Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
80,184cataloged exploits
37,029CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,476Referência 23,521GitHub PoC 15,321VulnCheck XDB 8,970Nuclei 4,394Metasploit 3,502✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
Netvolution CMS 1.0 - Cross-Site Scripting / SQL Injection
Cross-site scripting (XSS) vulnerability in ATCOM Netvolution 1.0 ASP allows remote attackers to inject arbitrary web sc
23RISK
open ↗Exploit-DB✓ VexDay Proof
DMXReady Classified Listings Manager 1.1 - SQL Injection
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Secure Document Library 1.1 and ear
23RISK
open ↗Exploit-DB✓ VexDay Proof
Dark Age CMS 0.2c Beta - Authentication Bypass
SQL injection vulnerability in login.php in Dark Age CMS 0.2c beta allows remote attackers to execute arbitrary SQL comm
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft HTML Workshop 4.74 - Universal Buffer Overflow
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included
60RISK
open ↗Exploit-DB✓ VexDay Proof
Triologic Media Player 7 - '.m3u' Local Heap Buffer Overflow (PoC)
Stack-based buffer overflow in Triologic Media Player 8.0.0.0 allows user-assisted remote attackers to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
Openfire 3.6.2 - 'group-summary.jsp' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.6.2 allow remote attackers to inject a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Openfire 3.6.2 - 'user-properties.jsp' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.6.2 allow remote attackers to inject a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Openfire 3.6.2 - 'log.jsp' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.6.2 allow remote attackers to inject a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Openfire 3.6.2 - 'log.jsp' Directory Traversal
Directory traversal vulnerability in log.jsp in Ignite Realtime Openfire 3.6.2 allows remote attackers to read arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Websphere DataPower XML Security Gateway 3.6.1 XS40 - Remote Denial of Service
The IBM WebSphere DataPower XML Security Gateway XS40 with firmware 3.6.1.5 allows remote attackers to cause a denial of
23RISK
open ↗Exploit-DB✓ VexDay Proof
QuoteBook - Remote Configuration File Disclosure
Multiple SQL injection vulnerabilities in QuoteBook allow remote attackers to execute arbitrary SQL commands via the (1)
23RISK
open ↗Exploit-DB✓ VexDay Proof
Multiple CA Service Management Products - Remote Command Execution
The smmsnmpd service in CA Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5 does not pro
35RISK
open ↗Exploit-DB✓ VexDay Proof
Plunet BusinessManager 4.1 - 'pagesUTF8/Sys_DirAnzeige.jsp?Pfad' Direct Request Information Disclosure
Plunet BusinessManager 4.1 and earlier allows remote authenticated users to bypass access restrictions and (1) read sens
23RISK
open ↗Exploit-DB✓ VexDay Proof
Plunet BusinessManager 4.1 - '/pagesUTF8/auftrag_allgemeinauftrag.jsp' Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in pagesUTF8/auftrag_allgemeinauftrag.jsp in Plunet BusinessManager 4.1 and ear
23RISK
open ↗Exploit-DB✓ VexDay Proof
Plunet BusinessManager 4.1 - 'pagesUTF8/auftrag_job.jsp?Pfad' Direct Request Information Disclosure
Plunet BusinessManager 4.1 and earlier allows remote authenticated users to bypass access restrictions and (1) read sens
23RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle 10g - SYS.LT.MERGEWORKSPACE SQL Injection
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3,
50RISK
open ↗Exploit-DB✓ VexDay Proof
Goople 1.8.2 - 'FrontPage.php' Blind SQL Injection
SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle 10g - SYS.LT.REMOVEWORKSPACE SQL Injection
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3,
50RISK
open ↗Exploit-DB✓ VexDay Proof
Destiny Media Player 1.61 - '.lst' Local Buffer Overflow (1)
Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code
50RISK
open ↗Exploit-DB✓ VexDay Proof
Destiny Media Player 1.61 - '.lst' Local Buffer Overflow (PoC)
Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code
50RISK
open ↗Exploit-DB✓ VexDay Proof
Destiny Media Player 1.61 - '.m3u' Local Stack Overflow
Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code
50RISK
open ↗Exploit-DB✓ VexDay Proof
Destiny Media Player 1.61 - '.m3u' Local Buffer Overflow (PoC)
Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code
50RISK
open ↗Exploit-DB✓ VexDay Proof
PHP 5.2.8 gd library - 'imageRotate()' Information Leak
Array index error in the imageRotate function in PHP 5.2.8 and earlier allows context-dependent attackers to read the co
23RISK
open ↗Exploit-DB✓ VexDay Proof
Viart shopping cart 3.5 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote att
23RISK
open ↗Exploit-DB✓ VexDay Proof
Viart shopping cart 3.5 - Multiple Vulnerabilities
ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to access the contents of an arbitrary shopping cart via a mo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Megacubo 5.0.7 - 'mega://' Arbitrary File Download and Execute
Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Safari 3.2 WebKit - 'alink' Property Memory Leak Remote Denial of Service (1)
Memory leak in WebKit.dll in WebKit, as used by Apple Safari 3.2 on Windows Vista SP1, allows remote attackers to cause
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHPFootball 1.6 - Remote Hash Disclosure
SQL injection vulnerability in login.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHPFootball 1.6 - Remote Hash Disclosure
Multiple cross-site scripting (XSS) vulnerabilities in PHPFootball 1.6 allow remote attackers to inject arbitrary web sc
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Safari 3.2 WebKit - 'alink' Property Memory Leak Remote Denial of Service (2)
Memory leak in WebKit.dll in WebKit, as used by Apple Safari 3.2 on Windows Vista SP1, allows remote attackers to cause
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.