Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,064cataloged exploits
37,667CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,044GitHub PoC 15,521VulnCheck XDB 9,080Nuclei 4,432Metasploit 3,505✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
Layton Technology HelpBox 3.0.1 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Layton HelpBox 3.0.1 allow remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
Serena TeamTrack 6.1.1 - Remote Authentication Bypass
Serena TeamTrack 6.1.1 allows remote attackers to obtain sensitive information such as user names, versions, and databas
23RISK
open ↗Exploit-DB✓ VexDay Proof
SCI Photo Chat 3.4.9 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in SCI Photo Chat Server 3.4.9 allows remote attackers to execute arbitrary web
23RISK
open ↗Exploit-DB✓ VexDay Proof
Medal of Honor - Remote Buffer Overflow (PoC)
Buffer overflow in Medal of Honor (1) Allied Assault 1.11v9 and earlier, (2) Breakthrough 2.40b and earlier, and (3) Spe
50RISK
open ↗Exploit-DB✓ VexDay Proof
British National Corpus SARA - Remote Buffer Overflow
Buffer overflow in British National Corpus SARA (sarad) allows remote attackers to execute arbitrary code by calling the
23RISK
open ↗Exploit-DB✓ VexDay Proof
SCO Multi-channel Memorandum Distribution Facility - Multiple Vulnerabilities
Multiple unknown vulnerabilities in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - Utility Manager All-in-One (MS04-019)
Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which all
28RISK
open ↗Exploit-DB✓ VexDay Proof
Outblaze Webmail - HTML Injection
Cross-site scripting (XSS) vulnerability in Outblaze Email allows remote attackers to inject arbitrary web script or HTM
23RISK
open ↗Exploit-DB✓ VexDay Proof
CuteNews 1.3 - Comment HTML Injection
Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in Cu
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Task Scheduler (XP/2000) - '.job' (MS04-022)
Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, al
35RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Fusion Database Backup - Information Disclosure
The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups direct
23RISK
open ↗Exploit-DB✓ VexDay Proof
Unreal Tournament 2004 - 'Secure' Remote Overflow (Metasploit)
The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier,
60RISK
open ↗Exploit-DB✓ VexDay Proof
Merak Mail Server 7.4.5 - HTML Message Body Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - Universal Language Utility Manager (MS04-019)
Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which all
28RISK
open ↗Exploit-DB✓ VexDay Proof
Merak Mail Server 7.4.5 - 'address.html' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
Merak Mail Server 7.4.5 - address.html Full Path Disclosure
The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sens
23RISK
open ↗Exploit-DB✓ VexDay Proof
Gallery 1.4.4 - Remote Server-Side Script Execution
The set_time_limit function in Gallery before 1.4.4_p2 deletes non-image files in a temporary directory every 30 seconds
23RISK
open ↗Exploit-DB✓ VexDay Proof
Merak Mail Server 7.4.5 - 'attachment.html?attachmentpage_text_error' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
Merak Mail Server 7.4.5 - 'calendar.html?schedule' SQL Injection
SQL injection vulnerability in calendar.html in Merak Mail Server 5.2.7 allows remote attackers to execute arbitrary SQL
23RISK
open ↗Exploit-DB✓ VexDay Proof
Merak Mail Server 7.4.5 - 'settings.html' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - POSIX Subsystem Privilege Escalation (MS04-020)
Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which all
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT 4.0/2000 - POSIX Subsystem Local Buffer Overflow / Local Privilege Escalation (MS04-020)
The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain pa
71RISK
open ↗Exploit-DB✓ VexDay Proof
RaXnet Cacti 0.6.x/0.8.x - 'Auth_Login.php' SQL Injection
SQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
CuteNews 1.3.1 - 'show_archives.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in Cu
23RISK
open ↗Exploit-DB✓ VexDay Proof
Gattaca Server 2003 POP3 - Denial of Service
POP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote authenticated users to cause a denial of service (applicatio
23RISK
open ↗Exploit-DB✓ VexDay Proof
Gattaca Server 2003 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in web.tmpl in Gattaca Server 2003 1.1.10.0 allows remote attackers to inject a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Gattaca Server 2003 - 'Language' Path Exposure
Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00"
23RISK
open ↗Exploit-DB✓ VexDay Proof
Gattaca Server 2003 - Null Byte Full Path Disclosure
Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00"
23RISK
open ↗Exploit-DB✓ VexDay Proof
BoardPower Forum - 'ICQ.cgi' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in icq.cgi in Board Power 2.04PF allows remote attackers to inject arbitrary we
23RISK
open ↗Exploit-DB✓ VexDay Proof
Gattaca Server 2003 - 'web.tmpl?Language' CPU Consumption (Denial of Service)
Gattaca Server 2003 1.1.10.0 allows remote attackers to cause a denial of service (CPU consumption) via directory specif
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.