Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,429GitHub PoC 14,270VulnCheck XDB 8,693Nuclei 4,299Metasploit 3,474✓ verified onlyrecentpopularrisk
24,455 exploits
Exploit-DB✓ VexDay Proof
Barcodewiz ActiveX Control 2.52 - 'Barcodewiz.dll' Overwrite (SEH)
Stack-based buffer overflow in the Verify function in the BarCodeWiz ActiveX control 2.0 and 2.52 (BarcodeWiz.dll) allow
23RISK
open ↗Exploit-DB✓ VexDay Proof
CA (Multiple Products) - Console Server / 'InoCore.dll' Remote Code Execution
CA Anti-Virus for the Enterprise r8 and Threat Manager r8 before 20070510 use weak permissions (NULL security descriptor
23RISK
open ↗Exploit-DB✓ VexDay Proof
IncrediMail IMMenuShellExt - ActiveX Control Buffer Overflow
Stack-based buffer overflow in the DoWebMenuAction function in the IncrediMail IMMenuShellExt ActiveX control (ImShExt.d
35RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe RoboHelp - Frameset-7.HTML Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp X5, 6, and Server 6 allows remote attackers to inject arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
Taltech Tal Bar Code - ActiveX Control Buffer Overflow
The SaveBarCode function in the Taltech Tal Bar Code ActiveX control allows remote attackers to cause a denial of servic
23RISK
open ↗Exploit-DB✓ VexDay Proof
Campsite 2.6.1 - 'ArticleData.php?g_documentRoot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Campsite 2.6.1 - 'article.php?g_documentRoot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Python 2.5 - 'PyLocale_strxfrm' Remote Information Leak
Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect
28RISK
open ↗Exploit-DB✓ VexDay Proof
Campsite 2.6.1 - 'ArticleImage.php?g_documentRoot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Campsite 2.6.1 - '/implementation/Management/db_connect.php?g_documentRoot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Campsite 2.6.1 - 'Alias.php?g_documentRoot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1 - 'TBLinf32.dll' ActiveX Control Remote Code Execution
The tblinf32.dll (aka vstlbinf.dll) ActiveX control for Internet Explorer 5.01, 6 SP1, and 7 uses an incorrect IObjectsa
35RISK
open ↗Exploit-DB✓ VexDay Proof
Campsite 2.6.1 - 'ArticleIndex.php?g_documentRoot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
SmartCode VNC Manager 3.6 - 'scvncctrl.dll' Denial of Service
Heap-based buffer overflow in the ConnectAsyncEx function in VNC Viewer ActiveX control (scvncctrl.dll) in the SmartCode
23RISK
open ↗Exploit-DB✓ VexDay Proof
Campsite 2.6.1 - 'ArticlePublish.php?g_documentRoot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Campsite 2.6.1 - 'ArticleAttachment.php?g_documentRoot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Campsite 2.6.1 - 'ArticleComment.php?g_documentRoot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Campsite 2.6.1 - 'ArticleTypeField.php?g_documentRoot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Campsite 2.6.1 - 'template.php?g_documentRoot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Campsite 2.6.1 - 'Country.php?g_documentRoot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Campsite 2.6.1 - 'SystemPref.php?g_documentRoot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Campsite 2.6.1 - 'UserType.php?g_documentRoot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Campsite 2.6.1 - 'ShortURL.php?g_documentRoot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Campsite 2.6.1 - 'topic.php?g_documentRoot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Advanced Guestbook 2.4.2 - 'Lang' Cookie Local File Inclusion
Directory traversal vulnerability in Advanced Guestbook 2.4.2 allows remote attackers to bypass .htaccess settings, and
23RISK
open ↗Exploit-DB✓ VexDay Proof
Campsite 2.6.1 - 'ArticleType.php?g_documentRoot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Campsite 2.6.1 - 'TimeUnit.php?g_documentRoot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Campsite 2.6.1 - '/implementation/Management/configuration.php?g_documentRoot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Campsite 2.6.1 - 'user.php?g_documentRoot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Campsite 2.6.1 - 'Subscription.php?g_documentRoot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.