Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,003cataloged exploits
37,620CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,011GitHub PoC 15,501VulnCheck XDB 9,077Nuclei 4,427Metasploit 3,505✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
McNews 1.x - 'install.php' Arbitrary File Inclusion
PHP remote file inclusion vulnerability in install.php in mcNews 1.3 and earlier allows remote attackers to execute arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000/2003 - Graphical Device Interface Library Denial of Service
The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (
35RISK
open ↗Exploit-DB✓ VexDay Proof
iSnooker 1.6.8 - Local Password Disclosure
ThePoolClub (1) iPool and (2) iSnooker 1.6.81 and earlier stores usernames and passwords in cleartext in the MyDetails.t
23RISK
open ↗Exploit-DB✓ VexDay Proof
PunBB 1.2.3 - Multiple HTML Injection Vulnerabilities
Cross-site scripting (XSS) vulnerability in PunBB 1.2.3 allows remote attackers to inject arbitrary web script or HTML v
23RISK
open ↗Exploit-DB✓ VexDay Proof
iPool 1.6.81 - Local Password Disclosure
ThePoolClub (1) iPool and (2) iSnooker 1.6.81 and earlier stores usernames and passwords in cleartext in the MyDetails.t
23RISK
open ↗Exploit-DB✓ VexDay Proof
GoodTech Telnet Server < 5.0.7 - Buffer Overflow Crash
Buffer overflow in the administration web server for GoodTech Telnet Server 4.0 and 5.0, and possibly all versions befor
50RISK
open ↗Exploit-DB✓ VexDay Proof
ZPanel 2.5 - SQL Injection
SQL injection vulnerability in ZPanel 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) uname pa
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHPOpenChat 2.3.4/3.0.1 - 'poc_loginform.php?phpbb_root_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in PHPOpenChat 3.0.1 and earlier allow remote attackers to execute ar
28RISK
open ↗Exploit-DB✓ VexDay Proof
PHPOpenChat 2.3.4/3.0.1 - 'ENGLISH_poc.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in PHPOpenChat 3.0.1 and earlier allow remote attackers to execute ar
28RISK
open ↗Exploit-DB✓ VexDay Proof
PHPOpenChat 2.3.4/3.0.1 - 'poc.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in PHPOpenChat 3.0.1 and earlier allow remote attackers to execute ar
28RISK
open ↗Exploit-DB✓ VexDay Proof
Frank McIngvale LuxMan 0.41 - Local Buffer Overflow
Buffer overflow in luxman before 0.41, if used with certain insecure svgalib libraries, allows local users to execute ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHPAdsNew 2.0.4 - 'AdFrame.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in adframe.php in phpAdsNew 2.0.4-pr1, when register_globals is enabled, allows
23RISK
open ↗Exploit-DB✓ VexDay Proof
SimpGB 1.0 - 'Guestbook.php' SQL Injection
SQL injection vulnerability in gb_new.inc in SimpGB allows remote attackers to execute arbitrary SQL commands via the qu
23RISK
open ↗Exploit-DB✓ VexDay Proof
Phorum 5.0.14 - Multiple Subject and Attachment HTML Injection Vulnerabilities
Cross-site scripting (XSS) vulnerability in Phorum before 5.0.14a allows remote attackers to inject arbitrary web script
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Suite/Firefox/Thunderbird - Nested Anchor Tag Status Bar Spoofing
Mozilla Firefox 1.0.1 and possibly other versions, including Mozilla and Thunderbird, allows remote attackers to spoof t
23RISK
open ↗Exploit-DB✓ VexDay Proof
PaX - Double-Mirrored VMA munmap Privilege Escalation
Unknown vulnerability in PaX from the September 2003 release to 2.2 before 2005.03.05, related to SEGMEXEC or RANDEXEC a
23RISK
open ↗Exploit-DB✓ VexDay Proof
LimeWire 4.1.2 < 4.5.6 - 'GET' Remote File Read
LimeWire 4.1.2 through 4.5.6 allows remote attackers to read arbitrary files by specifying the full pathname in a Gnutel
23RISK
open ↗Exploit-DB✓ VexDay Proof
HolaCMS 1.2.x/1.4.x Voting Module - Directory Traversal Remote File Corruption
Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sentinel LM 7.x - UDP License Service Remote Buffer Overflow
Buffer overflow in the Sentinel LM (Lservnt) service in the Sentinel License Manager 7.2.0.2 allows remote attackers to
60RISK
open ↗Exploit-DB✓ VexDay Proof
PAFileDB 1.1.3/2.1.1/3.0/3.1 - 'category.php?start' SQL Injection
SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
HolaCMS 1.2/1.4.x Voting Module - Remote File Corruption
HolaCMS 1.4.9 does not restrict file access to the holaDB/votes directory, which allows remote attackers to overwrite ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
PAFileDB 1.1.3/2.1.1/3.0/3.1 - 'viewall.php?start' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows rem
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ethereal 0.10.9 (Windows) - '3G-A11' Remote Buffer Overflow
The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting st
23RISK
open ↗Exploit-DB✓ VexDay Proof
PAFileDB 1.1.3/2.1.1/3.0/3.1 - 'category.php?start' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows rem
23RISK
open ↗Exploit-DB✓ VexDay Proof
PAFileDB 1.1.3/2.1.1/3.0/3.1 - 'viewall.php?start' SQL Injection
SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
SocialMPN - Arbitrary File Injection
PHP remote file inclusion vulnerability in article mode for modules.php in SocialMPN allows remote attackers to execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
MySQL 4.x - CREATE FUNCTION Arbitrary libc Code Execution
MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to
28RISK
open ↗Exploit-DB✓ VexDay Proof
MySQL 4.x - CREATE FUNCTION mysql.func Table Arbitrary Library Injection
MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to
28RISK
open ↗Exploit-DB✓ VexDay Proof
UBBCentral UBB.Threads 6.0 - 'Printthread.php' SQL Injection
SQL injection vulnerability in printthread.php in UBB.Threads allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpBB 2.0.12 - Session Handling Authentication Bypass
sessions.php in phpBB 2.0.12 and earlier allows remote attackers to gain administrator privileges via the autologinid va
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.