Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
24,695 exploits
Exploit-DB✓ VexDay Proof
phpLDAPadmin 1.2.1.1 - Remote PHP Code Injection (Metasploit) (2)
The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary
50RISK
open ↗Exploit-DB✓ VexDay Proof
e107 0.7.24 - 'cmd' Remote Command Execution
Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installat
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpLDAPadmin 1.2.1.1 - Remote PHP Code Injection (1)
The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary
50RISK
open ↗Exploit-DB✓ VexDay Proof
phpLDAPadmin 1.2.1.1 - Remote PHP Code Injection (1)
Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to inject
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Win32k - Null Pointer De-reference (PoC) (MS11-077)
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, W
41RISK
open ↗Exploit-DB✓ VexDay Proof
DELL Quest One Password Manager - CAPTCHA Security Bypass
The Dell Quest One Password Manager, possibly 5.0, allows remote attackers to bypass CAPTCHA protections and obtain sens
23RISK
open ↗Exploit-DB✓ VexDay Proof
Pre Studio Business Cards Designer - SQL Injection
SQL injection vulnerability in page.php in Pre Studio Business Cards Designer allows remote attackers to execute arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
HP Power Manager - 'formExportDataLogs' Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to ex
60RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Safari Webkit - libxslt Arbitrary File Creation (Metasploit)
xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Safari Webkit - libxslt Arbitrary File Creation (Metasploit)
WebKit in Apple Safari before 5.0.6 has improper libxslt security settings, which allows remote attackers to create arbi
50RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Safari - 'file://' Arbitrary Code Execution (Metasploit)
Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers
50RISK
open ↗Exploit-DB✓ VexDay Proof
Toshiba e-Studio (Multiple Devices) - Security Bypass
The TopAccess web-based management interface on TOSHIBA TEC e-Studio multi-function peripheral (MFP) devices with firmwa
23RISK
open ↗Exploit-DB✓ VexDay Proof
vTiger CRM 5.2 - 'onlyforuser' SQL Injection
SQL injection vulnerability in the Calendar module in vTiger CRM 5.2.1 and earlier allows remote attackers to execute ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsys PROMOTIC 8.1.4 - ActiveX GetPromoticSite Unitialized Pointer
Heap-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - '.fon' Kernel-Mode Buffer Overrun (PoC) (MS11-077)
Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, W
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsys PROMOTIC 8.1.4 - ActiveX GetPromoticSite Unitialized Pointer
Stack-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox - 'Array.reduceRight()' Integer Overflow (Metasploit) (2)
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird bef
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsys PROMOTIC 8.1.4 - ActiveX GetPromoticSite Unitialized Pointer
Directory traversal vulnerability in the PmWebDir object in the web server in MICROSYS PROMOTIC before 8.1.5 allows remo
28RISK
open ↗Exploit-DB✓ VexDay Proof
PcVue 10.0 SV.UIGrdCtrl.1 - 'LoadObject()'/'SaveObject()' Trusted DWORD (Metasploit)
An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows
43RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox - 'Array.reduceRight()' Integer Overflow (1)
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird bef
60RISK
open ↗Exploit-DB✓ VexDay Proof
TugZip 3.5 Archiver - '.ZIP' File Parsing Buffer Overflow (Metasploit)
Stack-based buffer overflow in TUGzip 3.5.0.0 allows remote attackers to denial of service (crash) or execute arbitrary
50RISK
open ↗Exploit-DB✓ VexDay Proof
SilverStripe CMS 2.4.5 - Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in the process function in SSViewer.php in SilverStripe before 2.3.13 and 2.4.x
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 8 - Select Element Memory Corruption
Microsoft Internet Explorer 8 does not properly allocate and access memory, which allows remote attackers to execute arb
28RISK
open ↗Exploit-DB✓ VexDay Proof
Apache mod_proxy - Reverse Proxy Exposure
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does
60RISK
open ↗Exploit-DB✓ VexDay Proof
atvise webMI2ADS Web Server 1.0 - Multiple Vulnerabilities
Directory traversal vulnerability in the web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 allows remote at
23RISK
open ↗Exploit-DB✓ VexDay Proof
atvise webMI2ADS Web Server 1.0 - Multiple Vulnerabilities
The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 does not properly check return values from functions,
23RISK
open ↗Exploit-DB✓ VexDay Proof
OPC Systems.NET 4.00.0048 - Denial of Service
Open Automation Software OPC Systems.NET before 5.0 allows remote attackers to cause a denial of service via a malformed
23RISK
open ↗Exploit-DB✓ VexDay Proof
atvise webMI2ADS Web Server 1.0 - Multiple Vulnerabilities
The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 does not properly validate values in HTTP requests, w
23RISK
open ↗Exploit-DB✓ VexDay Proof
GoAhead Web Server 2.18 - 'addlimit.asp?url' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in GoAhead Webserver 2.18 allow remote attackers to inject arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
ACDSee FotoSlate - '.PLP' File 'id' Local Overflow (Metasploit)
Multiple stack-based buffer overflows in ACDSee FotoSlate 4.0 Build 146 allow remote attackers to execute arbitrary code
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.