Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,980cataloged exploits
36,899CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,476Referência 23,400GitHub PoC 15,250VulnCheck XDB 8,959Nuclei 4,393Metasploit 3,502✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
Quick.Cart 3.4 / Quick.CMS 2.4 - Delete Function Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.Cart 3.4 allow remote attackers to hijack the authen
23RISK
open ↗Exploit-DB✓ VexDay Proof
kr-web 1.1b2 - Remote File Inclusion
PHP remote file inclusion vulnerability in adm/krgourl.php in KR-Web 1.1b2 and earlier allows remote attackers to execut
50RISK
open ↗Exploit-DB✓ VexDay Proof
outreach project tool 1.2.6 - Remote File Inclusion
PHP remote file inclusion vulnerability in forums/Forum_Include/index.php in Outreach Project Tool (OPT) 1.2.7 and earli
23RISK
open ↗Exploit-DB✓ VexDay Proof
XM Easy Personal FTP Server 5.8.0 - Remote Denial of Service
Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (daemon outage)
23RISK
open ↗Exploit-DB✓ VexDay Proof
Autodesk SoftImage Scene TOC - Arbitrary Command Execution
Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene pac
23RISK
open ↗Exploit-DB✓ VexDay Proof
Autodesk Maya Script - Nodes Arbitrary Command Execution
Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Autodesk SoftImage 7.0 Scene - '.TOC' File Remote Code Execution
Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene pac
23RISK
open ↗Exploit-DB✓ VexDay Proof
MySQL 6.0.9 - SELECT Statement WHERE Clause Sub-query Denial of Service
mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of cert
28RISK
open ↗Exploit-DB✓ VexDay Proof
MySQL 6.0.9 - 'GeomFromWKB()' Function First Argument Geometry Value Handling Denial of Service
mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of cert
28RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Com_Joomclip - 'cat' SQL Injection
SQL injection vulnerability in the JoomClip (com_joomclip) component for Joomla! allows remote attackers to execute arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Betsy CMS versions 3.5 - Local File Inclusion
Directory traversal vulnerability in admin/popup.php in Betsy CMS 3.5 allows remote attackers to include and execute arb
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cacti 0.8.x - 'graph.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7e allow remote attackers to inject arbitrary web scrip
23RISK
open ↗Exploit-DB✓ VexDay Proof
AIMP2 Audio Converter 2.53 build 330 - Playlist '.pls' Unicode Buffer Overflow
Stack-based buffer overflow in AIMP2 Audio Converter 2.53 (build 330) and earlier allows remote attackers to cause a den
28RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco VPN Client - Integer Overflow Denial of Service
The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0
23RISK
open ↗Exploit-DB✓ VexDay Proof
TEKUVA - Password Reminder Authentication Bypass
TUKEVA Password Reminder before 1.0.0.4 uses a hard-coded password for rem.accdb, which allows local users to discover c
23RISK
open ↗Exploit-DB✓ VexDay Proof
Opera Web Browser 10.01 - 'dtoa()' Remote Code Execution
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation
28RISK
open ↗Exploit-DB✓ VexDay Proof
KDE 4.3.3 - KDELibs 'dtoa()' Remote Code Execution
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation
28RISK
open ↗Exploit-DB✓ VexDay Proof
CubeCart 3.0.4/4.3.6 - 'ProductID' SQL Injection
SQL injection vulnerability in includes/content/viewProd.inc.php in CubeCart before 4.3.7 remote attackers to execute ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
SeaMonkey 1.1.8 - Remote Array Overrun
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation
28RISK
open ↗Exploit-DB✓ VexDay Proof
KDE KDELibs 4.3.3 - Remote Array Overrun
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation
28RISK
open ↗Exploit-DB✓ VexDay Proof
Opera 10.01 - Remote Array Overrun
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation
28RISK
open ↗Exploit-DB✓ VexDay Proof
K-Meleon 1.5.3 - Remote Array Overrun
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation
28RISK
open ↗Exploit-DB✓ VexDay Proof
Shoutbox 1.0 - HTML / Cross-Site Scripting Injection
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Plohni Shoutbox 1.0 allow remote attackers to inject
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Extension iF Portfolio Nexus - SQL Injection
SQL injection vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.1 for Joomla! allows remot
23RISK
open ↗Exploit-DB✓ VexDay Proof
Xerver 4.31/4.32 - HTTP Response Splitting
CRLF injection vulnerability in Xerver HTTP Server 4.31 and 4.32 allows remote attackers to inject arbitrary HTTP header
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM SolidDB - Invalid Error Code
The embedded database engine service (aka ovdbrun.exe) in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows
23RISK
open ↗Exploit-DB✓ VexDay Proof
JiRo's (Multiple Products) - '/files/login.asp' Multiple SQL Injections
Multiple SQL injection vulnerabilities in files/login.asp in JiRo's Banner System eXperience (JBSX) allow remote attacke
23RISK
open ↗Exploit-DB✓ VexDay Proof
Novell eDirectory - HTTPSTK Login Stack Overflow
Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated use
23RISK
open ↗Exploit-DB✓ VexDay Proof
ActiveBids - 'default.asp' Blind SQL Injection
Multiple SQL injection vulnerabilities in ActiveWebSoftwares Active Bids allow remote attackers to execute arbitrary SQL
23RISK
open ↗Exploit-DB✓ VexDay Proof
TelebidAuctionScript - 'aid' Blind SQL Injection
SQL injection vulnerability in allauctions.php in Telebid Auction Script allows remote attackers to execute arbitrary SQ
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.