Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,192cataloged exploits
37,765CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,138GitHub PoC 15,542VulnCheck XDB 9,091Nuclei 4,434Metasploit 3,505✓ verified onlyrecentpopularrisk
24,482 exploits
Exploit-DB✓ VexDay Proof
IncrediMail 2.0 - ActiveX (Authenticated) Buffer Overflow (PoC)
Buffer overflow in the Authenticate method in the INCREDISPOOLERLib.Pop ActiveX control in ImSpoolU.dll in IncrediMail 2
23RISK
open ↗Exploit-DB
PHP-fusion dsmsf Mod Downloads - SQL Injection
SQL injection vulnerability in screen.php in the Download System mSF (dsmsf) module for PHP-Fusion allows remote attacke
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component JP Jobs 1.4.1 - SQL Injection
SQL injection vulnerability in the JP Jobs (com_jp_jobs) component 1.4.1 and earlier for Joomla! allows remote attackers
23RISK
open ↗Exploit-DB
Microsoft Internet Explorer Tabular Data Control - ActiveX Remote Code Execution
The Tabular Data Control (TDC) ActiveX control in Microsoft Internet Explorer 5.01 SP4, 6 on Windows XP SP2 and SP3, and
60RISK
open ↗Exploit-DB
DynPG CMS 4.1.0 - 'popup.php' / 'counter.php' Multiple Vulnerabilities
Multiple PHP remote file inclusion vulnerabilities in DynPG CMS 4.1.0, and possibly earlier, when magic_quotes_gpc is di
28RISK
open ↗Exploit-DB
CMS Made Simple 1.7 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in CMS Made Simple 1.8.1 and earlier allows remote attackers to hijack t
23RISK
open ↗Exploit-DB✓ VexDay Proof
Free MP3 CD Ripper 2.6 - '.wav' Local Overflow
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RISK
open ↗Exploit-DB
Joomla! Component webERPcustomer - Local File Inclusion
Directory traversal vulnerability in weberpcustomer.php in the webERPcustomer (com_weberpcustomer) component 1.2.1 and 1
38RISK
open ↗Exploit-DB
DynPG CMS 4.1.0 - Multiple Vulnerabilities
Multiple PHP remote file inclusion vulnerabilities in DynPG CMS 4.1.0, and possibly earlier, when magic_quotes_gpc is di
28RISK
open ↗Exploit-DB
Joomla! Component User Status - Local File Inclusion
Directory traversal vulnerability in userstatus.php in the User Status (com_userstatus) component 1.21.16 for Joomla! al
43RISK
open ↗Exploit-DB✓ VexDay Proof
TugZip 3.5 Archiver - '.ZIP' File Buffer Overflow
Stack-based buffer overflow in TUGzip 3.5.0.0 allows remote attackers to denial of service (crash) or execute arbitrary
50RISK
open ↗Exploit-DB
Joomla! Component Jvehicles - Local File Inclusion
SQL injection vulnerability in the Jvehicles (com_jvehicles) component 1.0, 2.0, and 2.1111 for Joomla! allows remote at
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component DW Graph - Local File Inclusion
Directory traversal vulnerability in dwgraphs.php in the DecryptWeb DW Graphs (com_dwgraphs) component 1.0 for Joomla! a
38RISK
open ↗Exploit-DB✓ VexDay Proof
Free MP3 CD Ripper 2.6 - '.wav' Local Stack Buffer Overflow
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Reader - Escape From '.PDF' Execute Embedded Executable
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RISK
open ↗Exploit-DB
OpenDcHub 0.8.1 - Remote Code Execution
Stack-based buffer overflow in Open Direct Connect Hub (aka Open DC Hub or OpenDCHub) 0.8.1 allows remote authenticated
23RISK
open ↗Exploit-DB✓ VexDay Proof
Centreon IT & Network Monitoring 2.1.5 - SQL Injection
SQL injection vulnerability in main.php in Centreon 2.1.5 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Reader - Escape From '.PDF' Execute Embedded Executable
Foxit Reader before 3.2.1.0401 allows remote attackers to (1) execute arbitrary local programs via a certain "/Type /Act
23RISK
open ↗Exploit-DB✓ VexDay Proof
Piwik 0.5.5 - 'form_url' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Login form in Piwik 0.1.6 through 0.5.5 allows remote attackers to injec
23RISK
open ↗Exploit-DB✓ VexDay Proof
Easy-Clanpage 2.1 - SQL Injection
SQL injection vulnerability in index.php in the gallery module in Easy-Clanpage 2.2 allows remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Shadow Stream Recorder 3.0.1.7 - '.asx' Local Buffer Overflow
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Pepsi CMS (Irmin cms) pepsi-0.6-BETA2 - Multiple Local File
Directory traversal vulnerability in Irmin CMS (formerly Pepsi CMS) 0.6 BETA2 allows remote attackers to read arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
Pepsi CMS (Irmin cms) pepsi-0.6-BETA2 - Multiple Local File
Directory traversal vulnerability in includes/template-loader.php in Irmin CMS (formerly Pepsi CMS) 0.5 and 0.6 BETA2, w
23RISK
open ↗Exploit-DB
Yamamah 1.00 - Multiple Vulnerabilities
SQL injection vulnerability in index.php in Yamamah Photo Gallery 1.00, as distributed before 20100618, allows remote at
23RISK
open ↗Exploit-DB
Yamamah 1.00 - Multiple Vulnerabilities
SQL injection vulnerability in index.php in Yamamah (aka Dove Photo Album) 1.00 allows remote attackers to execute arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
ASX to MP3 Converter 3.0.0.100 - Local Stack Overflow
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RISK
open ↗Exploit-DB
HP OpenView Network Node Manager (OV NNM) - 'OvWebHelp.exe' CGI Topic Overflow
Heap-based buffer overflow in OvWebHelp.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows rem
60RISK
open ↗Exploit-DB✓ VexDay Proof
Free MP3 CD Ripper 2.6 - '.wav' (PoC)
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component com_weblinks - 'id' SQL Injection
SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
ASX to MP3 Converter 3.0.0.100 - Local Stack Overflow (PoC)
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.