Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
24,695 exploits
Exploit-DB✓ VexDay Proof
Dede CMS - SQL Injection
Multiple SQL injection vulnerabilities in DeDeCMS, possibly 5.6, allow remote attackers to execute arbitrary SQL command
23RISK
open ↗Exploit-DB✓ VexDay Proof
Akiva WebBoard 8.x - SQL Injection
Akiva WebBoard 8.x stores passwords in plaintext, which allows local users to obtain sensitive information by reading fr
23RISK
open ↗Exploit-DB✓ VexDay Proof
Winn Guestbook 2.4.8c - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the addPost function in data/functions.php in Winn GuestBook before 2.4.8d a
23RISK
open ↗Exploit-DB✓ VexDay Proof
DIY-CMS blog mod - SQL Injection
Multiple SQL injection vulnerabilities in the blog module 1.0 for DiY-CMS allow remote attackers to execute arbitrary SQ
23RISK
open ↗Exploit-DB✓ VexDay Proof
Pligg CMS 1.1.2 - 'status' SQL Injection
SQL injection vulnerability in search.php in Pligg CMS 1.1.2 allows remote attackers to execute arbitrary SQL commands v
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 3.1.8 - KVM Local Denial of Service
The em_syscall function in arch/x86/kvm/emulate.c in the KVM implementation in the Linux kernel before 3.2.14 does not p
23RISK
open ↗Exploit-DB✓ VexDay Proof
Pligg CMS 1.1.4 - 'SERVER[php_self]' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Pligg CMS 1.1.4 allows remote attackers to inject arbitrary web script or HT
23RISK
open ↗Exploit-DB✓ VexDay Proof
CoCSoft Stream Down 6.8.0 - Universal (Metasploit)
Stack-based buffer overflow in CoCSoft Stream Down 6.8.0 allows remote web servers to execute arbitrary code via a long
50RISK
open ↗Exploit-DB✓ VexDay Proof
TelnetD encrypt_keyid - Function Pointer Overwrite
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RISK
open ↗Exploit-DB✓ VexDay Proof
Open Conference/Journal/Harvester Systems 2.3.x - Multiple Remote Code Execution Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Journal Sys
23RISK
open ↗Exploit-DB✓ VexDay Proof
Open Conference/Journal/Harvester Systems 2.3.x - Multiple Remote Code Execution Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Harvester S
23RISK
open ↗Exploit-DB✓ VexDay Proof
Open Conference/Journal/Harvester Systems 2.3.x - Multiple Remote Code Execution Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Conference
23RISK
open ↗Exploit-DB✓ VexDay Proof
SpamTitan 5.08 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in SpamTitan 5.08 and earlier allow remote attackers to inject arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
SpamTitan 5.08 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in SpamTitan 5.07 and possibly earlier allow remote attackers or aut
23RISK
open ↗Exploit-DB✓ VexDay Proof
Plone and Zope - Remote Command Execution
Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, a
60RISK
open ↗Exploit-DB✓ VexDay Proof
IrfanView - '.tiff' Image Processing Buffer Overflow
Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows
23RISK
open ↗Exploit-DB✓ VexDay Proof
Tiki Wiki CMS Groupware 8.1 - 'show_errors' HTML Injection
Cross-site scripting (XSS) vulnerability in tiki-cookie-jar.php in TikiWiki CMS/Groupware before 8.2 and LTS before 6.5
23RISK
open ↗Exploit-DB✓ VexDay Proof
IrfanView FlashPix PlugIn - Double-Free
Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the Fla
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cyberoam UTM 10 - 'tableid' SQL Injection
SQL injection vulnerability in corporate/Controller in Elitecore Technologies Cyberoam UTM before 10.01.2 build 059 allo
23RISK
open ↗Exploit-DB✓ VexDay Proof
TORCS 1.3.1 - acc Buffer Overflow
Buffer overflow in the ulSetError function in util/ulError.cxx in PLIB 1.8.5, as used in TORCS 1.3.1 and other products,
28RISK
open ↗Exploit-DB✓ VexDay Proof
PHP Booking Calendar 10e - 'page_info_message' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in details_view.php in PHP Booking Calendar 10e allows remote attackers to inje
23RISK
open ↗Exploit-DB✓ VexDay Proof
DotA OpenStats 1.3.9 - SQL Injection
SQL injection vulnerability in DotA OpenStats 1.3.9 and earlier allows remote attackers to execute arbitrary SQL command
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Safari - GdiDrawStream Blue Screen of Death
The Graphics Device Interface (GDI) in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Window
35RISK
open ↗Exploit-DB✓ VexDay Proof
PHP 5.3.8 - Remote Denial of Service
Memory leak in the timezone functionality in PHP before 5.3.9 allows remote attackers to cause a denial of service (memo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Flirt-Projekt 4.8 - 'rub' SQL Injection
SQL injection vulnerability in rub2_w.php in PHP Flirt-Projekt 4.8 and possibly earlier allows remote attackers to execu
23RISK
open ↗Exploit-DB✓ VexDay Proof
Seotoaster - SQL Injection
Multiple SQL injection vulnerabilities in the selectUserIdByLoginPass function in seotoaster_core/application/models/Log
23RISK
open ↗Exploit-DB✓ VexDay Proof
Capexweb 1.1 - SQL Injection
Multiple SQL injection vulnerabilities in servlet/capexweb.parentvalidatepassword in cApexWEB 1.1 allow remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
Splunk - Remote Command Execution
Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an envir
23RISK
open ↗Exploit-DB✓ VexDay Proof
Splunk - Remote Command Execution
mappy.py in Splunk Web in Splunk 4.2.x before 4.2.5 does not properly restrict use of the mappy command to access Python
43RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.