Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,064cataloged exploits
37,667CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,044GitHub PoC 15,521VulnCheck XDB 9,080Nuclei 4,432Metasploit 3,505✓ verified onlyrecentpopularrisk
24,482 exploits
Exploit-DB
DIY-CMS 1.0 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in DiY-CMS 1.0 allow remote attackers to execute arbitrary PHP code v
23RISK
open ↗Exploit-DB✓ VexDay Proof
GaleriaSHQIP 1.0 - SQL Injection
SQL injection vulnerability in index.php in GaleriaSHQIP 1.0, when magic_quotes_gpc is disabled, allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
XOOPS 2.0.14 - 'article.php' SQL Injection
SQL injection vulnerability in article.php in the Article module for XOOPS allows remote attackers to execute arbitrary
23RISK
open ↗Exploit-DB
textpattern CMS 4.2.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Textpattern CMS 4.2.0 allows remote attackers to execute arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel < 2.6.36-rc1 (Ubuntu 10.04 / 2.6.32) - 'CAN BCM' Local Privilege Escalation
Integer overflow in net/can/bcm.c in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.27.
23RISK
open ↗Exploit-DB
pecio CMS 2.0.5 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Pecio CMS 2.0.5 allow remote attackers to execute arbitrary PHP co
23RISK
open ↗Exploit-DB✓ VexDay Proof
iGaming CMS - Multiple SQL Injections
Multiple SQL injection vulnerabilities in iGaming 1.5 and earlier allow remote attackers to execute arbitrary SQL comman
23RISK
open ↗Exploit-DB✓ VexDay Proof
kontakt formular 1.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in formmailer.php in Kontakt Formular 1.1 allows remote attackers to execute arb
23RISK
open ↗Exploit-DB✓ VexDay Proof
Gaestebuch 1.2 - Remote File Inclusion
PHP remote file inclusion vulnerability in guestbook/gbook.php in Gaestebuch 1.2 allows remote attackers to execute arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
EncFS 1.6.0 - Flawed CBC/CFB Cryptography Implementation
SSL_Cipher.cpp in EncFS before 1.7.0 does not properly handle integer data sizes when constructing headers intended for
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - Object Type (MS03-020) (Metasploit)
Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Address Book 6.00.2900.5512 - 'wab32res.dll' DLL Hijacking
Untrusted search path vulnerability in wab.exe 6.00.2900.5512 in Windows Address Book in Microsoft Windows XP SP2 and SP
28RISK
open ↗Exploit-DB✓ VexDay Proof
Mercur Messaging 2005 - IMAP Login Buffer Overflow (Metasploit)
Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause
50RISK
open ↗Exploit-DB
Adobe InDesign CS4 - 'ibfs32.dll' DLL Hijacking
Untrusted search path vulnerability in Adobe InDesign CS4 6.0, InDesign CS5 7.0.2 and earlier, Adobe InDesign Server CS5
28RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Thunderbird - 'dwmapi.dll' DLL Hijacking
Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 an
28RISK
open ↗Exploit-DB
Cisco Packet Tracer 5.2 - 'wintab32.dll' DLL Hijacking
Untrusted search path vulnerability in Cisco Packet Tracer 5.2 allows local users, and possibly remote attackers, to exe
23RISK
open ↗Exploit-DB✓ VexDay Proof
Skype 4.2.0.169 - 'wab32.dll' DLL Hijacking
Untrusted search path vulnerability in Skype 4.2.0.169 and earlier allows local users, and possibly remote attackers, to
23RISK
open ↗Exploit-DB✓ VexDay Proof
SquirrelMail PGP Plugin - Command Execution (SMTP) (Metasploit)
The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via s
43RISK
open ↗Exploit-DB
Avast! 5.0.594 - 'mfc90loc.dll' License Files DLL Hijacking
Untrusted search path vulnerability in avast! Free Antivirus version 5.0.594 and earlier allows local users, and possibl
23RISK
open ↗Exploit-DB✓ VexDay Proof
NTP daemon readvar - Remote Buffer Overflow (Metasploit)
Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial o
60RISK
open ↗Exploit-DB
Adobe Illustrator CS4 - 'aires.dll' DLL Hijacking
Untrusted search path vulnerability in Adobe Illustrator CS4 14.0.0, CS5 15.0.1 and earlier, and possibly other versions
28RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe ExtendedScript Toolkit CS5 3.5.0.52 - 'dwmapi.dll' DLL Hijacking
Untrusted search path vulnerability in Adobe ExtendScript Toolkit (ESTK) CS5 3.5.0.52 allows local users, and possibly r
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Services - 'nwapi32.dll' (MS06-066) (Metasploit)
Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 al
60RISK
open ↗Exploit-DB✓ VexDay Proof
Corel PHOTO-PAINT X3 13.0.0.576 - 'crlrib.dll' DLL Hijacking
DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel
23RISK
open ↗Exploit-DB✓ VexDay Proof
μTorrent (uTorrent) 2.0.3 - DLL Hijacking
Untrusted search path vulnerability in uTorrent 2.0.3 and earlier allows local users, and possibly remote attackers, to
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Extension Manager CS5 5.0.298 - 'dwmapi.dll' DLL Hijacking
Untrusted search path vulnerability in Adobe Extension Manager CS5 5.0.298 allows local users, and possibly remote attac
28RISK
open ↗Exploit-DB
VideoLAN VLC Media Player 1.1.3 - 'wintab32.dll' DLL Hijacking
Untrusted search path vulnerability in bin/winvlc.c in VLC Media Player 1.1.3 and earlier allows local users, and possib
28RISK
open ↗Exploit-DB✓ VexDay Proof
CorelDRAW X3 13.0.0.576 - 'crlrib.dll' DLL Hijacking
DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel
23RISK
open ↗Exploit-DB✓ VexDay Proof
httpdx - 'tolog()' Format String (Metasploit) (1)
Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remo
50RISK
open ↗Exploit-DB✓ VexDay Proof
httpdx - 'tolog()' Format String (Metasploit) (2)
Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remo
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.