Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,697GitHub PoC 14,455VulnCheck XDB 8,811Nuclei 4,349Metasploit 3,488✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
phpMyNewsletter 0.6.10 - Remote File Inclusion
PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
SurfControl SuperScout WebFilter for Windows 2000 - SQL Injection
SQL injection vulnerabilities in the Web Reports Server for SurfControl SuperScout WebFilter allow remote attackers to e
23RISK
open ↗Exploit-DB✓ VexDay Proof
SurfControl SuperScout WebFilter for Windows 2000 - File Disclosure
Directory traversal vulnerability in the Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
Midicart PHP - Information Disclosure
MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Jetty 3.1.6/3.1.7/4.1 Servlet Engine - Arbitrary Command Execution
Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execut
23RISK
open ↗Exploit-DB✓ VexDay Proof
Py-Membres 3.1 - 'index.php' Unauthorized Access
index.php in Py-Membres 3.1 allows remote attackers to log in as an administrator by setting the pymembs parameter to "a
23RISK
open ↗Exploit-DB✓ VexDay Proof
MySimpleNews 1.0 - PHP Injection
Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code an
23RISK
open ↗Exploit-DB✓ VexDay Proof
Midicart PHP - Arbitrary File Upload
MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to a
23RISK
open ↗Exploit-DB✓ VexDay Proof
TightAuction 3.0 - Config.INC Information Disclosure
TightAuction 3.0 stores config.inc under the web document root with insufficient access control, which allows remote att
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache 1.3/2.0.x - Server Side Include Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26,
45RISK
open ↗Exploit-DB✓ VexDay Proof
MySimpleNews 1.0 - Remote Readable Administrator Password
The admin.html file in MySimple News 1.0 stores its administrative password in plaintext, which allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpWebSite 0.8.3 - 'article.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sendmail 8.12.x - SMRSH Double Pipe Access Validation
Sendmail Consortium's Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 fro
23RISK
open ↗Exploit-DB✓ VexDay Proof
Monkey HTTP Server 0.1/0.4/0.5 - Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in Monkey 0.5.0 allows remote attackers to inject arbitrary web script or HTML
23RISK
open ↗Exploit-DB✓ VexDay Proof
Rogue 5.3 - Local Buffer Overflow
Multiple buffer overflows in rogue on NetBSD 1.6 and earlier, FreeBSD 4.6, and possibly other operating systems, allows
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sun ONE Starter Kit 2.0 / ASTAware SearchDisc 3.1 - Search Engine Directory Traversal
Directory traversal vulnerability in ASTAware SearchDisk engine for Sun ONE Starter Kit 2.0 allows remote attackers to r
23RISK
open ↗Exploit-DB✓ VexDay Proof
EmuMail 5.0 - Web Root Full Path Disclosure
emumail.cgi in EMU Webmail 5.0 allows remote attackers to determine the full pathname for emumail.cgi via a malformed st
23RISK
open ↗Exploit-DB✓ VexDay Proof
EmuMail 5.0 Email Form - Script Injection
Cross-site scripting (XSS) vulnerability in emumail.cgi for EMU Webmail 5.0 allows remote attackers to inject arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
SafeTP 1.46 - Passive Mode Internal IP Address Revealing
SafeTP 1.46, when network address translation (NAT) is being used, leaks the internal IP address of the FTP server in a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Jetty 4.1 Servlet Engine - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or
23RISK
open ↗Exploit-DB✓ VexDay Proof
vBulletin 2.0.3 - 'calendar.php' Command Execution
calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in
28RISK
open ↗Exploit-DB✓ VexDay Proof
GV 2.x/3.x - '.PDF'/'.PS' File Buffer Overflow (2)
Buffer overflow in (1) gv 3.5.8 and earlier, (2) gvv 1.0.2 and earlier, (3) ggv 1.99.90 and earlier, (4) gnome-gv, and (
23RISK
open ↗Exploit-DB✓ VexDay Proof
GV 2.x/3.x - '.PDF'/'.PS' File Buffer Overflow (1)
Buffer overflow in (1) gv 3.5.8 and earlier, (2) gvv 1.0.2 and earlier, (3) ggv 1.99.90 and earlier, (4) gnome-gv, and (
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 6.0 - News Message HTML Injection
Cross-site scripting (XSS) vulnerability in PHP-Nuke 6.0 allows remote attackers to inject arbitrary web script or HTML
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpWebSite 0.8.3 - News Message HTML Injection
Cross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
DaCode 1.2 - News Message HTML Injection
Cross-site scripting (XSS) vulnerability in DaCode 1.2.0 allows remote attackers to inject arbitrary web script or HTML
23RISK
open ↗Exploit-DB✓ VexDay Proof
Monkey HTTP Server 0.1.4 - File Disclosure
Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via .. (do
23RISK
open ↗Exploit-DB✓ VexDay Proof
Drupal 4.0 - News Message HTML Injection
Cross-site scripting (XSS) vulnerability in Drupal 4.0.0 allows remote attackers to inject arbitrary web script or HTML
23RISK
open ↗Exploit-DB✓ VexDay Proof
ACWeb 1.14/1.8 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in acWEB 1.8 and 1.14 allows remote attackers to insert arbitrary HTML and web
23RISK
open ↗Exploit-DB✓ VexDay Proof
NPDS 4.8 - News Message HTML Injection
Cross-site scripting (XSS) vulnerability in NPDS 4.8 allows remote attackers to inject arbitrary web script or HTML via
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.