Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
80,646cataloged exploits
37,382CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 23,825GitHub PoC 15,392VulnCheck XDB 9,029Nuclei 4,416Metasploit 3,502✓ verified onlyrecentpopularrisk
24,482 exploits
Exploit-DB✓ VexDay Proof
WordPress Plugin White Label CMS 1.5 - Cross-Site Request Forgery / Persistent Cross-Site Scripting
Cross-site request forgery (CSRF) vulnerability in wlcms-plugin.php in the White Label CMS plugin before 1.5.1 for WordP
23RISK
open ↗Exploit-DB
Movable Type Pro 5.13en - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote a
23RISK
open ↗Exploit-DB✓ VexDay Proof
subrion CMS 2.2.1 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS 2.2.1 allow remote attackers to inject arbitrary web
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebTitan - 'logs-x.php' Directory Traversal
Directory traversal vulnerability in logs-x.php in SpamTitan WebTitan before 3.60 allows remote authenticated users to r
38RISK
open ↗Exploit-DB✓ VexDay Proof
OTRS 3.1 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.15, 3.0.x befor
23RISK
open ↗Exploit-DB✓ VexDay Proof
OTRS 3.1 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.14, 3.0.x befor
23RISK
open ↗Exploit-DB
Oracle Database - Protocol Authentication Bypass
The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 all
35RISK
open ↗Exploit-DB✓ VexDay Proof
ModSecurity - 'POST' Security Bypass
The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver ar
28RISK
open ↗Exploit-DB
Oracle WebCenter Sites (FatWire Content Server) - Multiple Vulnerabilities
Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1,
23RISK
open ↗Exploit-DB
Oracle WebCenter Sites (FatWire Content Server) - Multiple Vulnerabilities
Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1,
23RISK
open ↗Exploit-DB
Oracle WebCenter Sites (FatWire Content Server) - Multiple Vulnerabilities
Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1,
23RISK
open ↗Exploit-DB
Oracle WebCenter Sites (FatWire Content Server) - Multiple Vulnerabilities
Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1,
23RISK
open ↗Exploit-DB✓ VexDay Proof
jCore - '/admin/index.php?path' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admin/index.php in jCore before 1.0pre2 allows remote attackers to inject ar
23RISK
open ↗Exploit-DB
Samsung Kies 2.3.2.12054_20 - Multiple Vulnerabilities
Samsung Kies before 2.5.0.12094_27_11 has arbitrary file modification.
23RISK
open ↗Exploit-DB
Samsung Kies 2.3.2.12054_20 - Multiple Vulnerabilities
Samsung Kies before 2.5.0.12094_27_11 has registry modification.
23RISK
open ↗Exploit-DB
Samsung Kies 2.3.2.12054_20 - Multiple Vulnerabilities
Samsung Kies before 2.5.0.12094_27_11 has arbitrary file execution.
35RISK
open ↗Exploit-DB
Samsung Kies 2.3.2.12054_20 - Multiple Vulnerabilities
Samsung Kies before 2.5.0.12094_27_11 has arbitrary directory modification.
23RISK
open ↗Exploit-DB
EZHomeTech EzServer 7.0 - Remote Heap Corruption
A Code Execution vulnerability exists in the memcpy function when processing AMF requests in Ezhometech EzServer 7.0, wh
23RISK
open ↗Exploit-DB
Huawei Technologies Internet Mobile - Unicode (SEH)
Buffer overflow in the back-end component in Huawei UTPS 1.0 allows local users to gain privileges via a long IDS_PLUGIN
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Excel - Denial of Service
Microsoft Excel Viewer (aka Xlview.exe) and Excel in Microsoft Office 2007 (aka Office 12) allow remote attackers to cau
28RISK
open ↗Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 2.0.3 - '.png' ReadAV Crash (PoC)
libpng_plugin in VideoLAN VLC media player 2.0.3 allows remote attackers to cause a denial of service (application crash
23RISK
open ↗Exploit-DB✓ VexDay Proof
KeyHelp - ActiveX LaunchTriPane Remote Code Execution (Metasploit)
An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Pl
50RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - execCommand Use-After-Free (MS12-063) (Metasploit)
Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 al
100RISK
open ↗Exploit-DB✓ VexDay Proof
Samba 3.4.16/3.5.14/3.6.4 - SetInformationPolicy AuditEventsInfo Heap Overflow (Metasploit)
The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement valida
60RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel UDEV < 1.4.1 - 'Netlink' Local Privilege Escalation (Metasploit)
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to ga
60RISK
open ↗Exploit-DB✓ VexDay Proof
OpenX 2.8.10 - 'plugin-index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admin/plugin-index.php in OpenX 2.8.10 before revision 81823 allows remote a
23RISK
open ↗Exploit-DB✓ VexDay Proof
InduSoft Web Studio - Arbitrary File Upload / Remote Code Execution (Metasploit)
CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require au
50RISK
open ↗Exploit-DB✓ VexDay Proof
Webmin 1.580 - '/file/show.cgi' Remote Command Execution (Metasploit)
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISK
open ↗Exploit-DB✓ VexDay Proof
Avaya IP Office Customer Call Reporter - 'ImageUpload.ashx' Remote Command Execution (Metasploit)
Unrestricted file upload vulnerability in ImageUpload.ashx in the Wallboard application in Avaya IP Office Customer Call
50RISK
open ↗Exploit-DB✓ VexDay Proof
NTR - ActiveX Control 'StopModule()' Remote Code Execution (Metasploit)
The StopModule method in the NTR ActiveX control before 2.0.4.8 allows remote attackers to execute arbitrary code via a
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.