Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,229cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,030VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
24,695 exploits
Exploit-DB✓ VexDay Proof
DELTAScripts PHP Links - Multiple SQL Injections
SQL injection vulnerability in admin/adm_login.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
DELTAScripts PHP Links - Multiple SQL Injections
SQL injection vulnerability in vote.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arb
23RISK
open ↗Exploit-DB✓ VexDay Proof
GNU glibc - 'strcoll()' Routine Integer Overflow
Integer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-depende
28RISK
open ↗Exploit-DB✓ VexDay Proof
SAP NetWeaver Dispatcher - DiagTraceR3Info Buffer Overflow (Metasploit)
The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispa
50RISK
open ↗Exploit-DB✓ VexDay Proof
Flogr - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Flogr 2.5.6 and earlier allow remote attackers to in
23RISK
open ↗Exploit-DB✓ VexDay Proof
Net-SNMP - SNMPD AgentX Subagent Timeout Denial of Service
Net-SNMP 5.7.1 and earlier, when AgentX is registering to handle a MIB and processing GETNEXT requests, allows remote at
23RISK
open ↗Exploit-DB✓ VexDay Proof
JBoss - DeploymentFileRepository WAR Deployment (via JMXInvokerServlet) (Metasploit)
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which
60RISK
open ↗Exploit-DB✓ VexDay Proof
Kayako Fusion - 'download.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in __swift/thirdparty/PHPExcel/PHPExcel/Shared/JAMA/docs/download.php in Kayako
23RISK
open ↗Exploit-DB✓ VexDay Proof
ThinPrint - 'tpfc.dll' Insecure Library Loading Arbitrary Code Execution
Untrusted search path vulnerability in VMware Tools in VMware Workstation before 8.0.4, VMware Player before 4.0.4, VMwa
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Photoshop CS6 - '.png' Parsing Heap Overflow
Buffer overflow in Adobe Photoshop CS6 13.x before 13.0.1 allows remote attackers to execute arbitrary code via a crafte
28RISK
open ↗Exploit-DB✓ VexDay Proof
Symantec Messaging Gateway 9.5/9.5.1 - SSH Default Password Security Bypass (Metasploit)
Symantec Messaging Gateway (SMG) before 10.0 has a default password for an unspecified account, which makes it easier fo
50RISK
open ↗Exploit-DB✓ VexDay Proof
Crowbar - 'file' Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in crowbar_framework/app/views/support/index.html.haml in the Crowbar barclamp
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Download Monitor - 'dlsearch' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attac
43RISK
open ↗Exploit-DB✓ VexDay Proof
Phorum 5.2.18 - Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in the group moderation screen in the control center (control.php) in Phorum be
23RISK
open ↗Exploit-DB✓ VexDay Proof
PrestaShop 1.4.7 - Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in PrestaShop before 1.4.9 allows remote attackers to inject arbitrary web scri
23RISK
open ↗Exploit-DB✓ VexDay Proof
HP Intelligent Management Center < 5.0 E0102 - UAM Buffer Overflow (Metasploit)
Stack-based buffer overflow in uam.exe in the User Access Manager (UAM) component in HP Intelligent Management Center (I
50RISK
open ↗Exploit-DB✓ VexDay Proof
Java 7 Applet - Remote Code Execution (Metasploit)
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow
100RISK
open ↗Exploit-DB✓ VexDay Proof
Java 7 Applet - Remote Code Execution (Metasploit)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - Intel x64 SYSRET (MS12-042)
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and
50RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Rational ClearQuest 8.0 - Multiple Vulnerabilities
IBM Rational ClearQuest 7.1.x through 7.1.2.7 and 8.x through 8.0.0.3 allows remote attackers to obtain potentially sens
23RISK
open ↗Exploit-DB✓ VexDay Proof
Zabbix Server - Arbitrary Command Execution (Metasploit)
The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via
50RISK
open ↗Exploit-DB✓ VexDay Proof
Websense Content Gateway - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in monitor/m_overview.ink in Websense Content Gateway before 7.7.3 a
23RISK
open ↗Exploit-DB✓ VexDay Proof
SAP NetWeaver Dispatcher 7.0 ehp1/2 - Multiple Vulnerabilities
The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver
23RISK
open ↗Exploit-DB✓ VexDay Proof
SAP NetWeaver Dispatcher 7.0 ehp1/2 - Multiple Vulnerabilities
The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0
23RISK
open ↗Exploit-DB✓ VexDay Proof
Symantec Web Gateway 5.0.3.18 - Arbitrary Password Change (Metasploit)
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to change arbitrary passwor
23RISK
open ↗Exploit-DB✓ VexDay Proof
SAP NetWeaver Dispatcher 7.0 ehp1/2 - Multiple Vulnerabilities
The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.
23RISK
open ↗Exploit-DB✓ VexDay Proof
SAP NetWeaver Dispatcher 7.0 ehp1/2 - Multiple Vulnerabilities
The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver
23RISK
open ↗Exploit-DB✓ VexDay Proof
SAP NetWeaver Dispatcher 7.0 ehp1/2 - Multiple Vulnerabilities
The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispa
50RISK
open ↗Exploit-DB✓ VexDay Proof
Symantec Web Gateway 5.0.3.18 - Arbitrary Password Change
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to change arbitrary passwor
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.