Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,003cataloged exploits
37,620CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,011GitHub PoC 15,501VulnCheck XDB 9,077Nuclei 4,427Metasploit 3,505✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
3Com 3CDaemon FTP - Unauthorized 'USER' Remote Buffer Overflow
Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service
50RISK
open ↗Exploit-DB✓ VexDay Proof
paFaq beta4 - 'search.php?search_item' SQL Injection
SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQ
23RISK
open ↗Exploit-DB✓ VexDay Proof
BibORB 1.3.2 Login Module - Multiple SQL Injections
SQL injection vulnerability in BibORB 1.3.2, and possibly earlier versions, allows remote attackers to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
paFaq beta4 - 'comment.php' Multiple SQL Injections
SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQ
23RISK
open ↗Exploit-DB✓ VexDay Proof
paFaq beta4 - 'question.php' Multiple SQL Injections
SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQ
23RISK
open ↗Exploit-DB✓ VexDay Proof
3Com FTP Server 2.0 - Remote Overflow
Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service
50RISK
open ↗Exploit-DB✓ VexDay Proof
BibORB 1.3.2 - 'index.php' Traversal Arbitrary File Manipulation
Directory traversal vulnerability in index.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
BibORB 1.3.2 - 'bibindex.php?search' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in bibindex.php for BibORB 1.3.2, and possibly earlier versions, allows remote
23RISK
open ↗Exploit-DB✓ VexDay Proof
paFaq beta4 - 'answer.php?offset' SQL Injection
SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQ
23RISK
open ↗Exploit-DB✓ VexDay Proof
BibORB 1.3.2 - Add Database 'Description' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in bibindex.php for BibORB 1.3.2, and possibly earlier versions, allows remote
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft ASP.NET 1.0/1.1 - Unicode Character Conversion Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attacker
28RISK
open ↗Exploit-DB✓ VexDay Proof
Typespeed 0.4.1 - Local Format String
Unknown vulnerability in typespeed 0.4.1 and earlier allows local users to gain privileges.
23RISK
open ↗Exploit-DB✓ VexDay Proof
CitrusDB 0.3.6 - 'importcc.php' Arbitrary Database Injection
CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows rem
23RISK
open ↗Exploit-DB✓ VexDay Proof
CitrusDB 0.3.6 - Arbitrary Local PHP File Inclusion
Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and local users to
23RISK
open ↗Exploit-DB✓ VexDay Proof
Savant Web Server 3.1 (French Windows)- Remote Buffer Overflow
Buffer overflow in Savant Web Server 3.1 allows remote attackers to execute arbitrary code via a long HTTP request.
23RISK
open ↗Exploit-DB✓ VexDay Proof
CitrusDB 0.3.6 - 'importcc.php' CSV File SQL Injection
SQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and earlier allows remote attackers to inject data via th
23RISK
open ↗Exploit-DB✓ VexDay Proof
vBulletin 3.0.4 - 'forumdisplay.php' Code Execution (2)
Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled,
23RISK
open ↗Exploit-DB✓ VexDay Proof
CitrusDB 0.3.6 - 'uploadcc.php' Arbitrary Database Injection
CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows rem
23RISK
open ↗Exploit-DB✓ VexDay Proof
vBulletin 3.0.4 - 'forumdisplay.php' Code Execution (1)
Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled,
23RISK
open ↗Exploit-DB✓ VexDay Proof
Brooky CubeCart 2.0.1/2.0.4 - 'index.php?language' Traversal Arbitrary File Access
Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via th
23RISK
open ↗Exploit-DB✓ VexDay Proof
Brooky CubeCart 2.0.1/2.0.4 - 'index.php?language' Cross-Site Scripting
index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-
23RISK
open ↗Exploit-DB✓ VexDay Proof
AWStats 6.4 - Denial of Service
Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of
23RISK
open ↗Exploit-DB✓ VexDay Proof
AWStats 6.4 - Denial of Service
awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmo
23RISK
open ↗Exploit-DB✓ VexDay Proof
MercuryBoard 1.1.1 - SQL Injection
SQL injection vulnerability in post.php for MercuryBoard 1.1.1 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
CA BrightStor ARCserve Backup - Remote Buffer Overflow (PoC)
Buffer overflow in the Discovery Service in BrightStor ARCserve Backup 9.0 through 11.1 allows remote attackers to execu
60RISK
open ↗Exploit-DB✓ VexDay Proof
Quake 3 Engine - Infostring Crash and Shutdown
The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown ga
23RISK
open ↗Exploit-DB✓ VexDay Proof
Armagetron Advanced 0.2.7.0 - Server Crash
Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of serv
33RISK
open ↗Exploit-DB✓ VexDay Proof
CMScore - SQL Injection
Multiple SQL injection vulnerabilities in CMScore allow remote attackers to execute arbitrary SQL commands via the (1) E
23RISK
open ↗Exploit-DB✓ VexDay Proof
MyPHP Forum 1.0 - SQL Injection
Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (
23RISK
open ↗Exploit-DB✓ VexDay Proof
Armagetron Advanced 0.2.7.0 - Server Crash
Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of s
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.