Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
72,034cataloged exploits
32,227CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,025GitHub PoC 13,348VulnCheck XDB 8,195Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
20,023 exploits
Referência
ActSoft DVD-Tools - 'dvdtools.ocx' Remote Buffer Overflow (PoC)
Buffer overflow in the ActSoft DVD-Tools ActiveX control (dvdtools.ocx) allows remote attackers to execute arbitrary cod
23RISK
open ↗Referência
ActSoft DVD-Tools - 'dvdtools.ocx' Remote Buffer Overflow
Buffer overflow in the ActSoft DVD-Tools ActiveX control (dvdtools.ocx) allows remote attackers to execute arbitrary cod
23RISK
open ↗Referência
CVE-2004-1444
Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via .. (d
23RISK
open ↗Referência
CVE-2017-10309
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affecte
23RISK
open ↗Referência
CVE-2012-6708
jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differen
23RISK
open ↗Referência
CVE-2012-6708
jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differen
23RISK
open ↗Referência
WOW Web On Windows ActiveX Control 2 - Remote Code Execution
Multiple insecure method vulnerabilities in the Web On Windows (WOW) ActiveX control in WOW ActiveX 2 allow remote attac
23RISK
open ↗Referência
WebYep 1.1.9 - 'webyep_sIncludePath' File Inclusion
Multiple PHP remote file inclusion vulnerabilities in WebYep 1.1.9, when register_globals is enabled, allow remote attac
23RISK
open ↗Referência
Mozilla Firefox 3.0.10 - 'KEYGEN' Remote Denial of Service
Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, application hang, and memory
23RISK
open ↗Referência
Alcatel OmniPCX Office 210/061.1 - Remote Command Execution
cgi-data/FastJSData.cgi in OmniPCX Office with Internet Access services OXO210 before 210/091.001, OXO600 before 610/014
23RISK
open ↗Referência
LeadTools Raster - Dialog File_D Object Remote Buffer Overflow (PoC)
Buffer overflow in a certain ActiveX control in LeadTools Raster Dialog File_D Object (LTRDFD14e.DLL) 14.5.0.44 allows r
23RISK
open ↗Referência
PHPStore Car Dealers - Arbitrary File Upload
Unrestricted file upload vulnerability in PHPStore Auto Classifieds allows remote authenticated users to execute arbitra
23RISK
open ↗Referência
CVE-2013-1606
Buffer overflow in the ubnt-streamer RTSP service on the Ubiquiti UBNT AirCam with airVision firmware before 1.1.6 allow
28RISK
open ↗Referência
MangoBery CMS 0.5.5 - 'quotes.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in MangoBery CMS 0.5.5 allow remote attackers to execute arbitrary PH
23RISK
open ↗Referência
CVE-2015-8357
Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users t
23RISK
open ↗Referência
CVE-2010-4051
The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows c
35RISK
open ↗Referência
CVE-2015-8357
Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users t
23RISK
open ↗Referência
CVE-2021-45092
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection vi
50RISK
open ↗Referência
CVE-2022-1631
Users Account Pre-Takeover or Users Account Takeover. in microweber/microweber
33RISK
open ↗Referência
CVE-2012-5329
Buffer overflow in TYPSoft FTP Server 1.1 allows remote authenticated users to cause a denial of service (application cr
23RISK
open ↗Referência
HP Digital Imaging 'hpqxml.dll 2.0.0.133' - Arbitrary Data Write
Absolute path traversal in a certain ActiveX control in hpqxml.dll 2.0.0.133 in Hewlett-Packard (HP) Photo Digital Imagi
23RISK
open ↗Referência
CVE-2017-8311
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an inpu
23RISK
open ↗Referência
CVE-2009-3710
RioRey RIOS 4.6.6 and 4.7.0 uses an undocumented, hard-coded username (dbadmin) and password (sq!us3r) for an SSH tunnel
23RISK
open ↗Referência
CVE-2019-15943
vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or de
23RISK
open ↗Referência
MVCnPHP 3.0 - glConf[path_libraries] Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Tony Bibbs and Vincent Furia MVCnPHP 3.0 allow remote attackers to
23RISK
open ↗Referência
CVE-2014-8826
LaunchServices in Apple OS X before 10.10.2 does not properly handle file-type metadata, which allows attackers to bypas
23RISK
open ↗Referência
CVE-2014-8826
LaunchServices in Apple OS X before 10.10.2 does not properly handle file-type metadata, which allows attackers to bypas
23RISK
open ↗Referência
CVE-2018-7736
In Z-BlogPHP 1.5.1.1740, cmd.php has XSS via the ZC_BLOG_SUBNAME parameter or ZC_UPLOAD_FILETYPE parameter. NOTE: the so
23RISK
open ↗Referência
CVE-2018-7736
In Z-BlogPHP 1.5.1.1740, cmd.php has XSS via the ZC_BLOG_SUBNAME parameter or ZC_UPLOAD_FILETYPE parameter. NOTE: the so
23RISK
open ↗Referência
CVE-2012-1614
Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.