Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,697GitHub PoC 14,455VulnCheck XDB 8,811Nuclei 4,349Metasploit 3,488✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
SmartMail Server 2.0 - Closed Connection Denial of Service
SmartMail Server 2.0 allows remote attackers to cause a denial of service (crash) by sending data and closing the connec
23RISK
open ↗Exploit-DB✓ VexDay Proof
LPRNG html2ps 1.0 - Remote Command Execution
Unknown vulnerability in html2ps HTML/PostScript converter 1.0, when used within LPRng, allows remote attackers to execu
23RISK
open ↗Exploit-DB✓ VexDay Proof
SmartMail Server 1.0 Beta 10 - Oversized Request Denial of Service
Buffer overflow in SmartMail Server 1.0 Beta 10 allows remote attackers to cause a denial of service (crash) via a long
23RISK
open ↗Exploit-DB✓ VexDay Proof
Benjamin Lefevre Dobermann Forum 0.x - 'newtopic.php?subpath' Remote File Inclusion
Benjamin Lefevre Dobermann FORUM 0.5 and earlier allows remote attackers to remotely include and execute malicious PHP f
23RISK
open ↗Exploit-DB✓ VexDay Proof
Benjamin Lefevre Dobermann Forum 0.x - 'entete.php?subpath' Remote File Inclusion
Benjamin Lefevre Dobermann FORUM 0.5 and earlier allows remote attackers to remotely include and execute malicious PHP f
23RISK
open ↗Exploit-DB✓ VexDay Proof
Benjamin Lefevre Dobermann Forum 0.x - 'index.php?subpath' Remote File Inclusion
Benjamin Lefevre Dobermann FORUM 0.5 and earlier allows remote attackers to remotely include and execute malicious PHP f
23RISK
open ↗Exploit-DB✓ VexDay Proof
Benjamin Lefevre Dobermann Forum 0.x - 'enteteacceuil.php?subpath' Remote File Inclusion
Benjamin Lefevre Dobermann FORUM 0.5 and earlier allows remote attackers to remotely include and execute malicious PHP f
23RISK
open ↗Exploit-DB✓ VexDay Proof
MailReader.com 2.3.x - 'NPH-MR.cgi' File Disclosure
Directory traversal vulnerability in nph-mr.cgi in Mailreader.com 2.3.20 through 2.3.31 allows remote attackers to view
23RISK
open ↗Exploit-DB✓ VexDay Proof
Alt-N MDaemon 6.0.x - POP Server Buffer Overflow
Buffer overflow in MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service v
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco AS5350 - Universal Gateway Portscan Denial of Service
Cisco AS5350 IOS 12.2(11)T with access control lists (ACLs) applied and possibly with ssh running allows remote attacker
23RISK
open ↗Exploit-DB✓ VexDay Proof
SolarWinds TFTP Server Standard Edition 5.0.55 - Directory Traversal
Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to rea
28RISK
open ↗Exploit-DB✓ VexDay Proof
Mojo Mail 2.7 - Email Form Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in mojo.cgi for Mojo Mail 2.7 allows remote attackers to inject arbitrary web s
23RISK
open ↗Exploit-DB✓ VexDay Proof
SolarWinds TFTP Server Standard Edition 5.0.55 - Large UDP Packet
SolarWinds TFTP server 5.0.55 and earlier allows remote attackers to cause a denial of service (crash) via a large UDP d
28RISK
open ↗Exploit-DB✓ VexDay Proof
MyMarket 1.71 - 'Form_Header.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in form_header.php in MyMarket 1.71 allows remote attackers to inject arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Websphere Edge Server 3.6/4.0 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 all
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Websphere Edge Server 3.69/4.0 - HTTP Header Injection
Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 all
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5/6 - Cached Objects Zone Bypass
Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information o
35RISK
open ↗Exploit-DB✓ VexDay Proof
gBook 1.4 - Administrative Access
index.php in gBook 1.4 allows remote attackers to bypass authentication and gain administrative privileges by setting th
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000/NT 4.0 - RPC Service Denial of Service (1)
The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000/NT 4.0 - RPC Service Denial of Service (2)
The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (
35RISK
open ↗Exploit-DB✓ VexDay Proof
AOL Instant Messenger 4.8.2790 - Local File Execution
Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8.2790 allows remote attackers to execute arbitrary p
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP Arena PAFileDB 1.1.3/2.1.1/3.0 - 'Email To Friend' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in pafiledb.php in PHP Arena paFileDB 1.1.3 through 3.0 allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
KMMail 1.0 - E-Mail HTML Injection
Cross-site scripting (XSS) vulnerability in kmMail 1.0, 1.0a, and 1.0b allows remote attackers to inject arbitrary web s
23RISK
open ↗Exploit-DB✓ VexDay Proof
AN HTTPD 1.38/1.39/1.40/1.41 - 'SOCKS4' Buffer Overflow
Buffer overflow in AN HTTPd 1.38 through 1.4.1c allows remote attackers to execute arbitrary code via a SOCKS4 request w
23RISK
open ↗Exploit-DB✓ VexDay Proof
YaBB 1.40/1.41 - Login Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote a
23RISK
open ↗Exploit-DB✓ VexDay Proof
vBulletin 2.0/2.2.x - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in global.php in Jelsoft vBulletin 2.0.0 through 2.2.8 allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Websphere Caching Proxy 3.6/4.0 - Denial of Service
IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to cause a denial of se
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000/NT 4.0 - RPC Service Denial of Service (3)
The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000/NT 4.0 - RPC Service Denial of Service (4)
The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (
35RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco CatOS 5.x/6.1/7.3/7.4 - CiscoView HTTP Server Buffer Overflow
Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote atta
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.