Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
80,930cataloged exploits
37,572CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 23,973GitHub PoC 15,478VulnCheck XDB 9,069Nuclei 4,426Metasploit 3,502✓ verified onlyrecentpopularrisk
24,482 exploits
Exploit-DB
PHPBoost 3.0 - Remote Download Backup
PHPBoost 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attac
23RISK
open ↗Exploit-DB✓ VexDay Proof
InTerra Blog Machine 1.84 - 'subject' HTML Injection
Cross-site scripting (XSS) vulnerability in actions/add.php in InTerra Blog Machine 1.84, and possibly earlier versions,
23RISK
open ↗Exploit-DB✓ VexDay Proof
Perl 5.x - 'lc()' / 'uc()' TAINT Mode Protection Security Bypass
The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x
28RISK
open ↗Exploit-DB✓ VexDay Proof
ICJobSite 1.1 - 'pid' SQL Injection
SQL injection vulnerability in ICloudCenter ICJobSite 1.1 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Exploit-DB✓ VexDay Proof
Andy's PHP KnowledgeBase 0.95.2 - 'viewusers.php' SQL Injection
Multiple SQL injection vulnerabilities in Andy's PHP Knowledgebase (Aphpkb) before 0.95.3 allow remote attackers to exec
23RISK
open ↗Exploit-DB✓ VexDay Proof
Andy's PHP KnowledgeBase 0.95.4 - SQL Injection
SQL injection vulnerability in plugins/pdfClasses/pdfgen.php in Andy's PHP Knowledgebase (Aphpkb) 0.95.4 allows remote a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Tracks 1.7.2 - URI Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in app/controllers/todos_controller.rb in Tracks 1.7.2, 2.0RC2, and 2.0devel al
23RISK
open ↗Exploit-DB
WordPress Plugin BackWPup - Remote Code Execution / Local Code Execution
PHP remote file inclusion vulnerability in wp_xml_export.php in the BackWPup plugin before 1.7.2 for WordPress allows re
28RISK
open ↗Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 1.1.4 - 'AMV' Dangling Pointer (Metasploit)
libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a
60RISK
open ↗Exploit-DB✓ VexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'getnnmdata.exe Hostname' CGI Buffer Overflow (Metasploit)
Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows r
50RISK
open ↗Exploit-DB✓ VexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'getnnmdata.exe ICount' CGI Buffer Overflow (Metasploit)
Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows r
50RISK
open ↗Exploit-DB✓ VexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'nnmRptConfig.exe schdParams' Remote Buffer Overflow (Metasploit)
Multiple buffer overflows in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allow remote at
60RISK
open ↗Exploit-DB✓ VexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'getnnmdata.exe' (MaxAge) CGI Buffer Overflow (Metasploit)
Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows r
60RISK
open ↗Exploit-DB✓ VexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'ovwebsnmpsrv.exe main' Remote Buffer Overflow (Metasploit)
Buffer overflow in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers t
50RISK
open ↗Exploit-DB✓ VexDay Proof
HP Network Node Manager (NMM) - CGI 'webappmon.exe execvp' Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in the execvp_nc function in the ov.dll module in HP OpenView Network Node Manager (OV NNM)
60RISK
open ↗Exploit-DB
Symantec LiveUpdate Administrator Management GUI - HTML Injection
Cross-site request forgery (CSRF) vulnerability in adduser.do in Symantec LiveUpdate Administrator (LUA) before 2.3 allo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Progea Movicon 11 - 'TCPUploadServer' Remote File System
TCPUploadServer.exe in Progea Movicon 11.2 before Build 1084 does not require authentication for critical functions, whi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Advantech/BroadWin SCADA Webaccess 7.0 - Multiple Vulnerabilities
webvrpcs.exe in Advantech/BroadWin WebAccess allows remote attackers to execute arbitrary code or obtain a security-code
28RISK
open ↗Exploit-DB✓ VexDay Proof
Perl 5.x - 'Perl_reg_numbered_buff_fetch()' Remote Denial of Service
The Perl_reg_numbered_buff_fetch function in Perl 5.10.0, 5.12.0, 5.14.0, and other versions, when running with debuggin
23RISK
open ↗Exploit-DB✓ VexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'ovwebsnmpsrv.exe' Unrecognized Option Buffer Overflow (Metasploit)
Buffer overflow in the error handling functionality in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.5
50RISK
open ↗Exploit-DB✓ VexDay Proof
HP OpenView Network Node Manager (OV NNM) - nnmRptConfig nameParams Buffer Overflow (Metasploit)
Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers t
60RISK
open ↗Exploit-DB✓ VexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'ovwebsnmpsrv.exe ovutil' Remote Buffer Overflow (Metasploit)
Buffer overflow in ovutil.dll in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remo
50RISK
open ↗Exploit-DB✓ VexDay Proof
HP Network Node Manager (NMM) - CGI 'webappmon.exe OvJavaLocale' Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in webappmon.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote at
50RISK
open ↗Exploit-DB✓ VexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'snmpviewer.exe' Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in the doLoad function in snmpviewer.exe in HP OpenView Network Node Manager (OV NNM) 7.01,
50RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - AVM Bytecode Verification (Metasploit)
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.1
98RISK
open ↗Exploit-DB
Symantec LiveUpdate Administrator Management GUI - HTML Injection
Cross-site scripting (XSS) vulnerability in the management login GUI page in Symantec LiveUpdate Administrator (LUA) bef
23RISK
open ↗Exploit-DB
DATAC RealWin - Multiple Vulnerabilities
Multiple integer overflows in the HMI application in DATAC RealFlex RealWin 2.1 (Build 6.1.10.10) and earlier allow remo
28RISK
open ↗Exploit-DB
7-Technologies IGSS 9.00.00.11059 - Multiple Vulnerabilities
Directory traversal vulnerability in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Graphica
50RISK
open ↗Exploit-DB
7-Technologies IGSS 9.00.00.11059 - Multiple Vulnerabilities
Format string vulnerability in the logText function in shmemmgr9.dll in IGSSdataServer.exe 9.00.00.11074, and 9.00.00.11
28RISK
open ↗Exploit-DB
7-Technologies IGSS 9.00.00.11059 - Multiple Vulnerabilities
Directory traversal vulnerability in dc.exe 9.00.00.11059 and earlier in 7-Technologies Interactive Graphical SCADA Syst
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.