Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,559cataloged exploits
34,978CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 13,960VulnCheck XDB 8,542Nuclei 4,243Metasploit 3,472✓ verified onlyrecentpopularrisk
24,443 exploits
Exploit-DB✓ VexDay Proof
Sun Solaris Telnet - Remote Authentication Bypass (Metasploit)
Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterpr
60RISK
open ↗Exploit-DB✓ VexDay Proof
Mercury/32 Mail Server < 4.01b - LOGIN Buffer Overflow (Metasploit)
Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers
50RISK
open ↗Exploit-DB✓ VexDay Proof
CA BrightStor ArcServe - Media Service Stack Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Me
60RISK
open ↗Exploit-DB✓ VexDay Proof
Video Community portal - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attacke
23RISK
open ↗Exploit-DB✓ VexDay Proof
K-Search - SQL Injection / Cross-Site Scripting
Multiple SQL injection vulnerabilities in K-Search 1.0 and earlier allow remote attackers to execute arbitrary SQL comma
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Picasa2Gallery 1.2.8 - Local File Inclusion
Directory traversal vulnerability in the Picasa2Gallery (com_picasa2gallery) component 1.2.8 and earlier for Joomla! all
38RISK
open ↗Exploit-DB✓ VexDay Proof
Asus Dpcproxy - Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in the DPC Proxy server (DpcProxy.exe) in ASUS Remote Console (aka ARC or ASMB3) 2.0.0.19 an
60RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox/Thunderbird/SeaMonkey - XSLT Integer Overflow
Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4,
28RISK
open ↗Exploit-DB✓ VexDay Proof
Netcat 1.10 - NT Stack Buffer Overflow (Metasploit)
Stack-based buffer overflow in doexec.c in Netcat for Windows 1.1, when running with the -e option, allows remote attack
50RISK
open ↗Exploit-DB✓ VexDay Proof
K-Search - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in K-Search allows remote attackers to inject arbitrary web script
23RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris Sadmind - Command Execution (Metasploit)
The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attack
60RISK
open ↗Exploit-DB✓ VexDay Proof
Mercury/32 Mail SMTPD - AUTH CRAM-MD5 Buffer Overflow (Metasploit)
Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, all
50RISK
open ↗Exploit-DB✓ VexDay Proof
Job Search Engine Script - SQL Injection
SQL injection vulnerability in show_search_result.php in 2daybiz Job Search Engine Script allows remote attackers to exe
23RISK
open ↗Exploit-DB✓ VexDay Proof
G.CMS Generator - SQL Injection
SQL injection vulnerability in G.CMS generator allows remote attackers to execute arbitrary SQL commands via the lang pa
23RISK
open ↗Exploit-DB
Linker IMG 1.0 - Remote File Inclusion
Multiple directory traversal vulnerabilities in index.php in Linker IMG 1.0 and earlier allow remote attackers to read a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Samba 2.2.8 (OSX/PPC) - 'trans2open' Remote Overflow (Metasploit)
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RISK
open ↗Exploit-DB✓ VexDay Proof
Jamroom 4.0.2/4.1.x - 'forum.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in forum.php in Jamroom before 4.1.9 allows remote attackers to inject arbitrar
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Websphere ILOG JRules 6.7 - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in content/internalError.jsp in IBM WebSphere ILOG JRules 6.7 allow
23RISK
open ↗Exploit-DB✓ VexDay Proof
Samba 2.2.8 (Solaris SPARC) - 'trans2open' Remote Overflow (Metasploit)
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RISK
open ↗Exploit-DB✓ VexDay Proof
MoreAmp - '.maf' Local Stack Buffer Overflow (SEH)
Stack-based buffer overflow in MoreAmp allows remote attackers to execute arbitrary code via a long line in a song list
23RISK
open ↗Exploit-DB✓ VexDay Proof
Overstock Script - SQL Injection
SQL injection vulnerability in storecat.php in JCE-Tech Overstock 1 allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Exploit-DB✓ VexDay Proof
Shareasale Script - SQL Injection
SQL injection vulnerability in merchant_product_list.php in JCE-Tech Shareasale Script (SASS) 1 allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
OroHYIP - SQL Injection
SQL injection vulnerability in withdraw_money.php in Toma Cero OroHYIP allows remote attackers to execute arbitrary SQL
23RISK
open ↗Exploit-DB✓ VexDay Proof
iBoutique - 'page' SQL Injection / Cross-Site Scripting
SQL injection vulnerability in index.php in NetArt Media iBoutique 4.0 allows remote attackers to execute arbitrary SQL
23RISK
open ↗Exploit-DB✓ VexDay Proof
iBoutique - 'page' SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in iBoutique 4.0 allows remote attackers to inject arbitrary web s
23RISK
open ↗Exploit-DB✓ VexDay Proof
Elite Gaming Ladders 3.5 - 'ladder[id]' SQL Injection
SQL injection vulnerability in standings.php in Elite Gaming Ladders 3.5 allows remote attackers to execute arbitrary SQ
23RISK
open ↗Exploit-DB✓ VexDay Proof
MoreAmp - '.maf' Buffer Overflow (PoC)
Stack-based buffer overflow in MoreAmp allows remote attackers to execute arbitrary code via a long line in a song list
23RISK
open ↗Exploit-DB✓ VexDay Proof
Orbital Viewer 1.04 - '.ov' Local Universal Stack Overflow (SEH)
Stack-based buffer overflow in Orbital Viewer 1.04 allows user-assisted remote attackers to execute arbitrary code via a
50RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component RSComments 1.0.0 - Persistent Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the RSComments (com_rscomments) component 1.0.0 Rev 2 for Joomla!
23RISK
open ↗Exploit-DB✓ VexDay Proof
Banner Management Script - SQL Injection
SQL injection vulnerability in trackads.php in YourFreeWorld Banner Management allows remote attackers to execute arbitr
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.