Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,697GitHub PoC 14,455VulnCheck XDB 8,811Nuclei 4,349Metasploit 3,488✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
GoAhead Web Server 2.1.x - Error Page Cross-Site Scripting
Cross-site scripting vulnerability in GoAhead Web Server 2.1 allows remote attackers to execute script as other web user
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5/6 - OBJECT Tag Same Origin Policy Violation
Microsoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which al
28RISK
open ↗Exploit-DB✓ VexDay Proof
Fluid Dynamics Search Engine 2.0 - Cross-Site Scripting
Cross-site scripting vulnerability in search.pl for Fluid Dynamics Search Engine (FDSE) before 2.0.0.0055 allows remote
23RISK
open ↗Exploit-DB✓ VexDay Proof
HP Tru64 4.0/5.0/5.1 - _XKB_CHARSET Local Buffer Overflow
Buffer overflow in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows attackers to execute arbitrary code via a long _
28RISK
open ↗Exploit-DB✓ VexDay Proof
GoAhead Web Server 2.1.x - URL Encoded Slash Directory Traversal
Directory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL wi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 4.0.3 - Servlet Mapping Cross-Site Scripting
Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users v
28RISK
open ↗Exploit-DB✓ VexDay Proof
iPlanet Web Server 4.1 - Search Component File Disclosure
Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise S
23RISK
open ↗Exploit-DB✓ VexDay Proof
icecast server 1.3.12 - Directory Traversal Information Disclosure
Directory traversal vulnerability in the list_directory function in Icecast 1.3.12 allows remote attackers to determine
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.1.x - SoftwareUpdate Arbitrary Package Installation
SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote
23RISK
open ↗Exploit-DB✓ VexDay Proof
Working Resources BadBlue 1.7.3 - 'cleanSearchString()' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in BadBlue Personal Edition 1.7.3 allows remote attackers to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Foundation Class Library 7.0 - ISAPI Buffer Overflow
Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Cl
35RISK
open ↗Exploit-DB✓ VexDay Proof
Key Focus KF Web Server 1.0.2 - Directory Contents Disclosure
KeyFocus (KF) web server 1.0.2 allows remote attackers to list directories and read restricted files via an HTTP request
23RISK
open ↗Exploit-DB✓ VexDay Proof
Working Resources BadBlue 1.7.3 - GET Denial of Service
BadBlue server allows remote attackers to cause a denial of service (crash) via an HTTP GET request without a URI.
23RISK
open ↗Exploit-DB✓ VexDay Proof
ArGoSoft 1.8 Mail Server - Directory Traversal
Directory traversal vulnerability in webmail feature of ArGoSoft Mail Server Plus or Pro 1.8.1.5 and earlier allows remo
23RISK
open ↗Exploit-DB✓ VexDay Proof
WorldSpan Res Manager 4.1 - Malformed TCP Packet Denial of Service
Res Manager in Worldspan for Windows Gateway 4.1 allows remote attackers to cause a denial of service (crash) via a malf
23RISK
open ↗Exploit-DB✓ VexDay Proof
Nullsoft Winamp 2.80 - Automatic Update Check Buffer Overflow
Buffer overflow in the version update check for Winamp 2.80 and earlier allows remote attackers who can spoof www.winamp
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sun SunPCi II VNC Software 2.3 - Password Disclosure
SunPCi II VNC uses a weak authentication scheme, which allows remote attackers to obtain the VNC password by sniffing th
23RISK
open ↗Exploit-DB✓ VexDay Proof
HP Tru64/OSF1 DXTerm - Local Buffer Overflow
Buffer overflow in dxterm allows local users to execute arbitrary code via a long -xrm argument.
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpAuction 1/2 - Unauthorized Administrative Access
login.php for PHPAuction allows remote attackers to gain privileges via a direct call to login.php with the action param
23RISK
open ↗Exploit-DB✓ VexDay Proof
BBC Education Betsie 1.5 - Parserl.pl Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in BBC Education Text to Speech Internet Enhancer (Betsie) 1.5.11 and earlier a
23RISK
open ↗Exploit-DB✓ VexDay Proof
AnalogX Proxy 4.0 - Socks4A Buffer Overflow
Buffer overflows in AnalogX Proxy before 4.12 allows remote attackers to cause a denial of service and possibly execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
BlackBoard 5.0 - Cross-Site Scripting
Cross-site scripting vulnerabilities in Blackboard 5 allow remote attackers to execute arbitrary web script via (1) the
23RISK
open ↗Exploit-DB✓ VexDay Proof
E-Guest 1.1 - Server Side Include Arbitrary Command Execution
Cross-site scripting (XSS) vulnerability in E-Guest_sign.pl in E-Guest 1.1 allows remote attackers to inject arbitrary S
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mandrake 7/8/9 / RedHat 6.x/7 Bonobo EFSTool - Commandline Argument Buffer Overflow (1)
Buffer overflow in efstools in Bonobo, when installed setuid, allows local users to execute arbitrary code via long comm
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mandrake 7/8/9 / RedHat 6.x/7 Bonobo EFSTool - Commandline Argument Buffer Overflow (2)
Buffer overflow in efstools in Bonobo, when installed setuid, allows local users to execute arbitrary code via long comm
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mandrake 7/8/9 / RedHat 6.x/7 Bonobo EFSTool - Commandline Argument Buffer Overflow (3)
Buffer overflow in efstools in Bonobo, when installed setuid, allows local users to execute arbitrary code via long comm
23RISK
open ↗Exploit-DB✓ VexDay Proof
Macromedia JRun 3/4 - Administrative Authentication Bypass
Macromedia JRun Administration Server allows remote attackers to bypass authentication on the login form via an extra sl
28RISK
open ↗Exploit-DB✓ VexDay Proof
Summit Computer Networks Lil' HTTP Server 2 - 'URLCount.cgi' HTML Injection
Cross-site scripting vulnerability in PowerBASIC urlcount.cgi, as included in Lil' HTTP web server, allows remote attack
23RISK
open ↗Exploit-DB✓ VexDay Proof
Inktomi Traffic Server 4/5 - Traffic_Manager Path Argument Buffer Overflow
Buffer overflow in traffic_manager for Inktomi Traffic Server 4.0.18 through 5.2.2, Traffic Edge 1.1.2 and 1.5.0, and Me
23RISK
open ↗Exploit-DB✓ VexDay Proof
WU-IMAP 2000.287(1-2) - Remote Overflow
Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.