Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
80,409cataloged exploits
37,196CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,478Referência 23,664GitHub PoC 15,347VulnCheck XDB 9,003Nuclei 4,415Metasploit 3,502✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
Global Centre Aplomb Poll 1.1 - 'index.php?Madoa' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Madoa Poll 1.1 allow remote attackers to execute arbitrary PHP cod
23RISK
open ↗Exploit-DB✓ VexDay Proof
Global Centre Aplomb Poll 1.1 - 'admin.php?Madoa' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Madoa Poll 1.1 allow remote attackers to execute arbitrary PHP cod
23RISK
open ↗Exploit-DB✓ VexDay Proof
Global Centre Aplomb Poll 1.1 - 'vote.php?Madoa' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Madoa Poll 1.1 allow remote attackers to execute arbitrary PHP cod
23RISK
open ↗Exploit-DB✓ VexDay Proof
IT!CMS 0.2 - 'titletext-ed.php?wndtitle' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in IT!CMS (itcms) 0.2 allow remote attackers to inject arbitrary web
23RISK
open ↗Exploit-DB✓ VexDay Proof
Baidu Soba Search Bar 5.4 - 'BaiduBar.dll' ActiveX Control Remote Code Execution
A certain ActiveX control in BaiduBar.dll in Baidu Soba Search Bar 5.4 allows remote attackers to execute arbitrary code
23RISK
open ↗Exploit-DB✓ VexDay Proof
Fail2ban 0.8 - Remote Denial of Service
fail2ban 0.8 and earlier does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpCoupon - Remote Payment Bypass
user.php in the Billing Control Panel in phpCoupon allows remote authenticated users to obtain Premium Member status, an
23RISK
open ↗Exploit-DB✓ VexDay Proof
Online Store Application Template - 'Sign_In.aspx' SQL Injection
SQL injection vulnerability in sign_in.aspx in WebStore (Online Store Application Template) allows remote attackers to e
23RISK
open ↗Exploit-DB✓ VexDay Proof
Berthanas Ziyaretci Defteri 2.0 - 'Yonetici.asp' SQL Injection
Multiple SQL injection vulnerabilities in yonetici.asp in Berthanas Ziyaretci Defteri 2.0 allow remote attackers to exec
23RISK
open ↗Exploit-DB✓ VexDay Proof
Message Board / Threaded Discussion Forum - 'Sign_In.aspx' SQL Injection
SQL injection vulnerability in sign_in.aspx in Message Board / Threaded Discussion Forum Application Template allows rem
23RISK
open ↗Exploit-DB✓ VexDay Proof
Pay Roll Time Sheet and Punch Card Application With Web UI - 'login.asp' SQL Injection
SQL injection vulnerability in login.asp in CodeWidgets Pay Roll - Time Sheet and Punch Card Application With Web Interf
23RISK
open ↗Exploit-DB✓ VexDay Proof
Real Estate Listing Website Application Template Login Dialog - SQL Injection
SQL injection vulnerability in the login script in Real Estate listing website application template, when logging in as
23RISK
open ↗Exploit-DB✓ VexDay Proof
Nessus Vulnerability Scanner 3.0.6 - ActiveX Command Execution
The SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
Nessus Vulnerability Scanner 3.0.6 - ActiveX Command Execution
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attac
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM AIX 5.3 SP6 - FTP 'gets()' Local Privilege Escalation
Buffer overflow in the ftp client in IBM AIX 5.3 SP6 and 5.2.0 allows local users to execute arbitrary code via unspecif
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM AIX 5.3 SP6 - 'pioout' Arbitrary Library Loading Privilege Escalation
pioout in IBM AIX 5.3 SP6 allows local users to execute arbitrary code by specifying a malicious library with the -R (Pa
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM AIX 5.3 SP6 - Capture Terminal Sequence Privilege Escalation
Stack-based buffer overflow in capture in IBM AIX 5.3 SP6 and 5.2.0 allows remote attackers to execute arbitrary code vi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Metyus Forum Portal 1.0 - 'Philboard_Forum.asp' SQL Injection
SQL injection vulnerability in philboard_forum.asp in Metyus Forum Portal 1.0 allows remote attackers to execute arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
Bandersnatch 0.4 - Multiple Input Validation Vulnerabilities
Multiple SQL injection vulnerabilities in Bandersnatch 0.4 allow remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM AIX 5.2/5.3 - Capture Command Local Stack Buffer Overflow
Stack-based buffer overflow in capture in IBM AIX 5.3 SP6 and 5.2.0 allows remote attackers to execute arbitrary code vi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Explorer - '.png' Image Local Denial of Service
Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service (CPU consum
28RISK
open ↗Exploit-DB✓ VexDay Proof
IPSwitch IMail Server 2006 9.10 - Subscribe Remote Overflow
Multiple buffer overflows in Ipswitch IMail Server 2006 before 2006.21 (1) allow remote attackers to execute arbitrary c
28RISK
open ↗Exploit-DB✓ VexDay Proof
T1lib - 'intT1_Env_GetCompletePath' Buffer Overflow (PoC)
Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent at
28RISK
open ↗Exploit-DB✓ VexDay Proof
BSM Store Dependent Forums 1.02 - 'Username' SQL Injection
SQL injection vulnerability in BSM Store Dependent Forums 1.02 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
Nukedit 4.9.x - 'login.asp' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in utilities/login.asp in nukedit 4.9.7 and earlier allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin WP-FeedStats 2.1 - HTML Injection
Multiple cross-site scripting (XSS) vulnerabilities in the WP-FeedStats before 2.4 plugin for WordPress allow remote att
23RISK
open ↗Exploit-DB✓ VexDay Proof
Vikingboard 0.1.2 - 'user.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1.2 allow remote attackers to inject arbitrary web
23RISK
open ↗Exploit-DB✓ VexDay Proof
Vikingboard 0.1.2 - 'topic.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1.2 allow remote attackers to inject arbitrary web
23RISK
open ↗Exploit-DB✓ VexDay Proof
Vikingboard 0.1.2 - 'cp.php' Information Disclosure
Vikingboard 0.1.2 allows remote attackers to obtain sensitive information via the debug parameter to (1) forum.php, (2)
23RISK
open ↗Exploit-DB✓ VexDay Proof
Vikingboard 0.1.2 - 'forum.php' Information Disclosure
Vikingboard 0.1.2 allows remote attackers to obtain sensitive information via the debug parameter to (1) forum.php, (2)
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.