Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,697cataloged exploits
36,715CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,475Referência 23,264GitHub PoC 15,172VulnCheck XDB 8,920Nuclei 4,373Metasploit 3,493✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
Microsoft Unicode Scripts Processor - Remote Code Execution (MS10-063)
The Uniscribe (aka new Unicode Script Processor) implementation in USP10.DLL in Microsoft Windows XP SP2 and SP3, Server
28RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component JE Guestbook 1.0 - Multiple Vulnerabilities
SQL injection vulnerability in the JE Guestbook (com_jeguestbook) component 1.0 for Joomla! allows remote attackers to e
23RISK
open ↗Exploit-DB✓ VexDay Proof
MODx manager - '/controllers/default/resource/tvs.php?class_key' Traversal Local File Inclusion
Directory traversal vulnerability in manager/controllers/default/resource/tvs.php in MODx Revolution 2.0.2-pl, and possi
43RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel < 2.6.36-rc6 (RedHat / Ubuntu 10.04) - 'pktcdvd' Kernel Memory Disclosure
Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2
23RISK
open ↗Exploit-DB✓ VexDay Proof
MyPhpAuction 2010 - 'id' SQL Injection
SQL injection vulnerability in product_desc.php in MyPhpAuction 2010 allows remote attackers to execute arbitrary SQL co
23RISK
open ↗Exploit-DB✓ VexDay Proof
Webspell 4.2.1 - 'asearch.php' SQL Injection
SQL injection vulnerability in asearch.php in webSPELL 4.2.1 allows remote attackers to execute arbitrary SQL commands v
23RISK
open ↗Exploit-DB✓ VexDay Proof
MODx 2.0.2-pl - '/manager/index.php?modahsh' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in manager/index.php in MODx Revolution 2.0.2-pl allows remote attackers to inj
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Excel - SxView Record Parsing Heap Memory Corruption
Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML Fil
28RISK
open ↗Exploit-DB✓ VexDay Proof
Getsimple CMS 2.01 - 'changedata.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admin/changedata.php in GetSimple CMS 2.01 allows remote attackers to inject
23RISK
open ↗Exploit-DB✓ VexDay Proof
XFS - Deleted Inode Local Information Disclosure
The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode b
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft DNS RPC Service - 'extractQuotedChar()' Remote Overflow 'SMB' (MS07-029) (Metasploit)
Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 200
60RISK
open ↗Exploit-DB✓ VexDay Proof
PHPMyFAQ 2.6.x - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.6.9 allows remote attackers to inject arbitrary web script
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - 'Winhlp32.exe' MsgBox Code Execution (MS10-023) (Metasploit)
vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when
60RISK
open ↗Exploit-DB✓ VexDay Proof
Horde IMP Webmail 4.3.7 - 'fetchmailprefs.php' HTML Injection
Cross-site scripting (XSS) vulnerability in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Ed
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - MSHTML Findtext Processing
The Cinepak codec in Microsoft Windows XP SP2 and SP3, Windows Vista SP1 and SP2, and Windows 7 does not properly decomp
35RISK
open ↗Exploit-DB✓ VexDay Proof
Entrans - SQL Injection
SQL injection vulnerability in poll.php in Entrans 0.3.2 and earlier allows remote attackers to execute arbitrary SQL co
23RISK
open ↗Exploit-DB✓ VexDay Proof
Java - RMIConnectionImpl Deserialization Privilege Escalation (Metasploit)
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18
60RISK
open ↗Exploit-DB✓ VexDay Proof
Blue River Mura CMS - Directory Traversal
Directory traversal vulnerability in fileManager.cfc in Mura CMS 5.1 before 5.1.498 and 5.2 before 5.2.2809, and Sava CM
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Cinepak Codec CVDecompress - Heap Overflow (MS10-055)
The Cinepak codec in Microsoft Windows XP SP2 and SP3, Windows Vista SP1 and SP2, and Windows 7 does not properly decomp
35RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Illustrator CS4 14.0.0 - Postscript (.eps) Buffer Overflow (Metasploit)
Buffer overflow in Adobe Illustrator CS4 14.0.0, CS3 13.0.3 and earlier, and CS3 13.0.0 allows remote attackers to execu
60RISK
open ↗Exploit-DB✓ VexDay Proof
ProShow Gold 4.0.2549 - '.psh' Local Stack Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in Photodex ProShow Gold 4.0.2549 allow remote attackers to execute arbitrary code
50RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe - 'Doc.media.newPlayer' Use-After-Free (Metasploit) (2)
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before
100RISK
open ↗Exploit-DB✓ VexDay Proof
PointDev IDEAL Migration - Buffer Overflow (Metasploit)
Stack-based buffer overflow in Ideal Administration 2009 9.7.1, and possibly other versions, allows remote attackers to
50RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe - 'util.printf()' Local Buffer Overflow (Metasploit) (2)
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary c
100RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat - Bundled LibTIFF Integer Overflow (Metasploit)
Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a
100RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - 'newfunction' Invalid Pointer Use (Metasploit) (2)
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrob
100RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Visual Basic - '.VBP' Local Buffer Overflow (Metasploit)
Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to ex
50RISK
open ↗Exploit-DB✓ VexDay Proof
ACDSee - '.XPM' File Section Buffer Overflow (Metasploit)
Stack-based buffer overflow in the ID_X.apl plugin in ACDSee 9.0 Build 108, Pro 8.1 Build 99, and Photo Editor 4.0 Build
50RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe - FlateDecode Stream Predictor 02 Integer Overflow (Metasploit) (2)
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows rem
100RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe - U3D CLODProgressiveMeshDeclaration Array Overrun (Metasploit) (2)
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x befor
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.