Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,496cataloged exploits
34,964CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 13,937VulnCheck XDB 8,510Nuclei 4,239Metasploit 3,468✓ verified onlyrecentpopularrisk
24,443 exploits
Exploit-DB✓ VexDay Proof
Kisisel Radyo Script - Multiple Vulnerabilities
SQL injection vulnerability in radyo.asp in Kisisel Radyo Script allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - NTLM Weak Nonce (MS10-012)
The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft ASP.NET - Padding Oracle File Download (MS10-070)
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Intern
35RISK
open ↗Exploit-DB✓ VexDay Proof
Kisisel Radyo Script - Multiple Vulnerabilities
Kisisel Radyo Script stores sensitive information under the web root with insufficient access control, which allows remo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Office - 'HtmlDlgHelper' Class Memory Corruption (MS10-071)
mshtmled.dll in Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code via a crafted Micr
28RISK
open ↗Exploit-DB
IBM solidDB 6.5.0.3 - Denial of Service
solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon recei
23RISK
open ↗Exploit-DB✓ VexDay Proof
DATAC RealWin SCADA Server 2.0 (Build 6.1.8.10) - Buffer Overflow
Multiple stack-based buffer overflows in DATAC RealWin 2.0 Build 6.1.8.10 and earlier allow remote attackers to cause a
50RISK
open ↗Exploit-DB
IBM solidDB 6.5.0.3 - Denial of Service
solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon recei
23RISK
open ↗Exploit-DB
IBM solidDB 6.5.0.3 - Denial of Service
Stack consumption vulnerability in solid.exe in IBM solidDB 6.5.0.3 and earlier allows remote attackers to cause a denia
23RISK
open ↗Exploit-DB✓ VexDay Proof
TWiki 5.0 - bin/login Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki before 5.0.1 allow remote attackers to inje
23RISK
open ↗Exploit-DB✓ VexDay Proof
TWiki 5.0 - '/bin/view?rev' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki before 5.0.1 allow remote attackers to inje
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox 3.5.10/3.6.6 - 'WMP' Memory Corruption Using Popups
Microsoft Windows Media Player (WMP) 9 through 12 does not properly deallocate objects during a browser reload action, w
28RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Solaris - 'su' Crash
Unspecified vulnerability in Oracle Solaris 10 and OpenSolaris allows local users to affect confidentiality and integrit
23RISK
open ↗Exploit-DB✓ VexDay Proof
Winamp 5.5.8.2985 - Multiple Buffer Overflows
Buffer overflow in the in_mod plugin in Winamp before 5.6 allows remote attackers to have an unspecified impact via vect
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Jstore - 'Controller' Local File Inclusion
Directory traversal vulnerability in Jstore (com_jstore) component for Joomla! allows remote attackers to read arbitrary
43RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Java 6 - OBJECT tag 'launchjnlp'/'docbase' Remote Buffer Overflow
Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows r
60RISK
open ↗Exploit-DB✓ VexDay Proof
Collabtive 0.65 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Collabtive 0.6.5 allow remote attackers to inject arbitrary web s
23RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Fusion Middleware 10.1.2/10.1.3 - BPEL Console Cross-Site Scripting
Unspecified vulnerability in the BPEL Console component in Oracle Fusion Middleware 11.1.1.1.0 and 11.1.1.2.0 allows rem
23RISK
open ↗Exploit-DB✓ VexDay Proof
AdaptCMS 2.0.1 Beta - Remote File Inclusion (Metasploit)
PHP remote file inclusion vulnerability in inc/smarty/libs/init.php in AdaptCMS 2.0.0 Beta, when register_globals is ena
23RISK
open ↗Exploit-DB✓ VexDay Proof
HP OpenView Network Node Manager (OV NNM) 7.53/7.51 - 'OVAS.exe' Stack Buffer Overflow (Metasploit)
Stack-based buffer overflow in ovwparser.dll in HP OpenView Network Node Manager (OV NNM) 7.53, 7.51, and earlier allows
60RISK
open ↗Exploit-DB✓ VexDay Proof
Collabtive 0.65 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in admin.php in Collabtive 0.6.5 allows remote attackers to hijack the a
23RISK
open ↗Exploit-DB✓ VexDay Proof
BaconMap 1.0 - Local File Disclosure
Directory traversal vulnerability in admin/updatelist.php in BaconMap 1.0 allows remote attackers to include and execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
BaconMap 1.0 - SQL Injection
SQL injection vulnerability in doadd.php in BaconMap 1.0 allows remote attackers to execute arbitrary SQL commands via t
23RISK
open ↗Exploit-DB✓ VexDay Proof
OrangeHRM 2.6.0.1 - Local File Inclusion
Directory traversal vulnerability in index.php in OrangeHRM 2.6.0.1 allows remote attackers to include and execute arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Fusion Mod Mg User Fotoalbum 1.0.1 - SQL Injection
SQL injection vulnerability in infusions/mg_user_fotoalbum_panel/mg_user_fotoalbum.php in the MG User-Fotoalbum (mg_user
23RISK
open ↗Exploit-DB✓ VexDay Proof
Site2Nite Auto e-Manager - SQL Injection
SQL injection vulnerability in detail.asp in Site2Nite Auto e-Manager allows remote attackers to execute arbitrary SQL c
23RISK
open ↗Exploit-DB✓ VexDay Proof
Chipmunk Pwngame - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Chipmunk Pwngame 1.0, when magic_quotes_gpc is disabled, allow remote attacker
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple QuickTime (Mac OSX) - RTSP Content-Type Overflow (Metasploit)
Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac
50RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX EvoCam Web Server - GET Buffer Overflow (Metasploit)
Buffer overflow in the web server for EvoLogical EvoCam 3.6.6 and 3.6.7 allows remote attackers to execute arbitrary cod
50RISK
open ↗Exploit-DB✓ VexDay Proof
UFO: Alien Invasion IRC Client (OSX) - Remote Buffer Overflow (Metasploit)
Buffer overflow in the web server for EvoLogical EvoCam 3.6.6 and 3.6.7 allows remote attackers to execute arbitrary cod
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.