Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,003cataloged exploits
37,620CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,011GitHub PoC 15,501VulnCheck XDB 9,077Nuclei 4,427Metasploit 3,505✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
The Includer CGI 1.0 - Remote Command Execution (2)
includer.cgi in The Includer allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the U
23RISK
open ↗Exploit-DB✓ VexDay Proof
PostNuke Phoenix 0.760 RC3 - 'Module' Cross-Site Scripting
Multiple cross-site scripting vulnerabilities in PostNuke 0.760-RC3 allow remote attackers to inject arbitrary web scrip
23RISK
open ↗Exploit-DB✓ VexDay Proof
The Includer CGI 1.0 - Remote Command Execution (3)
includer.cgi in The Includer allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the U
23RISK
open ↗Exploit-DB✓ VexDay Proof
PostNuke Phoenix 0.760 RC3 - 'OP' Cross-Site Scripting
Multiple cross-site scripting vulnerabilities in PostNuke 0.760-RC3 allow remote attackers to inject arbitrary web scrip
23RISK
open ↗Exploit-DB✓ VexDay Proof
AN HTTPD 1.42 - Arbitrary Log Content Injection
CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide
23RISK
open ↗Exploit-DB✓ VexDay Proof
AN HTTPD - 'CMDIS.dll' Remote Buffer Overflow (PoC)
Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via
23RISK
open ↗Exploit-DB✓ VexDay Proof
SGI IRIX 6.5.22 - GR_OSView Information Disclosure
gr_osview in SGI IRIX 6.5.22, and possibly other 6.5 versions, does not drop privileges when opening description files w
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linksys WET11 - Password Update Remote Authentication Bypass
Linksys WET11 1.5.4 allows remote attackers to change the password without providing the original password via the data
23RISK
open ↗Exploit-DB✓ VexDay Proof
P2P Share Spy 2.2 - Local Password Disclosure
Rebrand P2P Share Spy 2.2 stores the user password in plaintext in the txtPassword value in the registry, which allows l
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 6.x < 7.6 Top module - SQL Injection
SQL injection vulnerability in the Top module for PHP-Nuke 6.x through 7.6 allows remote attackers to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 7.6 Web_Links Module - Multiple SQL Injections
Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 7.6 allow remote attackers to execute arbitr
23RISK
open ↗Exploit-DB✓ VexDay Proof
SGI IRIX 6.5.22 - GR_OSView Local Arbitrary File Overwrite
gr_osview in SGI IRIX does not drop privileges before opening files, which allows local users to overwrite arbitrary fil
23RISK
open ↗Exploit-DB✓ VexDay Proof
Active Auction House - 'ItemInfo.asp' SQL Injection
Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpBB 2.0.13 Linkz Pro Module - SQL Injection
Multiple SQL injection vulnerabilities in SnailSource phpBB 2.0.x mods allow remote attackers to execute arbitrary SQL c
23RISK
open ↗Exploit-DB✓ VexDay Proof
CubeCart 2.0.x - 'tellafriend.php?product' Full Path Disclosure
CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.ph
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 7.6 Web_Links Module - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 7.6 allow remote attackers to inject arbitrary web scrip
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Lotus Domino Server 6.5.1 Web Service - Remote Denial of Service
NLSCCSTR.DLL in the web service in IBM Lotus Domino Server 6.5.1, 6.0.3, and possibly other versions allows remote attac
23RISK
open ↗Exploit-DB✓ VexDay Proof
Active Auction House - 'account.asp?ReturnURL' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Active Auction House allow remote attackers to inject arbitrary w
23RISK
open ↗Exploit-DB✓ VexDay Proof
Active Auction House - 'start.asp?ReturnURL' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Active Auction House allow remote attackers to inject arbitrary w
23RISK
open ↗Exploit-DB✓ VexDay Proof
CubeCart 2.0.x - 'view_product.php?product' Full Path Disclosure
CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.ph
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpBB 2.0.13 DLMan Pro Module - SQL Injection
Multiple SQL injection vulnerabilities in SnailSource phpBB 2.0.x mods allow remote attackers to execute arbitrary SQL c
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ocean12 Membership Manager Pro - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in main.asp for Ocean12 Membership Manager Pro 1.x allows remote attackers to i
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 7.6 - 'banners.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 7.6 allow remote attackers to inject arbitrary web scrip
23RISK
open ↗Exploit-DB✓ VexDay Proof
CubeCart 2.0.x - 'index.php' Multiple Full Path Disclosures
CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.ph
23RISK
open ↗Exploit-DB✓ VexDay Proof
FTP Now 2.6.14 - Local Password Disclosure
FTP Now 2.6.14 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local use
23RISK
open ↗Exploit-DB✓ VexDay Proof
Active Auction House - 'sendpassword.asp' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Active Auction House allow remote attackers to inject arbitrary w
23RISK
open ↗Exploit-DB✓ VexDay Proof
CubeCart 2.0.x - 'view_cart.php?add' Full Path Disclosure
CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.ph
23RISK
open ↗Exploit-DB✓ VexDay Proof
Active Auction House - 'default.asp' Multiple SQL Injections
Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
Active Auction House - 'WatchThisItem.asp' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Active Auction House allow remote attackers to inject arbitrary w
23RISK
open ↗Exploit-DB✓ VexDay Proof
Aeon 0.2a - Local Linux (1)
Buffer overflow in the getConfig function in Aeon 0.2a and earlier allows local users to gain privileges via a long HOME
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.