Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,600GitHub PoC 14,323VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
Linksys - DHCP Information Disclosure
DHCP on Linksys BEFSR11, BEFSR41, BEFSR81, and BEFSRU31 Cable/DSL Routers, firmware version 1.45.7, does not properly cl
23RISK
open ↗Exploit-DB✓ VexDay Proof
e107 website system 0.6 - 'email article to a friend' Feature Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary web script
23RISK
open ↗Exploit-DB✓ VexDay Proof
e107 website system 0.6 - 'usersettings.php?avmsg' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary web script
23RISK
open ↗Exploit-DB✓ VexDay Proof
Land Down Under - BBCode HTML Injection
Cross-site scripting (XSS) vulnerability in Land Down Under (LDU) before LDU 700 allows remote attackers to inject arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
jPORTAL 2.2.1 - 'print.php' SQL Injection
SQL injection vulnerability in the art_print function in print.inc.php in unknown versions of jPortal before 2.3.1 allow
23RISK
open ↗Exploit-DB✓ VexDay Proof
MiniShare 1.3.2 - Remote Denial of Service
MiniShare 1.3.2 allows remote attackers to cause a denial of service (crash) via a malformed HTTP GET or HEAD request wi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Orenosv HTTP/FTP Server 0.5.9 - GET Denial of Service (1)
Orenosv 0.5.9f allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.
23RISK
open ↗Exploit-DB✓ VexDay Proof
cPanel 5 < 9 - Local Privilege Escalation
cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path optio
23RISK
open ↗Exploit-DB✓ VexDay Proof
VocalTec VGW120/VGW480 Telephony Gateway Remote H.225 - Denial of Service
Unknown vulnerability in the ASN.1/H.323/H.225 stack of VocalTec VGW120 and VGW480 allows remote attackers to cause a de
23RISK
open ↗Exploit-DB✓ VexDay Proof
Netgear RP114 3.26 - Content Filter Bypass
Netgear RP114 allows remote attackers to bypass the keyword based URL filtering by requesting a long URL, as demonstrate
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mollensoft Lightweight FTP Server 3.6 - Remote Denial of Service
Buffer overflow in Mollensoft Lightweight FTP Server 3.6 allows remote authenticated users to cause a denial of service
23RISK
open ↗Exploit-DB✓ VexDay Proof
Liferay Enterprise Portal 1.x/2.x/5.0.2 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in index.jsp for Liferay before 2.2.0 release 10/1/2004 allow remote
23RISK
open ↗Exploit-DB✓ VexDay Proof
e107 Website System 0.5/0.6 - 'Log.php' HTML Injection
Cross-site scripting (XSS) vulnerability in stats.php in e107 allows remote attackers to inject arbitrary web script or
23RISK
open ↗Exploit-DB✓ VexDay Proof
Netscape Navigator 7.1 - Embedded Image URI Obfuscation
Netscape Navigator 7.1 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified
23RISK
open ↗Exploit-DB✓ VexDay Proof
Subversion 1.0.2 - Date Overflow (Metasploit)
Stack-based buffer overflow during the apr_time_t data conversion in Subversion 1.0.2 and earlier allows remote attacker
60RISK
open ↗Exploit-DB✓ VexDay Proof
LHA 1.x - 'extract_one' Multiple Buffer Overflow Vulnerabilities
Buffer overflow in the extract_one function from lhext.c in LHA may allow attackers to execute arbitrary code via a long
28RISK
open ↗Exploit-DB✓ VexDay Proof
ActivePerl 5.x / Cygwin 1.5.x - System Function Call Buffer Overflow
ActivePerl 5.8.x and others, and Larry Wall's Perl 5.6.1 and others, when running on Windows systems, allows attackers t
23RISK
open ↗Exploit-DB✓ VexDay Proof
ActivePerl 5.x / Larry Wall Perl 5.x - Duplication Operator Integer Overflow
Integer overflow in the duplication operator in ActivePerl allows remote attackers to cause a denial of service (crash)
23RISK
open ↗Exploit-DB✓ VexDay Proof
dsm light Web file browser 2.0 - Directory Traversal
Directory traversal vulnerability in explorer.php in DSM Light Web File Browser 2.0 allows remote attackers to read arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
KDE Konqueror 3.x - Embedded Image URI Obfuscation
KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with m
23RISK
open ↗Exploit-DB✓ VexDay Proof
TurboTrafficTrader C 1.0 - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Turbo Traffic Trader C (TTT-C) 1.0 allow remote attackers to inje
23RISK
open ↗Exploit-DB✓ VexDay Proof
vBulletin 1.0/2.x/3.0 - 'index.php' User Interface Spoofing
Cross-site scripting (XSS) vulnerability in index.php in Jelsoft vBulletin allows remote attackers to spoof parts of a w
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP - Self-Executing Folder
Microsoft Windows XP Explorer allows local users to execute arbitrary code via a system folder with a Desktop.ini file c
28RISK
open ↗Exploit-DB✓ VexDay Proof
osCommerce 2.x - File Manager Directory Traversal
Directory traversal vulnerability in file_manager.php in osCommerce 2.2 allows remote attackers to view arbitrary files
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.3.x - Help Protocol Remote Code Execution
HelpViewer in Mac OS X 10.3.3 and 10.2.8 processes scripts that it did not initiate, which can allow attackers to execut
23RISK
open ↗Exploit-DB✓ VexDay Proof
WGet 1.x - Insecure File Creation Race Condition
Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being do
23RISK
open ↗Exploit-DB
HelpCenter Live! < 1.2.7 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in Help Center Live allow remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Exploit-DB
HelpCenter Live! < 1.2.7 - Multiple Vulnerabilities
Cross-Site Request Forgery (CSRF) vulnerability in Help Center Live allows remote attackers to perform actions as the ad
33RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 6.x/7.x - 'Modpath' File Inclusion
PHP remote file inclusion vulnerability in index.php in Php-Nuke 6.x through 7.3 allows remote attackers to execute arbi
23RISK
open ↗Exploit-DB
HelpCenter Live! < 1.2.7 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Help Center Live allow remote attackers to inject arbitrary web s
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.