Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,211cataloged exploits
36,421CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,464Referência 23,022GitHub PoC 15,027VulnCheck XDB 8,846Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
24,695 exploits
Exploit-DB✓ VexDay Proof
AR Web Content Manager (AWCM) - 'cookie_gen.php' Arbitrary Cookie Generation
cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to ge
23RISK
open ↗Exploit-DB✓ VexDay Proof
OrangeHRM - 'sortField' SQL Injection
Multiple SQL injection vulnerabilities in OrangeHRM 2.7.1 RC 1 allow remote authenticated administrators to execute arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cryptocat 2.0.21 Chrome Extension - 'img/keygen.gif' File Information Disclosure
Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure
28RISK
open ↗Exploit-DB✓ VexDay Proof
Cryptocat 2.0.22 - Arbitrary Script Injection
Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input
23RISK
open ↗Exploit-DB✓ VexDay Proof
EMC NetWorker - Format String (Metasploit)
Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.
50RISK
open ↗Exploit-DB✓ VexDay Proof
VeriCentre - Multiple SQL Injections
Multiple SQL injection vulnerabilities in terminal/paramedit.aspx in VeriFone VeriCentre Web Console before 2.2 build 36
23RISK
open ↗Exploit-DB✓ VexDay Proof
ZPanel 10.0.1 - Cross-Site Request Forgery / Cross-Site Scripting / SQL Injection / Password Reset
Cross-site scripting (XSS) vulnerability in ZPanel 10.0.1 and earlier allows remote attackers to inject arbitrary web sc
23RISK
open ↗Exploit-DB✓ VexDay Proof
ZPanel 10.0.1 - Cross-Site Request Forgery / Cross-Site Scripting / SQL Injection / Password Reset
ZPanel 10.0.1 has insufficient entropy for its password reset process.
23RISK
open ↗Exploit-DB✓ VexDay Proof
ZPanel 10.0.1 - Cross-Site Request Forgery / Cross-Site Scripting / SQL Injection / Password Reset
SQL injection vulnerability in ZPanel 10.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via t
23RISK
open ↗Exploit-DB✓ VexDay Proof
ZPanel 10.0.1 - Cross-Site Request Forgery / Cross-Site Scripting / SQL Injection / Password Reset
Multiple cross-site request forgery (CSRF) vulnerabilities in ZPanel 10.0.1 and earlier allow remote attackers to hijack
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin All Video Gallery 1.1 - SQL Injection
Unspecified vulnerability in the All Video Gallery (all-video-gallery) plugin before 1.2.0 for WordPress has unspecified
23RISK
open ↗Exploit-DB✓ VexDay Proof
Invision Power Board (IP.Board) 3.3.4 - 'Unserialize()' PHP Code Execution
Unspecified vulnerability in admin/sources/base/core.php in Invision Power Board (aka IPB or IP.Board) 3.1.x through 3.3
43RISK
open ↗Exploit-DB✓ VexDay Proof
SolarWinds Orion IP Address Manager (IPAM) - 'search.aspx' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in the IPAM web interface before 3.0-HotFix1 in SolarWi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Axigen Mail Server - 'Filename' Directory Traversal
Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote att
60RISK
open ↗Exploit-DB✓ VexDay Proof
Freefloat FTP Server - 'PUT' Remote Buffer Overflow
Stack-based buffer overflow in FreeFloat FTP Server 1.0 allows remote authenticated users to execute arbitrary code via
28RISK
open ↗Exploit-DB✓ VexDay Proof
HP Operations Agent - Opcode 'coda.exe' 0x34 Buffer Overflow (Metasploit)
Unspecified vulnerability in HP Operations Agent before 11.03.12 allows remote attackers to execute arbitrary code via u
50RISK
open ↗Exploit-DB✓ VexDay Proof
HP Operations Agent - Opcode 'coda.exe' 0x8c Buffer Overflow (Metasploit)
Unspecified vulnerability in HP Operations Agent before 11.03.12 allows remote attackers to execute arbitrary code via u
50RISK
open ↗Exploit-DB✓ VexDay Proof
Bitweaver 2.8.1 - Multiple Vulnerabilities
Directory traversal vulnerability in gmap/view_overlay.php in Bitweaver 2.8.1 and earlier allows remote attackers to rea
50RISK
open ↗Exploit-DB✓ VexDay Proof
subrion CMS 2.2.1 - Multiple Vulnerabilities
SQL injection vulnerability in register/ in Subrion CMS before 2.2.3 allows remote attackers to execute arbitrary SQL co
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin White Label CMS 1.5 - Cross-Site Request Forgery / Persistent Cross-Site Scripting
Cross-site request forgery (CSRF) vulnerability in wlcms-plugin.php in the White Label CMS plugin before 1.5.1 for WordP
23RISK
open ↗Exploit-DB✓ VexDay Proof
subrion CMS 2.2.1 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS 2.2.1 allow remote attackers to inject arbitrary web
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin White Label CMS 1.5 - Cross-Site Request Forgery / Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in wlcms-plugin.php in the White Label CMS plugin 1.5 for WordPress allows remo
23RISK
open ↗Exploit-DB✓ VexDay Proof
subrion CMS 2.2.1 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack
23RISK
open ↗Exploit-DB✓ VexDay Proof
subrion CMS 2.2.1 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to inject arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebTitan - 'logs-x.php' Directory Traversal
Directory traversal vulnerability in logs-x.php in SpamTitan WebTitan before 3.60 allows remote authenticated users to r
38RISK
open ↗Exploit-DB✓ VexDay Proof
OTRS 3.1 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.15, 3.0.x befor
23RISK
open ↗Exploit-DB✓ VexDay Proof
OTRS 3.1 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.14, 3.0.x befor
23RISK
open ↗Exploit-DB✓ VexDay Proof
ModSecurity - 'POST' Security Bypass
The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver ar
28RISK
open ↗Exploit-DB✓ VexDay Proof
jCore - '/admin/index.php?path' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admin/index.php in jCore before 1.0pre2 allows remote attackers to inject ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 2.0.3 - '.png' ReadAV Crash (PoC)
libpng_plugin in VideoLAN VLC media player 2.0.3 allows remote attackers to cause a denial of service (application crash
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.