Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
24,695 exploits
Exploit-DB✓ VexDay Proof
Majordomo2 - 'SMTP/HTTP' Directory Traversal
The _list_file_get function in lib/Majordomo.pm in Majordomo 2 20110203 and earlier allows remote attackers to conduct d
60RISK
open ↗Exploit-DB✓ VexDay Proof
Majordomo2 - 'SMTP/HTTP' Directory Traversal
Directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allo
60RISK
open ↗Exploit-DB✓ VexDay Proof
Tandberg E & EX & C Series Endpoints - Default Root Account Credentials
The default configuration of Cisco Tandberg C Series Endpoints, and Tandberg E and EX Personal Video units, with softwar
28RISK
open ↗Exploit-DB✓ VexDay Proof
Terminal Server Client - '.rdp' Denial of Service
Stack-based buffer overflow in the tsc_launch_remote function (src/support.c) in Terminal Server Client (tsclient) 0.150
23RISK
open ↗Exploit-DB✓ VexDay Proof
Zikula CMS 1.2.4 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to hi
23RISK
open ↗Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 0.9.4 - TiVo Buffer Overflow (Metasploit)
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RISK
open ↗Exploit-DB✓ VexDay Proof
RedaxScript 0.3.2 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in includes/password.php in Redaxscript 0.3.2 allow remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Terminal Server Client - '.rdp' Denial of Service
Multiple stack-based buffer overflows in the tsc_launch_remote function (src/support.c) in Terminal Server Client (tscli
23RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Java - Floating-Point Value Denial of Service
The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and
28RISK
open ↗Exploit-DB✓ VexDay Proof
Moodle 2.0.1 - 'PHPCOVERAGE_HOME' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Spike PHPCoverage (aka spikephpcoverage) library, as used in Moodle 2.0.
23RISK
open ↗Exploit-DB✓ VexDay Proof
OpenVAS Manager - Command Injection
The email function in manage_sql.c in OpenVAS Manager 1.0.x through 1.0.3 and 2.0.x through 2.0rc2 allows remote authent
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - MHTML Protocol Handler Cross-Site Scripting
The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Wind
45RISK
open ↗Exploit-DB✓ VexDay Proof
AWCM 2.2 Final - Local File Inclusion
Multiple directory traversal vulnerabilities in AR Web Content Manager (AWCM) 2.2 allow remote attackers to read arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
PivotX 2.2.2 - 'module_image.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in pivotx/modules/module_image.php in PivotX before 2.2.3 allows remote attacke
23RISK
open ↗Exploit-DB✓ VexDay Proof
PivotX 2.2 - '/pivotx/includes/blogroll.php?color' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in PivotX 2.2.0, and possibly other versions before 2.2.2, allow rem
23RISK
open ↗Exploit-DB✓ VexDay Proof
ActiveWeb Professional 3.0 - Arbitrary File Upload
Unrestricted file upload vulnerability in the EasyEdit module in Lomtec ActiveWeb Professional 3.0 allows remote attacke
23RISK
open ↗Exploit-DB✓ VexDay Proof
Automated Solutions Modbus/TCP OPC Server - Remote Heap Corruption (PoC)
Heap-based buffer overflow in Automated Solutions Modbus/TCP Master OPC Server before 3.0.2 allows remote attackers to c
28RISK
open ↗Exploit-DB✓ VexDay Proof
PivotX 2.2 - '/pivotx/includes/timwrapper.php?src' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in PivotX 2.2.0, and possibly other versions before 2.2.2, allow rem
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft SQL Server - sp_replwritetovarbin Memory Corruption (MS09-004) (Metasploit)
Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop
60RISK
open ↗Exploit-DB✓ VexDay Proof
Golden FTP Server 4.70 - 'PASS' Buffer Overflow
Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (
50RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin RSS Feed Reader 0.1 - 'rss_url' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in RSS Feed Reader 0.1 for WordPress allo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sun Java Web Start BasicServiceImpl - Remote Code Execution (Metasploit)
Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server - Service Relative Path Stack Corruption (MS08-067) (Metasploit)
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISK
open ↗Exploit-DB✓ VexDay Proof
phpCMS 2008 - SQL Injection
SQL injection vulnerability in include/admin/model_field.class.php in PHPCMS 2008 V2 allows remote attackers to execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpCMS 2008 - SQL Injection
SQL injection vulnerability in data.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP Lowbids - 'viewfaqs.php' Blind SQL Injection
SQL injection vulnerability in viewfaqs.php in PHP LOW BIDS allows remote attackers to execute arbitrary SQL commands vi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - CSS SetUserClip Memory Corruption (MS10-090) (Metasploit)
Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary cod
100RISK
open ↗Exploit-DB✓ VexDay Proof
Novell iPrint 5.52 - ActiveX 'GetDriverSettings()' Command Execution
Stack-based buffer overflow in an ActiveX control in ienipp.ocx in Novell iPrint Client 5.52 allows remote attackers to
50RISK
open ↗Exploit-DB✓ VexDay Proof
acpid 1.0.x - Multiple Local Denial of Service Vulnerabilities
acpid.c in acpid before 2.0.9 does not properly handle a situation in which a process has connected to acpid.socket but
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component allCineVid 1.0.0 - Blind SQL Injection
SQL injection vulnerability in the allCineVid component (com_allcinevid) 1.0.0 for Joomla! allows remote attackers to ex
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.