Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,534GitHub PoC 13,654VulnCheck XDB 8,213Nuclei 4,218Metasploit 3,464✓ verified onlyrecentpopularrisk
21,534 exploits
Referência
CVE-2015-5353
Directory traversal vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to include and execute arbitrary lo
23RISK
open ↗Referência
CVE-2015-5353
Directory traversal vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to include and execute arbitrary lo
23RISK
open ↗Referência
CVE-2014-2477
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.2
38RISK
open ↗Referência
CVE-2018-4087
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchO
23RISK
open ↗Referência✓ VexDay Proof
Quantum Game Library 0.7.2c - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Quantum Game Library 0.7.2c allow remote attackers to execute arbi
28RISK
open ↗Referência✓ VexDay Proof
HydraIrc 0.3.164 - Remote Denial of Service
HydraIRC 0.3.164 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and applicat
23RISK
open ↗Referência
CVE-2017-6192
Buffer overflow in APNGDis 2.8 and earlier allows a remote attackers to cause denial of service and possibly execute arb
23RISK
open ↗Referência
CVE-2017-6192
Buffer overflow in APNGDis 2.8 and earlier allows a remote attackers to cause denial of service and possibly execute arb
23RISK
open ↗Referência✓ VexDay Proof
D-Link MPEG4 SHM Audio Control - 'VAPGDecoder.dll 1.7.0.5' Remote Buffer Overflow
Stack-based buffer overflow in VATDecoder.VatCtrl.1 ActiveX control in (1) 4xem VatCtrl Class (VATDecoder.dll 1.0.0.27 a
23RISK
open ↗Referência✓ VexDay Proof
Maxum Rumpus 6.0 - Multiple Remote Buffer Overflow Vulnerabilities
Multiple buffer overflows in Rumpus before 6.0.1 allow remote attackers to (1) cause a denial of service (segmentation f
23RISK
open ↗Referência✓ VexDay Proof
Mini-stream Ripper - '.m3u' Local Stack Overflow (PoC)
Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long U
23RISK
open ↗Referência
CVE-2010-0607
Cross-site scripting (XSS) vulnerability in Forms/status_statistics_1 in the Sterlite SAM300 AX Router allows remote att
23RISK
open ↗Referência
CVE-2023-36346
POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parame
38RISK
open ↗Referência
CVE-2010-0610
Multiple SQL injection vulnerabilities in the Photoblog (com_photoblog) component for Joomla! allow remote attackers to
23RISK
open ↗Referência
CVE-2010-0610
Multiple SQL injection vulnerabilities in the Photoblog (com_photoblog) component for Joomla! allow remote attackers to
23RISK
open ↗Referência
CVE-2010-0611
Multiple SQL injection vulnerabilities in adminlogin.php in Baal Systems 3.8 and earlier allow remote attackers to execu
23RISK
open ↗Referência
CVE-2016-1001
Heap-based buffer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows an
28RISK
open ↗Referência
CVE-2014-2994
Stack-based buffer overflow in Acunetix Web Vulnerability Scanner (WVS) 8 build 20120704 allows remote attackers to exec
28RISK
open ↗Referência
CVE-2010-0611
Multiple SQL injection vulnerabilities in adminlogin.php in Baal Systems 3.8 and earlier allow remote attackers to execu
23RISK
open ↗Referência✓ VexDay Proof
gCards 1.45 - Multiple Vulnerabilities
Directory traversal vulnerability in inc/setLang.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
Pi3Web 2.0.3 - 'ISAPI' Remote Denial of Service
Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi
43RISK
open ↗Referência✓ VexDay Proof
Mini-stream Ripper 3.0.1.1 - '.m3u' Universal Stack Overflow
Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long U
23RISK
open ↗Referência
CVE-2010-0631
Multiple SQL injection vulnerabilities in index.php in Eicra Car Rental-Script, when the plugin_id parameter is 4, allow
23RISK
open ↗Referência
CVE-2010-0632
SQL injection vulnerability in the Parkview Consultants SimpleFAQ (com_simplefaq) component for Joomla! allows remote at
23RISK
open ↗Referência
CVE-2010-0632
SQL injection vulnerability in the Parkview Consultants SimpleFAQ (com_simplefaq) component for Joomla! allows remote at
23RISK
open ↗Referência
CVE-2010-0642
Cisco Collaboration Server (CCS) 5 allows remote attackers to read the source code of JHTML files via URL encoded charac
23RISK
open ↗Referência
CVE-2021-25160
A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in v
23RISK
open ↗Referência✓ VexDay Proof
0irc-client 1345 build20060823 - Denial of Service
0irc 1345 build 20060823 allows remote attackers to cause a denial of service (application crash) by operating an IRC se
23RISK
open ↗Referência
CVE-2013-5639
Directory traversal vulnerability in users/login.php in Gnew 2013.1 and earlier allows remote attackers to read arbitrar
23RISK
open ↗Referência
CVE-2013-5639
Directory traversal vulnerability in users/login.php in Gnew 2013.1 and earlier allows remote attackers to read arbitrar
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.