Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,559cataloged exploits
34,978CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 13,960VulnCheck XDB 8,542Nuclei 4,243Metasploit 3,472✓ verified onlyrecentpopularrisk
24,443 exploits
Exploit-DB✓ VexDay Proof
fusebox - 'ProductList.cfm?CatDisplay' SQL Injection
SQL injection vulnerability in ProductList.cfm in Fusebox 5.5.1 allows remote attackers to execute arbitrary SQL command
23RISK
open ↗Exploit-DB✓ VexDay Proof
Nucleus Plugin Gallery - Remote File Inclusion / SQL Injection
PHP remote file inclusion vulnerability in nucleus/plugins/NP_gallery.php in the NP_Gallery plugin 0.94 for Nucleus allo
23RISK
open ↗Exploit-DB
Nucleus Plugin Twitter - Remote File Inclusion
PHP remote file inclusion vulnerability in nucleus/plugins/NP_Twitter.php in the NP_Twitter Plugin 0.8 and 0.9 for Nucle
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component BF Quiz 1.0 - SQL Injection (2)
SQL injection vulnerability in the BF Quiz (com_bfquiztrial) component before 1.3.1 for Joomla! allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component BF Quiz 1.3.0 - SQL Injection (1)
SQL injection vulnerability in the BF Quiz (com_bfquiztrial) component before 1.3.1 for Joomla! allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component My Car 1.0 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in the My Car (com_mycar) component 1.0 for Joomla! allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component My Car 1.0 - Multiple Vulnerabilities
SQL injection vulnerability in the My Car (com_mycar) component 1.0 for Joomla! allows remote attackers to execute arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component JE Job 1.0 - 'catid' SQL Injection
SQL injection vulnerability in the JExtensions JE Job (com_jejob) component 1.0 for Joomla! allows remote attackers to e
38RISK
open ↗Exploit-DB✓ VexDay Proof
FreeBSD 8.0 - 'ftpd' (FreeBSD-SA-10:05) Off-By-One (PoC)
Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeB
28RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Photoshop CS4 Extended 11.0 - '.ASL' File Handling Remote Buffer Overflow (PoC)
Multiple buffer overflows in Adobe Photoshop CS4 before 11.0.2 allow user-assisted remote attackers to execute arbitrary
28RISK
open ↗Exploit-DB✓ VexDay Proof
Worldweaver DX Studio Player 3.0.29 - 'shell.execute()' Command Execution (Metasploit)
Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a p
50RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Photoshop CS4 Extended 11.0 - '.GRD' File Handling Remote Buffer Overflow (PoC)
Multiple buffer overflows in Adobe Photoshop CS4 before 11.0.2 allow user-assisted remote attackers to execute arbitrary
28RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Photoshop CS4 Extended 11.0 - '.ABR' File Handling Remote Buffer Overflow (PoC)
Multiple buffer overflows in Adobe Photoshop CS4 before 11.0.2 allow user-assisted remote attackers to execute arbitrary
28RISK
open ↗Exploit-DB✓ VexDay Proof
Nitro Web Gallery - SQL Injection
SQL injection vulnerability in index.php in NITRO Web Gallery allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
Webby WebServer - Overflow (SEH) (PoC)
Buffer overflow in Webby Webserver 1.01 allows remote attackers to execute arbitrary code via a long HTTP GET request.
23RISK
open ↗Exploit-DB
LiSK CMS 4.4 - SQL Injection
Multiple SQL injection vulnerabilities in LiSK CMS 4.4 allow remote attackers to execute arbitrary SQL commands via (1)
23RISK
open ↗Exploit-DB
Microsoft Outlook Web Access (OWA) 8.2.254.0 - Information Disclosure
Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly
28RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco DPC2100 2.0.2 r1256-060303 - Multiple Security Bypass / Cross-Site Request Forgery Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the Cisco Scientific Atlanta WebSTAR
23RISK
open ↗Exploit-DB✓ VexDay Proof
RazorCMS 1.0 - '/admin/index.php' HTML Injection
Cross-site scripting (XSS) vulnerability in admin/core/admin_func.php in razorCMS 1.0 stable allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
e107 - Code Exection
bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the ph
23RISK
open ↗Exploit-DB✓ VexDay Proof
Getsimple CMS 2.01 - 'components.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admin/components.php in GetSimple CMS 2.01 allows remote attackers to inject
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Q-Personel 1.0 - SQL Injection
SQL injection vulnerability in the Q-Personel (com_qpersonel) component 1.0.2 and earlier for Joomla! allows remote atta
23RISK
open ↗Exploit-DB
Kingsoft Webshield 'KAVSafe.sys' 2010.4.14.609 (2010.5.23) - Kernel Mode Privilege Escalation
KAVSafe.sys 2010.4.14.609 and earlier, as used in Kingsoft Webshield 3.5.1.2 and earlier, allows local users to overwrit
23RISK
open ↗Exploit-DB✓ VexDay Proof
Recipes Website 1.0 - SQL Injection
SQL injection vulnerability in control/admin_login.php in ScriptsFeed Recipes Listing Portal 1.0 allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
cyberhost - 'default.asp' SQL Injection
SQL injection vulnerability in default.asp in Cyberhost allows remote attackers to execute arbitrary SQL commands via th
23RISK
open ↗Exploit-DB
ECShop - 'search.php' SQL Injection
SQL injection vulnerability in search.php in ECShop 2.7.2 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Exploit-DB
JV2 Folder Gallery 3.1 - 'gallery.php' Remote File Inclusion
PHP remote file inclusion vulnerability in gallery.php in JV2 Folder Gallery 3.1 allows remote attackers to execute arbi
23RISK
open ↗Exploit-DB
Apache Axis2 Administration Console - (Authenticated) Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Ap
35RISK
open ↗Exploit-DB✓ VexDay Proof
SolarWinds TFTP Server 10.4.0.10 - Denial of Service
SolarWinds TFTP Server 10.4.0.10 allows remote attackers to cause a denial of service (no new connections) via a crafted
50RISK
open ↗Exploit-DB✓ VexDay Proof
ConPresso 4.0.7 - SQL Injection
SQL injection vulnerability in firma.php in Bartels Schone ConPresso 4.0.7 allows remote attackers to execute arbitrary
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.