↗Exploit-DB✓ VexDay Proof
MPlayer 1.0pre4 GUI - Filename handling Overflow
Buffer overflow in TranslateFilename for common.c in MPlayer 1.0pre4 allows remote attackers to execute arbitrary code v
28RISK
open ↗Exploit-DB✓ VexDay Proof
Netegrity IdentityMinder Web Edition 5.6 - Management Interface Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the primary and management web interfaces in Netegrity IdentityMi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Netegrity IdentityMinder Web Edition 5.6 - Null Byte Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the primary and management web interfaces in Netegrity IdentityMi
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Lotus Domino Server 6 - Web Access Remote Denial of Service
Web Access in Lotus Domino 6.5.1 allows remote attackers to cause a denial of service (server crash) via a large e-mail
23RISK
open ↗Exploit-DB✓ VexDay Proof
CuteNews 0.88/1.3 - 'example2.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in Cu
23RISK
open ↗Exploit-DB✓ VexDay Proof
McMurtrey/Whitaker & Associates Cart32 2-5 GetLatestBuilds Script - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in (1) cart32.exe or (2) c32web.exe in Cart32 shopping cart allows remote attac
23RISK
open ↗Exploit-DB✓ VexDay Proof
CGIScript.net CSFAQ 1.0 Script - Full Path Disclosure
csFAQ.cgi in csFAQ allows remote attackers to gain sensitive information via an invalid database parameter, which reveal
23RISK
open ↗Exploit-DB✓ VexDay Proof
CuteNews 0.88/1.3 - 'show_archives.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in Cu
23RISK
open ↗Exploit-DB✓ VexDay Proof
PowerPortal 1.1/1.3 - 'modules.php' Traversal Arbitrary Directory Listing
Directory traversal vulnerability in modules.php in PowerPortal 1.x allows remote attackers to list arbitrary directorie
23RISK
open ↗Exploit-DB✓ VexDay Proof
CuteNews 0.88/1.3 - 'example1.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in Cu
23RISK
open ↗Exploit-DB✓ VexDay Proof
Rlpr 2.04 - 'msg()' Remote Format String
Format string vulnerability in the msg function for rlpr daemon (rlprd) 2.0.4 allows remote attackers to execute arbitra
28RISK
open ↗Exploit-DB✓ VexDay Proof
Subversion 1.0.2 - 'svn_time_from_cstring()' Remote Overflow
Stack-based buffer overflow during the apr_time_t data conversion in Subversion 1.0.2 and earlier allows remote attacker
60RISK
open ↗Exploit-DB✓ VexDay Proof
CVS (Linux/FreeBSD) - Remote Entry Line Heap Overflow
Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows
35RISK
open ↗Exploit-DB✓ VexDay Proof
CVS - Remote Entry Line Root Heap Overflow
Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows
35RISK
open ↗Exploit-DB✓ VexDay Proof
Borland Interbase 7.x - Remote Buffer Overflow
Buffer overflow in ibserver for Firebird Database 1.0 and other versions before 1.5, and possibly other products that us
28RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.4.x/2.6.x - Assembler Inline Function Local Denial of Service
Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an inf
23RISK
open ↗Exploit-DB✓ VexDay Proof
vBulletin 3.0.1 - 'newreply.php?WYSIWYG_HTML' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in (1) newreply.php or (2) newthread.php in vBulletin 3.0.1 allows remote attac
23RISK
open ↗Exploit-DB✓ VexDay Proof
ZaireWeb Solutions NewsLetter ZWS - Administrative Interface Authentication Bypass
admin.php in Newsletter ZWS allows remote attackers to gain administrative privileges via a list_user operation with the
23RISK
open ↗Exploit-DB✓ VexDay Proof
FreeBSD 4.10/5.x - 'execve()' Unaligned Memory Access Denial of Service
FreeBSD 5.1 for the Alpha processor allows local users to cause a denial of service (crash) via an execve system call wi
23RISK
open ↗Exploit-DB✓ VexDay Proof
BT Voyager 2000 Wireless ADSL Router - SNMP Community String Information Disclosure
The BT Voyager 2000 Wireless ADSL Router has a default public SNMP community name, which allows remote attackers to obta
23RISK
open ↗Exploit-DB✓ VexDay Proof
ArbitroWeb PHP Proxy 0.5/0.6 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in ArbitroWeb 0.6 allows remote attackers to inject arbitrary script or HTML vi
23RISK
open ↗Exploit-DB✓ VexDay Proof
osTicket STS 1.2 - Attachment Remote Command Execution
osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP reques
23RISK
open ↗Exploit-DB✓ VexDay Proof
SqWebMail 4.0.4.20040524 - Email Header HTML Injection
Cross-site scripting (XSS) vulnerability in the print_header_uc function for SqWebMail 4.0.4 and earlier, and possibly 3
23RISK
open ↗Exploit-DB✓ VexDay Proof
D-Link AirPlus DI-614+ / DI-624 / DI-704 - DHCP Log HTML Injection
Cross-site scripting (XSS) vulnerability in D-Link DI-614+ SOHO router running firmware 2.30, and DI-704 SOHO router run
23RISK
open ↗Exploit-DB✓ VexDay Proof
ircd-hybrid 7.0.1 / ircd-ratbox 1.5.1/2.0 - Socket Dequeuing Denial of Service
Non-registered IRC users using (1) ircd-hybrid 7.0.1 and earlier, (2) ircd-ratbox 1.5.1 and earlier, or (3) ircd-ratbox
23RISK
open ↗Exploit-DB✓ VexDay Proof
Rlpr 2.0 - 'msg()' Multiple Vulnerabilities
Format string vulnerability in the msg function for rlpr daemon (rlprd) 2.0.4 allows remote attackers to execute arbitra
28RISK
open ↗Exploit-DB✓ VexDay Proof
phpHeaven phpMyChat 0.14.5 - 'admin.php3' Arbitrary File Access
Multiple directory traversal vulnerabilities in admin.php3 in PHPMyChat 0.14.5 allow remote attackers with administrativ
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpHeaven phpMyChat 0.14.5 - 'usersL.php3' Multiple SQL Injections
Multiple SQL injection vulnerabilities in usersL.php3 in PHPMyChat 0.14.5 allow remote attackers to execute arbitrary SQ
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.