Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,324cataloged exploits
36,054CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,721GitHub PoC 14,477VulnCheck XDB 8,829Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
Working Resources BadBlue 1.2.7 - Full Path Disclosure
ext.dll in BadBlue 1.02.07 Personal Edition web server allows remote attackers to determine the physical path of the ser
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adcycle 0.77/0.78 - AdLibrary.pm Session Access
AdLibrary.pm in AdCycle 0.78b allows remote attackers to gain privileges to AdCycle via a malformed Agent: header in the
23RISK
open ↗Exploit-DB✓ VexDay Proof
Marconi ASX-1000 - Administration Denial of Service
Marconi ASX-1000 ASX switches allow remote attackers to cause a denial of service in the telnet and web management inter
23RISK
open ↗Exploit-DB✓ VexDay Proof
itafrica webactive 1.0 - Directory Traversal
Directory traversal vulnerability in ITAfrica WEBactive HTTP Server 1.00 allows remote attackers to read arbitrary files
23RISK
open ↗Exploit-DB✓ VexDay Proof
caucho Technology resin 1.2 - Directory Traversal
Directory traversal vulnerability in Caucho Resin 1.2.2 allows remote attackers to read arbitrary files via a "\.." (dot
23RISK
open ↗Exploit-DB✓ VexDay Proof
thinking arts es.one 1.0 - Directory Traversal
Directory traversal vulnerability in store.cgi in Thinking Arts ES.One package allows remote attackers to read arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
John Roy Pi3Web 1.0.1 - Buffer Overflow
Buffer overflow in tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to cause a denial of service, and pos
23RISK
open ↗Exploit-DB✓ VexDay Proof
Bajie 0.78 - Arbitrary Shell Command Execution
Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell
23RISK
open ↗Exploit-DB✓ VexDay Proof
Bajie WebServer 0.78/0.90 - Remote Command Execution
UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
KICQ 1.0 - Arbitrary Command Execution
kicq IRC client 1.0.0, and possibly later versions, allows remote attackers to execute arbitrary commands via shell meta
23RISK
open ↗Exploit-DB✓ VexDay Proof
Micro Focus Cobol 4.1 - Arbitrary Command Execution
MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with inse
23RISK
open ↗Exploit-DB✓ VexDay Proof
SilverPlatter WebSPIRS 3.3.1 - File Disclosure
Directory traversal vulnerability in WebSPIRS 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) att
23RISK
open ↗Exploit-DB✓ VexDay Proof
carey internets services commerce.cgi 2.0.1 - Directory Traversal
Directory traversal vulnerability in commerce.cgi CGI program allows remote attackers to read arbitrary files via a .. (
23RISK
open ↗Exploit-DB✓ VexDay Proof
Brightstation Muscat 1.0 - Full Path Disclosure
Muscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request
23RISK
open ↗Exploit-DB✓ VexDay Proof
his software auktion 1.62 - Directory Traversal
Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot)
28RISK
open ↗Exploit-DB✓ VexDay Proof
Martin Hamilton ROADS 2.3 - File Disclosure
ROADS search.pl program allows remote attackers to read arbitrary files by specifying the file name in the form paramete
23RISK
open ↗Exploit-DB✓ VexDay Proof
Way-Board 2.0 - File Disclosure
Way-board CGI program allows remote attackers to read arbitrary files by specifying the filename in the db parameter and
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.2.x - 'sysctl()' Memory Reading
Linux kernel 2.4 and 2.2 allows local users to read kernel memory and possibly gain privileges via a negative argument t
23RISK
open ↗Exploit-DB✓ VexDay Proof
SSH 1.2.x - CRC-32 Compensation Attack Detector
CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server
35RISK
open ↗Exploit-DB✓ VexDay Proof
soft lite serverworx 3.0 - Directory Traversal
Directory traversal vulnerability in Soft Lite ServerWorx 3.00 allows remote attackers to read arbitrary files by insert
23RISK
open ↗Exploit-DB✓ VexDay Proof
aolserver 3.2 Win32 - Directory Traversal
Directory traversal vulnerability in AOLserver 3.2 and earlier allows remote attackers to read arbitrary files by insert
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 98/2000 - UDP Socket Denial of Service
Windows 98 and Windows 2000 Java clients allow remote attackers to cause a denial of service via a Java applet that open
28RISK
open ↗Exploit-DB✓ VexDay Proof
informs picserver 1.0 - Directory Traversal
Picserver web server allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTP GET request.
23RISK
open ↗Exploit-DB✓ VexDay Proof
SSH 1.2.30 - Daemon Logging Failure
SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow re
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Net.Commerce 2.0/3.x/4.x - orderdspc.d2w order_rn Option SQL Injection
orderdspc.d2w macro in IBM Net.Commerce 3.x allows remote attackers to execute arbitrary SQL queries by inserting them i
23RISK
open ↗Exploit-DB✓ VexDay Proof
Guido Frassetto SEDUM HTTP Server 2.0 - Directory Traversal
Directory traversal vulnerability in SEDUM HTTP Server 2.0 allows remote attackers to read arbitrary files via a .. (dot
28RISK
open ↗Exploit-DB✓ VexDay Proof
Heat-On HSWeb Web Server 2.0 - Full Path Disclosure
HSWeb 2.0 HTTP server allows remote attackers to obtain the physical path of the server via a request to the /cgi/ direc
23RISK
open ↗Exploit-DB✓ VexDay Proof
GoAhead Web Server 2.0/2.1 - Directory Traversal
Directory traversal vulnerability in GoAhead web server 2.1 and earlier allows remote attackers to read arbitrary files
23RISK
open ↗Exploit-DB✓ VexDay Proof
PALS Library System WebPALS 1.0 - pals-cgi Traversal Arbitrary File Read
Directory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary file
23RISK
open ↗Exploit-DB✓ VexDay Proof
PALS Library System WebPALS 1.0 - 'pals-cgi' Arbitrary Command Execution
PALS Library System pals-cgi program allows remote attackers to execute arbitrary commands via shell metacharacters in t
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.