Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,554GitHub PoC 13,689VulnCheck XDB 8,216Nuclei 4,223Metasploit 3,464✓ verified onlyrecentpopularrisk
24,443 exploits
Exploit-DB✓ VexDay Proof
SafeNet Sentinel Protection Server 7.0 < 7.4 / Sentinel Keys Server 1.0.3 < 1.0.4 - Directory Traversal
Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.0.0 through 7.4.0 and possibly earlier version
28RISK
open ↗Exploit-DB✓ VexDay Proof
XOOPS Glossaire Module - '/modules/glossaire/glossaire-aff.php' SQL Injection
SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execut
23RISK
open ↗Exploit-DB
SPIP CMS < 2.0.23/ 2.1.22/3.0.9 - Privilege Escalation
SPIP 3.0.x before 3.0.9, 2.1.x before 2.1.22, and 2.0.x before 2.0.23 allows remote attackers to gain privileges and "ta
23RISK
open ↗Exploit-DB
HP Release Control - (Authenticated) XML External Entity (Metasploit)
Unspecified vulnerability in HP Release Control 9.x before 9.13 p3 and 9.2x before RC 9.21.0003 p1 on Windows and 9.2x b
23RISK
open ↗Exploit-DB
eGroupWare 1.8.006 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in EGroupware Enterprise Line (EPL) before 1.1.20140505, EGro
23RISK
open ↗Exploit-DB✓ VexDay Proof
RealPlayer - '.3gp' File Processing Memory Corruption
The GetGUID function in codecs/dmp4.dll in RealNetworks RealPlayer 16.0.3.51 and earlier allows remote attackers to exec
23RISK
open ↗Exploit-DB✓ VexDay Proof
Winamp - '.flv' File Processing Memory Corruption
Winamp 5.666 and earlier allows remote attackers to cause a denial of service (memory corruption and crash) via a malfor
23RISK
open ↗Exploit-DB✓ VexDay Proof
Wireshark 1.10.7 - Denial of Service (PoC)
The cairo_image_surface_get_data function in Cairo 1.10.2, as used in GTK+ and Wireshark, allows context-dependent attac
23RISK
open ↗Exploit-DB✓ VexDay Proof
CIS Manager - 'email' SQL Injection
SQL injection vulnerability in Construtiva CIS Manager allows remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Exploit-DB✓ VexDay Proof
ElasticSearch - Remote Code Execution
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execut
100RISK
open ↗Exploit-DB✓ VexDay Proof
Broadcom PIPA C211 - Sensitive Information Disclosure
cgi-bin/rpcBridge in the web interface 1.1 on Broadcom Ltd PIPA C211 rev2 does not properly restrict access, which allow
23RISK
open ↗Exploit-DB✓ VexDay Proof
Easy File Sharing Web Server 6.8 - Remote Stack Buffer Overflow
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 6.8 allows remote attackers to execute arbitrary code
60RISK
open ↗Exploit-DB
VM Turbo Operations Manager 4.5x - Directory Traversal
Directory traversal vulnerability in cgi-bin/help/doIt.cgi in VMTurbo Operations Manager before 4.6 allows remote attack
23RISK
open ↗Exploit-DB✓ VexDay Proof
EFS Easy Chat Server 3.1 - Remote Stack Buffer Overflow
chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username
60RISK
open ↗Exploit-DB✓ VexDay Proof
JetAudio 8.1.1 - '.ogg' Crash (PoC)
JetMPAd.ax in JetAudio 8.1.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted .ogg
23RISK
open ↗Exploit-DB✓ VexDay Proof
GOM Player 2.2.57.5189 - '.ogg' Crash (PoC)
GOM Media Player 2.2.57.5189 and earlier allows remote attackers to cause a denial of service (crash) via a crafted .ogg
23RISK
open ↗Exploit-DB✓ VexDay Proof
SpiceWorks 7.2.00174 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in SpiceWorks before 7.2.00195 allows remote authenticated users to inject arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - Shader Buffer Overflow (Metasploit)
Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS
60RISK
open ↗Exploit-DB✓ VexDay Proof
Yokogawa CS3000 - 'BKESimmgr.exe' Remote Buffer Overflow (Metasploit)
Yokogawa CENTUM CS 3000 Stack-based Buffer Overflow
68RISK
open ↗Exploit-DB
Skybox Security 6.3.x < 6.4.x - Multiple Information Disclosures
Skybox View Appliances with ISO 6.3.33-2.14, 6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, and 6.4.46-2.57 does not properly re
23RISK
open ↗Exploit-DB
Alienvault Open Source SIEM (OSSIM) 4.6.1 - (Authenticated) SQL Injection (Metasploit)
SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL
43RISK
open ↗Exploit-DB
Skybox Security 6.3.x < 6.4.x - Multiple Denial of Service Vulnerabilities
Skybox View Appliances with ISO 6.3.33-2.14, 6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, and 6.4.46-2.57 does not properly re
23RISK
open ↗Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 2.1.3 - '.wav' File Memory Corruption
codec\libpng_plugin.dll in VideoLAN VLC Media Player 2.1.3 allows remote attackers to cause a denial of service (crash)
23RISK
open ↗Exploit-DB
Cobbler 2.4.x < 2.6.x - Local File Inclusion
Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated us
23RISK
open ↗Exploit-DB✓ VexDay Proof
Foscam IP Camera - Predictable Credentials Security Bypass
Foscam IP camera 11.37.2.49 and other versions, when using the Foscam DynDNS option, generates credentials based on pred
28RISK
open ↗Exploit-DB✓ VexDay Proof
TOA - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in Open Assessment Technologies TAO 2.5.6 allows remote attackers to hij
23RISK
open ↗Exploit-DB✓ VexDay Proof
Collabtive 1.2 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Collabtive 1.2 allows remote authenticated users to inject arbitrary web scr
23RISK
open ↗Exploit-DB✓ VexDay Proof
Collabtive 1.2 - SQL Injection
SQL injection vulnerability in Collabtive 1.2 allows remote authenticated users to execute arbitrary SQL commands via th
23RISK
open ↗Exploit-DB✓ VexDay Proof
Caldera - '/costview2/printers.php?tr' SQL Injection
Multiple SQL injection vulnerabilities in Caldera 9.20 allow remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.