Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,781cataloged exploits
36,771CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,475Referência 23,305GitHub PoC 15,197VulnCheck XDB 8,932Nuclei 4,379Metasploit 3,493✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
Apache (Windows x86) - Chunked Encoding (Metasploit)
Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possi
60RISK
open ↗Exploit-DB✓ VexDay Proof
Sijio Community Software - SQL Injection / Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Sijio Community Software allows remote authenticated users to inject arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sijio Community Software - SQL Injection / Persistent Cross-Site Scripting
SQL injection vulnerability in gallery/index.php in Sijio Community Software allows remote attackers to execute arbitrar
23RISK
open ↗Exploit-DB✓ VexDay Proof
Simple Document Management System - SQL Injection
SQL injection vulnerability in detail.php in Simple Document Management System (SDMS) allows remote attackers to execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
Alt-N SecurityGateway 1.0.1 - 'Username' Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in SecurityGateway.dll in Alt-N Technologies SecurityGateway 1.0.1 allows remote attackers t
60RISK
open ↗Exploit-DB✓ VexDay Proof
Sijio Community Software - SQL Injection / Persistent Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Sijio Community Software allow remote authenticated users to inje
23RISK
open ↗Exploit-DB✓ VexDay Proof
Lyrics 3.0 - Engine SQL Injection
SQL injection vulnerability in index.php in RightInPoint Lyrics Script 3.0 allows remote attackers to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
BS Business Directory - 'articlesdetails.php' SQL Injection
SQL injection vulnerability in articlesdetails.php in BrotherScripts (BS) Business Directory allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Bladecenter Management - Multiple Web Application Vulnerabilities
The IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Bladecenter Management - Multiple Web Application Vulnerabilities
Directory traversal vulnerability in private/file_management.php on the IBM BladeCenter with Advanced Management Module
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component AutarTimonial 1.0.8 - SQL Injection
SQL injection vulnerability in the AutarTimonial (com_autartimonial) component 1.0.8 for Joomla! allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX EvoCam Web Server (Snow Leopard) - ROP Remote Overflow
Buffer overflow in the web server for EvoLogical EvoCam 3.6.6 and 3.6.7 allows remote attackers to execute arbitrary cod
50RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Bladecenter Management - Multiple Web Application Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities on the IBM BladeCenter with Advanced Management Module (AMM) firmwar
23RISK
open ↗Exploit-DB✓ VexDay Proof
Bs Recipes_Website Script - SQL Injection / Authentication Bypass
SQL injection vulnerability in recipedetail.php in BrotherScripts Recipe Website allows remote attackers to execute arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Orbis CMS 1.0.2 - 'editor-body.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admin/editors/text/editor-body.php in Orbis CMS 1.0.2 allows remote attacker
23RISK
open ↗Exploit-DB✓ VexDay Proof
WikiWebHelp 0.28 - SQL Injection
SQL injection vulnerability in handlers/getpage.php in Wiki Web Help 0.28 allows remote attackers to execute arbitrary S
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Canteen 1.0 - Local File Inclusion
SQL injection vulnerability in menu.php in the Canteen (com_canteen) component 1.0 for Joomla! allows remote attackers t
43RISK
open ↗Exploit-DB✓ VexDay Proof
NewsOffice 2.0.18 - 'news_show.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in news_show.php in Newanz NewsOffice 2.0.18 allows remote attackers to inject
23RISK
open ↗Exploit-DB✓ VexDay Proof
TCW PHP Album - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in photos/index.php in TCW PHP Album 1.0 allows remote attackers to inject arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
TCW PHP Album - Multiple Vulnerabilities
SQL injection vulnerability in photos/index.php in TCW PHP Album 1.0 allows remote attackers to execute arbitrary SQL co
23RISK
open ↗Exploit-DB✓ VexDay Proof
Esoftpro Online Photo Pro 2 - Multiple Vulnerabilities
SQL injection vulnerability in index.php in esoftpro Online Photo Pro 2.0 allows remote attackers to execute arbitrary S
23RISK
open ↗Exploit-DB✓ VexDay Proof
freeFTPd 1.0 - 'Username' Remote Overflow (Metasploit)
Stack-based buffer overflow in freeFTPd before 1.0.9 with Logging enabled, allows remote attackers to cause a denial of
60RISK
open ↗Exploit-DB✓ VexDay Proof
QuickTime Streaming Server - 'parse_xml.cgi' Remote Execution (Metasploit)
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote a
50RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'srv2.sys' SMB Negotiate ProcessID Function Table Dereference (MS09-050) (Metasploit)
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISK
open ↗Exploit-DB✓ VexDay Proof
Snort Back Orifice - Pre-Preprocessor Remote (Metasploit)
Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to exec
60RISK
open ↗Exploit-DB✓ VexDay Proof
The Matt Wright Guestbook.pl - Arbitrary Command Execution (Metasploit)
guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remo
60RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Core 1.5.1.3 - 'cache_lastpostdate' Arbitrary Code Execution (Metasploit)
Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP co
50RISK
open ↗Exploit-DB✓ VexDay Proof
Borland Interbase - 'INET_connect()' Remote Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RISK
open ↗Exploit-DB✓ VexDay Proof
TWiki History TWikiUsers - 'rev' Command Execution (Metasploit)
The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary co
60RISK
open ↗Exploit-DB✓ VexDay Proof
Firebird Relational Database - 'isc_attach_database()' Remote Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.