Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,064cataloged exploits
37,667CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,044GitHub PoC 15,521VulnCheck XDB 9,080Nuclei 4,432Metasploit 3,505✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
CactuSoft CactuShop 5.0/5.1 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in popuplargeimage.asp in CactuShop 5.x allows remote attackers to inject arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
Interchange 4.8.x/5.0 - Remote Information Disclosure
Interchange before 5.0.1 allows remote attackers to "expose the content of arbitrary variables" and read or modify sensi
23RISK
open ↗Exploit-DB✓ VexDay Proof
LinBit Technologies LINBOX Officeserver - Remote Authentication Bypass
LINBOX LIN:BOX allows remote attackers to bypass authentication, obtain sensitive information, or gain access via a dire
23RISK
open ↗Exploit-DB✓ VexDay Proof
MPlayer 0.9/1.0 - Remote HTTP Header Buffer Overflow
Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute ar
28RISK
open ↗Exploit-DB✓ VexDay Proof
WebCT Campus Edition 3.8/4.x - HTML Injection
Cross-site scripting (XSS) vulnerability in WebCT Campus Edition 4.1.1.5 allows remote attackers to inject arbitrary web
23RISK
open ↗Exploit-DB✓ VexDay Proof
Alan Ward A-CART 2.0 - 'category.asp?catcode' SQL Injection (2)
SQL injection vulnerability in category.asp in A-CART Pro and A-CART 2.0 allows remote attackers to gain privileges via
23RISK
open ↗Exploit-DB✓ VexDay Proof
Fresh Guest Book 1.0/2.x - HTML Injection
Cross-site scripting (XSS) vulnerability in guest.cgi in Fresh Guest Book allows remote attackers to inject arbitrary we
23RISK
open ↗Exploit-DB✓ VexDay Proof
PhotoPost PHP Pro 3.x/4.x - 'showgallery.php' Multiple SQL Injections
Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' pass
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ethereal 0.10.0 < 0.10.2 - IGAP Overflow
Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly
35RISK
open ↗Exploit-DB✓ VexDay Proof
RealSecure / Blackice - 'iss_pam1.dll' Remote Overflow
Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, a
60RISK
open ↗Exploit-DB✓ VexDay Proof
eSignal 7.6 - STREAMQUOTE Remote Buffer Overflow
Stack-based buffer overflow in WinSig.exe in eSignal 7.5 and 7.6 allows remote attackers to execute arbitrary code via a
23RISK
open ↗Exploit-DB✓ VexDay Proof
NetSupport School 7.0/7.5 - Weak Password Encryption
Invision NetSupport School Pro uses a weak encryption algorithm to encrypt passwords, which allows local users to obtain
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ethereal - EIGRP Dissector TLV_IP_INT Long IP Remote Denial of Service
Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly
35RISK
open ↗Exploit-DB✓ VexDay Proof
NSTX 1.0/1.1 - Remote Denial of Service
nstxd in Nstx 1.1 beta3 and earlier allows remote attackers to cause a denial of service (crash) via a large packet, whi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - ASN.1 Remote (MS04-007)
Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microso
60RISK
open ↗Exploit-DB✓ VexDay Proof
NexGen FTP Server 1.0/2.x - Directory Traversal
Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list
23RISK
open ↗Exploit-DB✓ VexDay Proof
Topic Calendar 1.0.1 - 'Calendar_Scheduler.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in calendar_scheduler.php in the Topic Calendar 1.0.1 module for phpBB allows r
23RISK
open ↗Exploit-DB✓ VexDay Proof
Trend Micro Interscan VirusWall localweb - Directory Traversal
Directory traversal vulnerability in Trend Micro Interscan Web Viruswall in InterScan VirusWall 3.5x allows remote attac
23RISK
open ↗Exploit-DB✓ VexDay Proof
PicoPhone Internet Phone 1.63 - Remote Buffer Overflow
Buffer overflow in the logging function in Picophone 1.63 and earlier allows remote attackers to execute arbitrary code
23RISK
open ↗Exploit-DB✓ VexDay Proof
HP Web Jetadmin 7.5.2456 - Arbitrary Command Execution
Directory traversal vulnerability in setinfo.hts in HP Web Jetadmin 7.5.2546 allows remote authenticated attackers to re
45RISK
open ↗Exploit-DB✓ VexDay Proof
HP Web Jetadmin 7.5.2456 - setinfo.hts Script Directory Traversal
Directory traversal vulnerability in setinfo.hts in HP Web Jetadmin 7.5.2546 allows remote authenticated attackers to re
45RISK
open ↗Exploit-DB✓ VexDay Proof
HP Web Jetadmin 7.5.2456 - Printer Firmware Update Script Arbitrary File Upload
devices_update_printer_fw_upload.hts in HP Web JetAdmin 7.5.2546, when no password is set, allows remote attackers to up
28RISK
open ↗Exploit-DB✓ VexDay Proof
Mythic Entertainment Dark Age of Camelot 1.6x - Encryption Key Signing
Dark Age of Camelot before 1.68 live patch does not sign the RSA public key, which could allow remote malicious servers
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ipswitch WS_FTP Server 4.0.2 - ALLO Remote Buffer Overflow
Multiple buffer overflows in Ipswitch WS_FTP Server 4.0.2 (1) allow remote authenticated users to execute arbitrary code
23RISK
open ↗Exploit-DB✓ VexDay Proof
Invision Power Services Invision Gallery 1.0.1 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrar
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sun Solaris 2.6/7.0/8/9 - vfs_getvfssw function Privilege Escalation
Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
xweb 1.0 - Directory Traversal
Directory traversal vulnerability in xweb 1.0 allows remote attackers to download arbitrary files via a .. (dot dot) in
23RISK
open ↗Exploit-DB✓ VexDay Proof
Invision Power Top Site List 1.0/1.1 - 'id' SQL Injection
SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
Expinion.net News Manager Lite 2.5 - 'search.asp' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
Expinion.net News Manager Lite 2.5 - 'more.asp?ID' SQL Injection
Multiple SQL injection vulnerabilities in News Manager Lite 2.5 allow remote attackers to execute arbitrary SQL code via
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.