Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,697GitHub PoC 14,455VulnCheck XDB 8,811Nuclei 4,349Metasploit 3,488✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
XTux Server 2001.0 6.01 - Garbage Denial of Service
XTux allows remote attackers to cause a denial of service (CPU consumption) via random inputs in the initial connection.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Xerver 2.10 - Multiple Request Denial of Service Vulnerabilities
Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request
28RISK
open ↗Exploit-DB✓ VexDay Proof
Cobalt RaQ 2.0/3.0/4.0 XTR - 'MultiFileUpload.php' Authentication Bypass (2)
MultiFileUploadHandler.php in the Sun Cobalt RaQ XTR administration interface allows local users to bypass authenticatio
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cobalt RaQ 2.0/3.0/4.0 XTR - 'MultiFileUpload.php' Authentication Bypass (1)
MultiFileUploadHandler.php in the Sun Cobalt RaQ XTR administration interface allows local users to bypass authenticatio
23RISK
open ↗Exploit-DB✓ VexDay Proof
OpenSSH 2.x/3.0.1/3.0.2 - Channel Code Off-by-One
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0/5.1 - Authentication Method Disclosure
Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily
35RISK
open ↗Exploit-DB✓ VexDay Proof
ReBB 1.0 - Image Tag Cross-Agent Scripting
Cross-site scripting vulnerability in ReBB allows remote attackers to execute arbitrary Javascript and steal cookies via
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ecartis 1.0.0/0.129 a Listar - Multiple Local Buffer Overflow Vulnerabilities (1)
Buffer overflows in Ecartis (formerly Listar) 1.0.0 in snapshot 20020427 and earlier allow local users to gain privilege
23RISK
open ↗Exploit-DB✓ VexDay Proof
Galacticomm Worldgroup 3.20 - Remote Web Server Denial of Service
Buffer overflow in Galacticomm Worldgroup web server 3.20 and earlier allows remote attackers to cause a denial of servi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ecartis 1.0.0/0.129 a Listar - Multiple Local Buffer Overflow Vulnerabilities (2)
Buffer overflows in Ecartis (formerly Listar) 1.0.0 in snapshot 20020427 and earlier allow local users to gain privilege
23RISK
open ↗Exploit-DB✓ VexDay Proof
Galacticomm Worldgroup 3.20 - Remote FTP Denial of Service
Buffer overflow in Galacticomm Worldgroup FTP server 3.20 and earlier allows remote attackers to cause a denial of servi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Rit Research Labs The Bat! 1.53 - Microsoft Denial of Service Device Name Denial of Service
The Bat! 1.53d and 1.54beta, and possibly other versions, allows remote attackers to cause a denial of service (crash) v
23RISK
open ↗Exploit-DB✓ VexDay Proof
xtell 2.6.1 - User Status Remote Information Disclosure
Directory traversal vulnerability in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to r
23RISK
open ↗Exploit-DB✓ VexDay Proof
xtell 1.91.1/2.6.1 - Multiple Remote Buffer Overflow Vulnerabilities
Buffer overflows in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
BPM Studio Pro 4.2 - HTTPd Directory Traversal
Directory traversal vulnerability in the HTTP server for BPM Studio Pro 4.2 allows remote attackers to read arbitrary fi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Snitz Forums 2000 3.0/3.1/3.3 - Image Tag Cross-Agent Scripting
Cross-site scripting vulnerability in Snitz Forums 2000 3.3.03 and earlier allows remote attackers to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
Working Resources BadBlue 1.5/1.6 - Directory Traversal
Directory traversal vulnerability in BadBlue before 1.6.1 allows remote attackers to read arbitrary files via a ... (mod
35RISK
open ↗Exploit-DB✓ VexDay Proof
IkonBoard 2.17/3.0/3.1 - Image Tag Cross-Agent Scripting
Cross-site scripting vulnerability in Ikonboard 3.0.1 allows remote attackers to execute arbitrary script as other Ikonb
23RISK
open ↗Exploit-DB✓ VexDay Proof
OpenBB 1.0.x - Image Tag Cross-Agent Scripting
Cross-site scripting vulnerability in codeparse.php of Open Bulletin Board (OpenBB) 1.0.0 allows remote attackers to exe
23RISK
open ↗Exploit-DB✓ VexDay Proof
Century Software Term For Linux 6.27.869 - Command Line Buffer Overflow
Buffer overflow in Century Software TERM allows local users to gain root privileges via a long tty argument to the calli
23RISK
open ↗Exploit-DB✓ VexDay Proof
XMB Forum 1.6 pre-beta - Image Tag Script Injection
Cross-site scripting vulnerability in eXtreme message board (XMB) 1.6x and earlier allows remote attackers to execute sc
23RISK
open ↗Exploit-DB✓ VexDay Proof
Powie PForum 1.1x - 'Username' Cross-Site Scripting
Cross-site scripting vulnerability in edituser.php for pforum 1.14 and earlier allows remote attackers to execute script
23RISK
open ↗Exploit-DB✓ VexDay Proof
Squid 2.0-4 - Cache FTP Proxy URL Buffer Overflow
Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache 1.3 - Artificially Long Slash Path Directory Listing (2)
The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview in
45RISK
open ↗Exploit-DB✓ VexDay Proof
Tarantella Enterprise 3 - Symbolic Link
The installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the
23RISK
open ↗Exploit-DB✓ VexDay Proof
GNUJSP 1.0 - File Disclosure
gnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass acce
23RISK
open ↗Exploit-DB✓ VexDay Proof
Phusion WebServer 1.0 - 'URL' Remote Buffer Overflow
Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary cod
28RISK
open ↗Exploit-DB✓ VexDay Proof
Phusion WebServer 1.0 - Long URL Denial of Service
Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary cod
28RISK
open ↗Exploit-DB✓ VexDay Proof
Icecast 1.x - AVLLib Buffer Overflow
Buffer overflows in icecast 1.3.11 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET req
23RISK
open ↗Exploit-DB✓ VexDay Proof
Phusion WebServer 1.0 - Directory Traversal (1)
Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (t
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.