Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 14,014VulnCheck XDB 8,571Nuclei 4,248Metasploit 3,472✓ verified onlyrecentpopularrisk
24,443 exploits
Exploit-DB✓ VexDay Proof
UoW IMAPd Server - LSUB Buffer Overflow (Metasploit)
Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via
50RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component dcsFlashGames 2.0RC1 - 'catid' SQL Injection
SQL injection vulnerability in Adam Corley dcsFlashGames (com_dcs_flashgames) allows remote attackers to execute arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Safari iPhone/iPod touch - Webpage Remote Code Execution
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash)
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple iOS Safari - Bad 'VML' Remote Denial of Service
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash)
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple iOS Safari - Remote Denial of Service
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash)
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Safari for iPhone/iPod touch - 'Throw' Exception Remote Code Execution
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash)
23RISK
open ↗Exploit-DB✓ VexDay Proof
Direct News 4.10.2 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Direct News 4.10.2, when register_globals is enabled, allow remote
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco TFTP Server 1.1 - Denial of Service
Cisco TFTP Server 1.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted (1) read (aka RR
23RISK
open ↗Exploit-DB✓ VexDay Proof
SiteX CMS 0.7.4 Beta - 'photo.php' SQL Injection
SQL injection vulnerability in photo.php in SiteX 0.7.4 beta allows remote attackers to execute arbitrary SQL commands v
23RISK
open ↗Exploit-DB✓ VexDay Proof
Lexmark Multiple Laser printers - Remote Stack Overflow
Stack-based buffer overflow in the base, IPDS DLE, Forms DLE, Barcode DLE, Prescribe DLE, and Printcryption DLE componen
23RISK
open ↗Exploit-DB✓ VexDay Proof
INVOhost - SQL Injection
Multiple SQL injection vulnerabilities in INVOhost 3.4 allow remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Exploit-DB✓ VexDay Proof
justVisual 2.0 - 'index.php' Local File Inclusion
Directory traversal vulnerability in index.php in justVisual CMS 2.0, when magic_quotes_gpc is disabled, allows remote a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox 3.6 - 'gfxTextRun::SanitizeGlyphRuns()' Remote Memory Corruption
The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.cpp in the browser engine in Mozilla Firefox 3.6 be
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sun Connection Update Manager for Solaris - Multiple Insecure Temporary File Creation Vulnerabilities
Certain patch-installation scripts in Oracle Solaris allow local users to append data to arbitrary files via a symlink a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component com_jresearch - 'Controller' Local File Inclusion
Directory traversal vulnerability in jresearch.php in the J!Research (com_jresearch) component for Joomla! allows remote
43RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox/Thunderbird/SeaMonkey - Multiple Memory Corruption Vulnerabilities
The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird befor
28RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Property - Local File Inclusion
Directory traversal vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows re
43RISK
open ↗Exploit-DB✓ VexDay Proof
Insky CMS 006-0111 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Insky CMS 006-0111, when register_globals is enabled, allow remote
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component SMEStorage - Local File Inclusion
Directory traversal vulnerability in the SMEStorage (com_smestorage) component before 1.1 for Joomla! allows remote atta
43RISK
open ↗Exploit-DB✓ VexDay Proof
RepairShop2 - 'index.php?Prod' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in RepairShop2 1.9.023 Trial, when magic_quotes_gpc is disabled, a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Lussumo Vanilla 1.1.10 - 'definitions.php' Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in definitions.php in Lussumo Vanilla 1.1.10, and possibly 0.9.2 and
23RISK
open ↗Exploit-DB✓ VexDay Proof
SpringSource (Multiple Products) - Multiple HTML Injection Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in SpringSource tc Server 6.0.20.B and earlier, Application Manageme
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mini-CMS RibaFS 1.0 - Authentication Bypass
SQL injection vulnerability in admin/login.php in Mini CMS RibaFS 1.0, when magic_quotes_gpc is disabled, allows remote
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Safari 4.0.5 - Object Tag 'JavaScriptCore.dll' Crash (Denial of Service)
JavaScriptCore.dll, as used in Apple Safari 4.0.5 on Windows XP SP3, allows remote attackers to cause a denial of servic
23RISK
open ↗Exploit-DB✓ VexDay Proof
Uiga Fan Club - SQL Injection
SQL injection vulnerability in index.php in Uiga Fan Club, as downloaded on 20100310, allows remote attackers to execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebMaid CMS 0.2-6 Beta - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in WebMaid CMS 0.2-6 Beta and earlier allow remote attackers to execu
23RISK
open ↗Exploit-DB✓ VexDay Proof
NotSopureEdit 1.4.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in templates/template.php in notsoPureEdit 1.4.1 and earlier, when register_glob
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebMaid CMS 0.2-6 Beta - Multiple Remote File Inclusions
Multiple directory traversal vulnerabilities in WebMaid CMS 0.2-6 Beta and earlier allow remote attackers to read arbitr
23RISK
open ↗Exploit-DB✓ VexDay Proof
Woltlab Burning Board Teamsite Hack 3.0 - 'ts_other.php' SQL Injection
SQL injection vulnerability in ts_other.php in the Teamsite Hack plugin 3.0 and earlier for WoltLab Burning Board allows
23RISK
open ↗Exploit-DB✓ VexDay Proof
Pay Per Watch & Bid Auktions System - 'auktion.php?id_auk' Blind SQL Injection
SQL injection vulnerability in auktion.php in Pay Per Watch & Bid Auktions System allows remote attackers to execute arb
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.