Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
24,695 exploits
Exploit-DB✓ VexDay Proof
TikiWiki tiki-graph_formula - PHP Remote Code Execution (Metasploit)
tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f ar
60RISK
open ↗Exploit-DB✓ VexDay Proof
HP OpenView OmniBack II - Command Execution (Metasploit)
Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack c
43RISK
open ↗Exploit-DB✓ VexDay Proof
BakBone NetVault - Remote Heap Overflow (Metasploit)
Multiple buffer overflows in BakBone NetVault 6.x and 7.x allow (1) remote attackers to execute arbitrary code via a mod
50RISK
open ↗Exploit-DB✓ VexDay Proof
AwingSoft Winds3D Player 3.5 - SceneURL Download and Execute (Metasploit)
The Awingsoft Awakening Winds3D Viewer plugin 3.5.0.9 allows remote attackers to execute arbitrary programs via a SceneU
43RISK
open ↗Exploit-DB✓ VexDay Proof
CA CAM (Windows x86) - 'log_security()' Remote Stack Buffer Overflow (Metasploit)
Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1
60RISK
open ↗Exploit-DB✓ VexDay Proof
SmarterMail 7.1.3876 - Directory Traversal
Directory traversal vulnerability in FileStorageUpload.ashx in SmarterMail 7.1.3876 allows remote attackers to read arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
BoutikOne 1.0 - SQL Injection
SQL injection vulnerability in list.php in BoutikOne 1.0 allows remote attackers to execute arbitrary SQL commands via t
23RISK
open ↗Exploit-DB✓ VexDay Proof
Novell iPrint Client Browser Plugin - 'call-back-url' Remote Stack Overflow
Stack-based buffer overflow in Novell iPrint Client before 5.44 allows remote attackers to execute arbitrary code via a
50RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Restaurant Guide 1.0.0 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in the Restaurant Guide (com_restaurantguide) component 1.0.0 for Joomla! allow
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple QuickTime FLI LinePacket - Remote Code Execution
Heap-based buffer overflow in QuickTimeAuthoring.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows remote attacker
28RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Restaurant Guide 1.0.0 - Multiple Vulnerabilities
SQL injection vulnerability in the Restaurant Guide (com_restaurantguide) component 1.0.0 for Joomla! allows remote atta
23RISK
open ↗Exploit-DB✓ VexDay Proof
xt:Commerce Gambio 2008 < 2010 - 'reviews.php' Error-Based SQL Injection
SQL injection vulnerability in product_reviews_info.php in xt:Commerce Gambio 2008 allows remote attackers to execute ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
Netautor Professional 5.5 - 'login2.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in netautor/napro4/home/login2.php in CMS Digital Workroom (formerly Netautor P
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox 3.6.4 - 'Plugin' EnsureCachedAttrParamArrays Remote Code Execution
Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remot
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Excel - HFPicture Record Parsing Remote Code Execution
Buffer overflow in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary
28RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.27 < 2.6.36 (RedHat x86-64) - 'compat' Local Privilege Escalation
The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit
23RISK
open ↗Exploit-DB✓ VexDay Proof
BACnet OPC Client - Local Buffer Overflow (1)
Stack-based buffer overflow in WTclient.dll in SCADA Engine BACnet OPC Client before 1.0.25 allows user-assisted remote
50RISK
open ↗Exploit-DB✓ VexDay Proof
mojoportal - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in ProfileView.aspx in mojoPortal 2.3.4.3 and 2.3.5.1 allows remote attackers t
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel < 2.6.36-rc4-git2 (x86-64) - 'ia32syscall' Emulation Privilege Escalation
The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.36-rc4-git2 on
23RISK
open ↗Exploit-DB✓ VexDay Proof
mojoportal - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in the file manager service (Services/FileService.ashx) in mojoPortal 2.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Axigen Webmail 1.0.1 - Directory Traversal
Directory traversal vulnerability in the HTTP interface in AXIGEN Mail Server 7.4.1 for Windows allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP microcms 1.0.1 - Multiple Vulnerabilities
Directory traversal vulnerability in index.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allows re
23RISK
open ↗Exploit-DB✓ VexDay Proof
Multple I-Escorts Products - 'escorts_search.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in escorts_search.php in I-Escorts Directory Script and Agency Scrip
23RISK
open ↗Exploit-DB✓ VexDay Proof
MP3 Workstation 9.2.1.1.2 - Local Overflow (SEH)
Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedi
50RISK
open ↗Exploit-DB✓ VexDay Proof
PHP microcms 1.0.1 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in login.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mollify 1.6 - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in backend/plugin/Registration/index.php in Mollify 1.6, 1.6.5.5, and possibly
23RISK
open ↗Exploit-DB✓ VexDay Proof
eNdonesia 8.4 - SQL Injection
SQL injection vulnerability in the Publisher module in eNdonesia 8.4 allows remote attackers to execute arbitrary SQL co
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Lotus Domino iCalendar - Email Address Stack Buffer Overflow
Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server i
50RISK
open ↗Exploit-DB✓ VexDay Proof
PaysiteReviewCMS 1.1 - 'search.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in PaysiteReviewCMS 1.1 allow remote attackers to inject arbitrary w
23RISK
open ↗Exploit-DB✓ VexDay Proof
PaysiteReviewCMS - 'image.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in PaysiteReviewCMS 1.1 allow remote attackers to inject arbitrary w
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.