Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,464Referência 22,936GitHub PoC 15,010VulnCheck XDB 8,846Nuclei 4,361Metasploit 3,490✓ verified onlyrecentpopularrisk
24,695 exploits
Exploit-DB✓ VexDay Proof
OpenMediaVault Cron - Remote Command Execution (Metasploit)
The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users
68RISK
open ↗Exploit-DB✓ VexDay Proof
Moodle - Remote Command Execution (Metasploit)
Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell
50RISK
open ↗Exploit-DB✓ VexDay Proof
vTiger CRM 5.3.0 5.4.0 - (Authenticated) Remote Code Execution (Metasploit)
vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability
50RISK
open ↗Exploit-DB✓ VexDay Proof
ISPConfig - (Authenticated) Arbitrary PHP Code Execution (Metasploit)
ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution
50RISK
open ↗Exploit-DB✓ VexDay Proof
NAS4Free - Remote Code Execution (Metasploit)
NAS4Free 9.1.0.1.804 and earlier allows remote authenticated users to execute arbitrary PHP code via a request to exec.p
43RISK
open ↗Exploit-DB✓ VexDay Proof
Zabbix - (Authenticated) Remote Command Execution (Metasploit)
Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability
50RISK
open ↗Exploit-DB✓ VexDay Proof
Openbravo ERP - XML External Entity Information Disclosure
The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML
43RISK
open ↗Exploit-DB✓ VexDay Proof
Olat CMS 7.8.0.1 - Persistent Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the Calendar module in Olat 7.8.0.1 (b20130821 N1) allow remote a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache + PHP < 5.3.12 / < 5.4.2 - cgi-bin Remote Code Execution
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not
35RISK
open ↗Exploit-DB✓ VexDay Proof
Olat CMS 7.8.0.1 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Calendar module in Olat 7.8.0.1 (b20130821 N1) allows remote attackers t
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache + PHP < 5.3.12 / < 5.4.2 - cgi-bin Remote Code Execution
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not
35RISK
open ↗Exploit-DB✓ VexDay Proof
Apache + PHP < 5.3.12 / < 5.4.2 - cgi-bin Remote Code Execution
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISK
open ↗Exploit-DB✓ VexDay Proof
BlazeDVD 6.2 - '.plf' Local Buffer Overflow (SEH)
Stack-based buffer overflow in BlazeVideo BlazeDVD Standard and Professional 5.0, and possibly earlier, allows remote at
50RISK
open ↗Exploit-DB✓ VexDay Proof
Poppler 0.14.3 - '/utils/pdfseparate.cc' Local Format String
Format string vulnerability in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.3 allows remote
28RISK
open ↗Exploit-DB✓ VexDay Proof
Open Flash Chart 2 - Arbitrary File Upload (Metasploit)
Multiple cross-site scripting (XSS) vulnerabilities in iTop (aka IT Operations Portal) 1.1.181 and 1.2.0-RC-282 allow re
23RISK
open ↗Exploit-DB✓ VexDay Proof
Open Flash Chart 2 - Arbitrary File Upload (Metasploit)
Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer
60RISK
open ↗Exploit-DB✓ VexDay Proof
Interactive Graphical SCADA System - Remote Command Injection (Metasploit)
Directory traversal vulnerability in dc.exe 9.00.00.11059 and earlier in 7-Technologies Interactive Graphical SCADA Syst
50RISK
open ↗Exploit-DB✓ VexDay Proof
HP Intelligent Management Center BIms UploadServlet - Directory Traversal (Metasploit)
Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Soft
50RISK
open ↗Exploit-DB✓ VexDay Proof
Apache Shindig - XML External Entity Information Disclosure
The gadget renderer in Apache Shindig 2.5.0 for PHP allows remote attackers to obtain sensitive information via an XML d
28RISK
open ↗Exploit-DB✓ VexDay Proof
ZonPHP 2.25 - Remote Code Execution
Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer
60RISK
open ↗Exploit-DB✓ VexDay Proof
ZonPHP 2.25 - Remote Code Execution
Multiple cross-site scripting (XSS) vulnerabilities in iTop (aka IT Operations Portal) 1.1.181 and 1.2.0-RC-282 allow re
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - CDisplayPointer Use-After-Free (MS13-080) (Metasploit)
Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allo
100RISK
open ↗Exploit-DB✓ VexDay Proof
HP Data Protector - Cell Request Service Buffer Overflow (Metasploit)
Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arb
60RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle GlassFish Server 2.1.1/3.0.1 - Multiple Subcomponent Resource Identifier Traversal Arbitrary File Access
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2;
50RISK
open ↗Exploit-DB✓ VexDay Proof
D-Link / PLANEX COMMUNICATIONS - 'RuntimeDiagnosticPing()' Remote Stack Buffer Overflow
Stack-based buffer overflow in the RuntimeDiagnosticPing function in /bin/webs on D-Link DIR-100 routers might allow rem
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Cart66 1.5.1.14 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in products.php in the Cart66 Lite plugin before 1.5.1.15 for WordPr
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Cart66 1.5.1.14 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in Cart66Product.php in the Cart66 Lite plugin before 1.5.1.15 for WordP
23RISK
open ↗Exploit-DB✓ VexDay Proof
VMware Hyperic HQ Groovy Script-Console - Java Execution (Metasploit)
The Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary cod
23RISK
open ↗Exploit-DB✓ VexDay Proof
vBulletin 4.1.x - '/install/upgrade.php' Security Bypass
The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the
50RISK
open ↗Exploit-DB✓ VexDay Proof
Fortinet FortiAnalyzer - Cross-Site Request Forgery
cgi-bin/module//sysmanager/admin/SYSAdminUserDialog in Fortinet FortiAnalyzer before 5.0.5 does not properly validate th
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.