Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,559cataloged exploits
34,978CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 13,960VulnCheck XDB 8,542Nuclei 4,243Metasploit 3,472✓ verified onlyrecentpopularrisk
21,899 exploits
Referência
CVE-2010-0610
Multiple SQL injection vulnerabilities in the Photoblog (com_photoblog) component for Joomla! allow remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
ZeroCMS 1.0 Alpha - Arbitrary File Upload / SQL Injection
Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended acce
23RISK
open ↗Referência✓ VexDay Proof
QuickTime Player 7.3.1.70 - 'RTSP' Buffer Overflow (PoC)
Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allo
28RISK
open ↗Referência✓ VexDay Proof
QuickTime Player 7.3.1.70 - 'RTSP' Remote Buffer Overflow
Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allo
28RISK
open ↗Referência✓ VexDay Proof
Microsoft Rich Textbox Control 6.0-SP6 - 'SaveFile()' Insecure Method
The Microsoft Rich Textbox ActiveX Control (RICHTX32.OCX) 6.1.97.82 allows remote attackers to execute arbitrary command
28RISK
open ↗Referência
CVE-2010-0611
Multiple SQL injection vulnerabilities in adminlogin.php in Baal Systems 3.8 and earlier allow remote attackers to execu
23RISK
open ↗Referência✓ VexDay Proof
StreamAudio ChainCast ProxyManager - 'ccpm_0237.dll' Remote Buffer Overflow
Buffer overflow in an ActiveX control in ccpm_0237.dll for StreamAudio ChainCast ProxyManager allows remote attackers to
28RISK
open ↗Referência
CVE-2010-0611
Multiple SQL injection vulnerabilities in adminlogin.php in Baal Systems 3.8 and earlier allow remote attackers to execu
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Visual InterDev 6.0 SP6 - '.sln' Local Buffer Overflow
Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a St
28RISK
open ↗Referência✓ VexDay Proof
iGaming CMS 1.3.1/1.5 - SQL Injection
SQL injection vulnerability in archive.php in iGaming 1.5, and 1.3.1 and earlier, allows remote attackers to execute arb
23RISK
open ↗Referência✓ VexDay Proof
minimal Gallery 0.8 - Remote File Disclosure
minimal Gallery 0.8 allows remote attackers to obtain configuration information via a direct request to php_info.php, wh
23RISK
open ↗Referência✓ VexDay Proof
TaskFreak! 0.6.1 - SQL Injection
SQL injection vulnerability in index.php in TaskFreak! 0.6.1 and earlier allows remote authenticated users to execute ar
23RISK
open ↗Referência✓ VexDay Proof
DomPHP 0.81 - Remote Add Administrator
SQL injection vulnerability in welcome/inscription.php in DomPHP 0.81 and earlier allows remote attackers to execute arb
23RISK
open ↗Referência✓ VexDay Proof
ImageAlbum 2.0.0b2 - 'id' SQL Injection
Multiple SQL injection vulnerabilities in ImageAlbum 2.0.0b2 allow remote attackers to execute arbitrary SQL commands vi
23RISK
open ↗Referência✓ VexDay Proof
DigitalHive 2.0 RC2 - 'user_id' SQL Injection
Multiple SQL injection vulnerabilities in Digital Hive 2.0 RC2 and earlier allow (1) remote attackers to execute arbitra
23RISK
open ↗Referência
CVE-2010-0632
SQL injection vulnerability in the Parkview Consultants SimpleFAQ (com_simplefaq) component for Joomla! allows remote at
23RISK
open ↗Referência✓ VexDay Proof
RichStrong CMS - 'cat' SQL Injection
SQL injection vulnerability in showproduct.asp in RichStrong CMS allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência✓ VexDay Proof
FaScript FaPersian Petition - SQL Injection
SQL injection vulnerability in show.php in FaScript FaPersian Petition allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
Aria 0.99-6 - 'page' Local File Inclusion
Directory traversal vulnerability in arias/help/effect.php in aria 0.99-6 allows remote attackers to include and execute
23RISK
open ↗Referência
CVE-2010-0642
Cisco Collaboration Server (CCS) 5 allows remote attackers to read the source code of JHTML files via URL encoded charac
23RISK
open ↗Referência✓ VexDay Proof
PHP-RESIDENCE 0.7.2 - 'Search' SQL Injection
SQL injection vulnerability in visualizza_tabelle.php in php-residence 0.7.2 and 1.0 allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
PHPEcho CMS 2.0 - 'id' SQL Injection
SQL injection vulnerability in index.php in the forum module in PHPEcho CMS, probably 2.0-rc3 and earlier, allows remote
23RISK
open ↗Referência✓ VexDay Proof
Small Axe 0.3.1 - 'cfile' Remote File Inclusion
PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute
35RISK
open ↗Referência✓ VexDay Proof
Crystal Reports XI Release 2 (Enterprise Tree Control) - ActiveX Buffer Overflow (Denial of Service) (PoC)
Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release
23RISK
open ↗Referência✓ VexDay Proof
Digital Data Communications - 'RtspVaPgCtrl' Class Remote Buffer Overflow
Buffer overflow in the Digital Data Communications RtspVaPgCtrl ActiveX control (RtspVapgDecoder.dll 1.1.0.29) allows re
28RISK
open ↗Referência✓ VexDay Proof
MyBulletinBoard (MyBB) 1.2.10 - Multiple Vulnerabilities
Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via
35RISK
open ↗Referência✓ VexDay Proof
MyBulletinBoard (MyBB) 1.2.10 - Remote Code Execution
Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via
35RISK
open ↗Referência✓ VexDay Proof
OpenBSD 4.2 - 'rtlabel_id2name()' Local Null Pointer Dereference Denial of Service
OpenBSD 4.2 allows local users to cause a denial of service (kernel panic) by calling the SIOCGIFRTLABEL IOCTL on an int
23RISK
open ↗Referência✓ VexDay Proof
alitalk 1.9.1.1 - Multiple Vulnerabilities
inc/elementz.php in aliTalk 1.9.1.1 does not properly verify authentication, which allows remote attackers to add an arb
23RISK
open ↗Referência
CVE-2016-0049
Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.