Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,640GitHub PoC 14,392VulnCheck XDB 8,755Nuclei 4,333Metasploit 3,478✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
http commander 4.0 - Directory Traversal
Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0 allows remote attackers t
23RISK
open ↗Exploit-DB✓ VexDay Proof
DATEV Nutzungskontrolle 2.1/2.2 - Unauthorized Access
DATEV Nutzungskontrolle 2.1 and 2.2 has insecure write permissions for critical registry keys, which allows local users
23RISK
open ↗Exploit-DB✓ VexDay Proof
Citrix Metaframe XP - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to injec
23RISK
open ↗Exploit-DB✓ VexDay Proof
Seyeon FlexWATCH Network Video Server 2.2 - Unauthorized Administrative Access
FlexWATCH Network video server 132 allows remote attackers to bypass authentication and gain administrative privileges v
23RISK
open ↗Exploit-DB✓ VexDay Proof
MLdonkey 2.5-4 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Mldonkey 2.5-4 allows remote attackers to inject arbitrary web script or HTM
23RISK
open ↗Exploit-DB✓ VexDay Proof
Tritanium Scripts Tritanium Bulletin Board 1.2.3 - Unauthorized Access
index.php in Tritanium Bulletin Board 1.2.3 allows remote attackers to read and reply to arbitrary messages by modifying
23RISK
open ↗Exploit-DB✓ VexDay Proof
BEA WebLogic 6/7/8 - InteractiveQuery.jsp Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier allows remote attacker
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ledscripts LedForums - Multiple HTML Injections
Cross-site scripting (XSS) vulnerability in index.php for Ledscripts.com LedForums Beta 1 allows remote attackers to inj
23RISK
open ↗Exploit-DB✓ VexDay Proof
BEA Tuxedo 6/7/8 and WebLogic Enterprise 4/5 - Input Validation
The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to determine the existence of files ou
23RISK
open ↗Exploit-DB✓ VexDay Proof
Serious Sam Engine 1.0.5 - Remote Denial of Service
Croteam Serious Sam demo test 2 2.1a, Serious Sam: the First Encounter 1.05, and Serious Sam: the Second Encounter 1.05
23RISK
open ↗Exploit-DB✓ VexDay Proof
E107 - 'Chatbox.php' Denial of Service
chatbox.php in e107 0.554 and 0.603 allows remote attackers to cause a denial of service (pages fail to load) via HTML i
23RISK
open ↗Exploit-DB✓ VexDay Proof
Centrinity FirstClass HTTP Server 7.1 - Directory Disclosure
Centrinity FirstClass 7.1 allows remote attackers to access sensitive information by appending search to the end of the
23RISK
open ↗Exploit-DB✓ VexDay Proof
kpopup 0.9.x - Privileged Command Execution
misc.cpp in KPopup 0.9.1 trusts the PATH variable when executing killall, which allows local users to elevate their priv
23RISK
open ↗Exploit-DB✓ VexDay Proof
Fastream NetFile 6.0.3.588 - Error Message Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Fastream NETFile Server 6.0.3.588 allows remote attackers to inject arbitrar
23RISK
open ↗Exploit-DB✓ VexDay Proof
RedHat Apache 2.0.40 - Directory Index Default Configuration Error
The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory
23RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris Runtime Linker (SPARC) - 'ld.so.1' Local Buffer Overflow
Stack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6 through 9 allows local users to gain root pri
23RISK
open ↗Exploit-DB✓ VexDay Proof
thttpd 2.2x - 'defang' Remote Buffer Overflow
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via
28RISK
open ↗Exploit-DB✓ VexDay Proof
Musicqueue 0.9/1.0/1.1 - Multiple Buffer Overrun Vulnerabilities
Buffer overflow in Musicqueue 1.2.0 allows local users to execute arbitrary code via a long language variable in the con
23RISK
open ↗Exploit-DB✓ VexDay Proof
Wireless Tools 26 (IWConfig) - ARGV Local Command Line Buffer Overflow (1)
Buffer overflow in iwconfig, when installed setuid, allows local users to execute arbitrary code via a long OUT environm
23RISK
open ↗Exploit-DB✓ VexDay Proof
SH-HTTPD 0.3/0.4 - Character Filtering Remote Information Disclosure
Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a G
23RISK
open ↗Exploit-DB✓ VexDay Proof
Wireless Tools 26 (IWConfig) - ARGV Local Command Line Buffer Overflow (3)
Buffer overflow in iwconfig, when installed setuid, allows local users to execute arbitrary code via a long OUT environm
23RISK
open ↗Exploit-DB✓ VexDay Proof
Les Visiteurs 2.0 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences
23RISK
open ↗Exploit-DB✓ VexDay Proof
Musicqueue 1.2 - SIGSEGV Signal Handler Insecure File Creation
Musicqueue 1.2.0 allows local users to overwrite arbitrary files by triggering a segmentation fault and using a symlink
23RISK
open ↗Exploit-DB✓ VexDay Proof
Symantec Norton Internet Security 2003 6.0.4.34 - Error Message Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Symantec Norton Internet Security 2003 6.0.4.34 allows remote attackers to i
23RISK
open ↗Exploit-DB✓ VexDay Proof
Chi Kien Uong Guestbook 1.51 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Chi Kien Uong Guestbook 1.51 allows remote attackers to inject arbitrary web
23RISK
open ↗Exploit-DB✓ VexDay Proof
Yahoo! Messenger 5.6 - File Transfer Buffer Overrun
Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send req
23RISK
open ↗Exploit-DB✓ VexDay Proof
thttpd 2.2x - 'defang' Remote Buffer Overflow (PoC)
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via
28RISK
open ↗Exploit-DB✓ VexDay Proof
Sun Microsystems Java Virtual Machine 1.x - Security Manager Denial of Service
Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the Cl
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000 - Messenger Service Buffer Overrun (MS03-043)
The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allow
35RISK
open ↗Exploit-DB✓ VexDay Proof
Apache cocoon 2.14/2.2 - Directory Traversal
Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows
35RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.