Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,596cataloged exploits
36,656CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,475Referência 23,212GitHub PoC 15,164VulnCheck XDB 8,883Nuclei 4,369Metasploit 3,493✓ verified onlyrecentpopularrisk
24,695 exploits
Exploit-DB✓ VexDay Proof
Mail Manager Pro - Cross-Site Request Forgery (Change Admin Password)
Cross-site request forgery (CSRF) vulnerability in admin.php in Mail Manager Pro allows remote attackers to hijack the a
23RISK
open ↗Exploit-DB✓ VexDay Proof
AdManagerPro - Cross-Site Request Forgery (Add Admin)
Cross-site request forgery (CSRF) vulnerability in administration/admins.php in Ad Manager Pro (aka AdManagerPro) 3.0 al
23RISK
open ↗Exploit-DB✓ VexDay Proof
WSCreator 1.1 - Blind SQL Injection
SQL injection vulnerability in ADMIN/loginaction.php in WSCreator 1.1, when magic_quotes_gpc is disabled, allows remote
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ruby on Rails 2.3.5 - 'protect_from_forgery' Cross-Site Request Forgery
Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, wh
23RISK
open ↗Exploit-DB✓ VexDay Proof
Zabbix Server - Multiple Vulnerabilities
The zbx_get_next_field function in libs/zbxcommon/str.c in Zabbix Server before 1.6.8 allows remote attackers to cause a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ez Poll Hoster - Multiple Cross-Site Scripting / Cross-Site Request Forgery Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
Digital Hive - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in base.php in DigitalHive 2.0 RC2 allows remote attackers to inject arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
RM Downloader 3.0.2.1 - '.m3u' Local Stack Overflow
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpFaber CMS 1.3.36 - 'module.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in module.php in PHPFABER CMS, possibly 1.3.36, allows remote attackers to inje
23RISK
open ↗Exploit-DB✓ VexDay Proof
Uploadscript 1.0 - Multiple Vulnerabilities
Uploadscript 1.2 and earlier stores sensitive data under the web root with insufficient access control, which allows rem
23RISK
open ↗Exploit-DB✓ VexDay Proof
HP OpenView Network Node Manager (OV NNM) 7.53 - 'ovalarm.exe' CGI Remote Buffer Overflow
Stack-based buffer overflow in ovalarm.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remo
50RISK
open ↗Exploit-DB✓ VexDay Proof
gif2png 2.5.2 - Remote Buffer Overflow
Stack-based buffer overflow in gif2png.c in gif2png 2.5.3 and earlier might allow context-dependent attackers to execute
28RISK
open ↗Exploit-DB✓ VexDay Proof
XAMPP 1.7.2 - Change Administrative Password
Cross-site request forgery (CSRF) vulnerability in security/xamppsecurity.php in XAMPP 1.6.8 allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
E-Store - SQL Injection
SQL injection vulnerability in SearchResults.php in Scripts For Sites (SFS) EZ e-store allows remote attackers to execut
23RISK
open ↗Exploit-DB✓ VexDay Proof
B2C Booking Centre Systems - SQL Injection
SQL injection vulnerability in hotel_tiempolibre_ext.php in Venalsur Booking Centre Booking System for Hotels Group, whe
23RISK
open ↗Exploit-DB✓ VexDay Proof
oBlog - Persistent Cross-Site Scripting / Cross-Site Request Forgery / Admin Brute Force
Multiple cross-site request forgery (CSRF) vulnerabilities in oBlog allow remote attackers to hijack the authentication
23RISK
open ↗Exploit-DB✓ VexDay Proof
oBlog - Persistent Cross-Site Scripting / Cross-Site Request Forgery / Admin Brute Force
Multiple cross-site scripting (XSS) vulnerabilities in oBlog allow remote attackers to inject arbitrary web script or HT
23RISK
open ↗Exploit-DB✓ VexDay Proof
Nuggetz CMS 1.0 - Remote Code Execution
Directory traversal vulnerability in admin/ajaxsave.php in Nuggetz CMS 1.0, when magic_quotes_gpc is disabled, allows re
23RISK
open ↗Exploit-DB✓ VexDay Proof
Zeeways ZeeJobsite - 'basic_search_result.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in basic_search_result.php in Zeeways ZeeJobsite 3x allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Mamboleto 2.0 RC3 - Remote File Inclusion
PHP remote file inclusion vulnerability in mamboleto.php in the Fernando Soares Mamboleto (com_mamboleto) component 2.0
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP Inventory 1.2 - Authentication Bypass
SQL injection vulnerability in index.php in PHP Inventory 1.2 allows remote authenticated users to execute arbitrary SQL
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP Inventory 1.2 - Authentication Bypass
Multiple SQL injection vulnerabilities in index.php in PHP Inventory 1.2 allow (1) remote authenticated users to execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP Inventory 1.2 - Authentication Bypass
Cross-site scripting (XSS) vulnerability in index.php in PHP Inventory 1.2 allows remote attackers to inject arbitrary w
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpLDAPadmin - Local File Inclusion
Directory traversal vulnerability in cmd.php in phpLDAPadmin 1.1.0.5 allows remote attackers to include and execute arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
TestLink Test Management and Execution System - Multiple Cross-Site Scripting / Injection Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.8.5 allow remote attackers to inject arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
TestLink Test Management and Execution System - Multiple Cross-Site Scripting / Injection Vulnerabilities
Multiple SQL injection vulnerabilities in TestLink before 1.8.5 allow remote authenticated users to execute arbitrary SQ
23RISK
open ↗Exploit-DB✓ VexDay Proof
Viscacha 0.8 Gold - Persistent Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in editprofile.php in Viscacha 0.8 Gold allow remote authenticated u
23RISK
open ↗Exploit-DB✓ VexDay Proof
AlefMentor 2.0 < 5.0 - 'id' SQL Injection
Multiple SQL injection vulnerabilities in cource.php in AlefMentor 2.0 and 2.2 allow remote attackers to execute arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
Polipo 1.0.4 - Remote Memory Corruption (PoC)
Polipo 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request wi
28RISK
open ↗Exploit-DB✓ VexDay Proof
Polipo 1.0.4 - Remote Memory Corruption (PoC)
The httpClientDiscardBody function in client.c in Polipo 0.9.8, 0.9.12, 1.0.4, and possibly other versions, allows remot
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.