Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,064cataloged exploits
37,667CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,044GitHub PoC 15,521VulnCheck XDB 9,080Nuclei 4,432Metasploit 3,505✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
Apache 1.3.x mod_include - Local Buffer Overflow
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI
23RISK
open ↗Exploit-DB✓ VexDay Proof
best software SalesLogix 2000.0 - Multiple Vulnerabilities
Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot)
23RISK
open ↗Exploit-DB✓ VexDay Proof
SLX Server 6.1 - Arbitrary File Creation
Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot)
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Lotus Domino 6.x - Cross-Site Scripting / HTML Injection
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Do
23RISK
open ↗Exploit-DB✓ VexDay Proof
Monit 4.2 - Basic Authentication Remote Code Execution
Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute
28RISK
open ↗Exploit-DB✓ VexDay Proof
ProFTPd 1.2.10 - Remote Users Enumeration
ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which al
50RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NNTP Service (XPAT) - Denial of Service (MS04-036)
The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Ser
35RISK
open ↗Exploit-DB✓ VexDay Proof
CoolPHP 1.0 - Multiple Remote Input Validation Vulnerabilities
Directory traversal vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to access arbitrary files a
23RISK
open ↗Exploit-DB✓ VexDay Proof
YahooPOPs 1.6 - SMTP Port Buffer Overflow
Multiple stack-based buffer overflows in YPOPs! (aka YahooPOPS) 0.4 through 0.6 allow remote attackers to cause a denial
60RISK
open ↗Exploit-DB✓ VexDay Proof
Yak! Chat Client 2.x - FTP Server Directory Traversal
Directory traversal vulnerability in Digicraft Yak! server 2.0 through 2.1.2 allows remote attackers to read or write ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP - Weak Default Configuration
The Internet Connection Firewall (ICF) in Microsoft Windows XP SP2 is configured by default to trust sessmgr.exe, which
23RISK
open ↗Exploit-DB✓ VexDay Proof
ocPortal 1.0.3 - Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in ocPortal 1.0.3 and earlier allows remote attackers to execute ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
3Com 3CRADSL72 ADSL Wireless Router - Information Disclosure / Authentication Bypass
The 3COM Wireless router 3CRADSL72 running Boot Code 1.3d allows remote attackers to gain sensitive information such as
23RISK
open ↗Exploit-DB✓ VexDay Proof
Icecast 2.0.1 (Win32) - Remote Code Execution (2)
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RISK
open ↗Exploit-DB✓ VexDay Proof
DUclassmate 1.x - 'account.asp?MM-recordId' Arbitrary Password Modification
account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by
23RISK
open ↗Exploit-DB✓ VexDay Proof
DUforum 3.x - Login Form 'Password' SQL Injection
SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
DUforum 3.x - 'messages.asp?FOR_ID' SQL Injection
SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
DUforum 3.x - 'messageDetail.asp?MSG_ID' SQL Injection
SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
DUclassified 4.x - 'adDetail.asp' Multiple SQL Injections
Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authenti
23RISK
open ↗Exploit-DB✓ VexDay Proof
Monolith Games - Local Buffer Overflow (PoC)
Buffer overflow in Monolith games including (1) Alien versus Predator 2 1.0.9.6 and earlier, (2) Blood 2 2.1 and earlier
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Core 1.2 - HTTP Splitting
CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting
28RISK
open ↗Exploit-DB✓ VexDay Proof
MySQL 3.x/4.x - ALTER TABLE/RENAME Forces Old Permission Checks
MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights o
28RISK
open ↗Exploit-DB✓ VexDay Proof
DCP-Portal 3.7/4.x/5.x - 'news.php?cid' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and earlier allow remote attackers to inject arb
23RISK
open ↗Exploit-DB✓ VexDay Proof
DCP-Portal 3.7/4.x/5.x - 'calendar.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and earlier allow remote attackers to inject arb
23RISK
open ↗Exploit-DB✓ VexDay Proof
Icecast 2.0.1 (Win32) - Remote Code Execution (1)
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft ASP.NET 1.x - URI Canonicalization Unauthorized Web Access
The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .asp
45RISK
open ↗Exploit-DB✓ VexDay Proof
DCP-Portal 3.7/4.x/5.x - 'calendar.php' HTTP Response Splitting
CRLF injection vulnerability in calendar.php in DCP-Portal 5.3.2 and earlier allows remote attackers to conduct HTTP res
23RISK
open ↗Exploit-DB✓ VexDay Proof
DCP-Portal 3.7/4.x/5.x - 'announcement.php?cid' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and earlier allow remote attackers to inject arb
23RISK
open ↗Exploit-DB✓ VexDay Proof
IPSwitch WhatsUp Gold 8.03 - Remote Buffer Overflow
Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to
50RISK
open ↗Exploit-DB✓ VexDay Proof
W-Agora 4.1.6a - 'login.php?loginuser' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in w-Agora 4.1.6a allow remote attackers to execute arbitrary web sc
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.