Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,066cataloged exploits
37,668CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,044GitHub PoC 15,521VulnCheck XDB 9,080Nuclei 4,434Metasploit 3,505✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
AllMyVisitors 0.x - 'info.inc.php' Arbitrary Code Execution
PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyG
23RISK
open ↗Exploit-DB✓ VexDay Proof
YABB SE 1.5 - 'Quote' SQL Injection
SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords v
23RISK
open ↗Exploit-DB✓ VexDay Proof
Freeform Interactive Purge 1.4.7/Purge Jihad 2.0.1 Game Client - Remote Buffer Overflow
Buffer overflow in Purge Jihad 2.0.1 and earlier allows remote game servers to execute arbitrary code via an information
23RISK
open ↗Exploit-DB✓ VexDay Proof
ProductCart 1.x/2.x - Weak Cryptography
EarlyImpact ProductCart uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the
23RISK
open ↗Exploit-DB✓ VexDay Proof
ACLogic CesarFTP 0.99 - Remote Resource Exhaustion (Denial of Service)
CesarFTP 0.99e allows remote attackers to cause a denial of service (CPU consumption) via a long RETR parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
RobotFTP Server 1.0/2.0 - 'Username' Buffer Overflow (1)
Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly
23RISK
open ↗Exploit-DB✓ VexDay Proof
AllMyGuests 0.x - 'info.inc.php' Arbitrary Code Execution
PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyG
23RISK
open ↗Exploit-DB✓ VexDay Proof
CitrusDB 0.3.6 - Remote Authentication Bypass
CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - ASN.1 'LSASS.exe' Remote Denial of Service (MS04-007)
Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microso
60RISK
open ↗Exploit-DB✓ VexDay Proof
KarjaSoft Sami HTTP Server 1.0.4 - GET Buffer Overflow
Buffer overflow in KarjaSoft Sami HTTP Server 1.0.4 allows remote attackers to cause a denial of service (crash) and pos
23RISK
open ↗Exploit-DB✓ VexDay Proof
rsync 2.5.7 - Local Stack Overflow / Local Privilege Escalation
Buffer overflow in the open_socket_out function in socket.c for rsync 2.5.7 and earlier allows local users to cause a de
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1 - ITS Protocol Zone Bypass (MS04-013)
The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to
35RISK
open ↗Exploit-DB✓ VexDay Proof
Sami FTP Server 1.1.3 - Library Crafted GET Remote Denial of Service
The samiftp.dll library in Sami FTP Server 1.1.3 allows remote authenticated users to cause a denial of service (pmsyste
23RISK
open ↗Exploit-DB✓ VexDay Proof
vBulletin 3.0 - 'search.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.php for Jelsoft vBulletin 3.0.0 RC4 allows remote attackers to inject
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sami FTP Server 1.1.3 - Invalid Command Argument Local Denial of Service
The samiftp.dll library in Sami FTP Server 1.1.3 allows local users to cause a denial of service (pmsystem.exe crash) by
23RISK
open ↗Exploit-DB✓ VexDay Proof
XFree86 4.x - CopyISOLatin1Lowered Font_Name Buffer Overflow
Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, a
28RISK
open ↗Exploit-DB✓ VexDay Proof
Crob FTP Server 3.5.2 - Remote Denial of Service
Crob FTP daemon 3.5.2 allows remote attackers to cause a denial of service (crash) by repeatedly connecting to and disco
23RISK
open ↗Exploit-DB✓ VexDay Proof
Macallan Mail Solution Macallan Mail Solution 2.8.4.6 (Build 260) - Web Interface Authentication Bypass
Macallan Mail Solution 2.8.4.6 (Build 260), and possibly earlier versions, allows remote attackers to bypass authenticat
23RISK
open ↗Exploit-DB✓ VexDay Proof
VisualShapers EZContents 1.x/2.0 - 'archivednews.php' Arbitrary File Inclusion
Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arb
23RISK
open ↗Exploit-DB✓ VexDay Proof
VisualShapers EZContents 1.x/2.0 - 'db.php' Arbitrary File Inclusion
Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arb
23RISK
open ↗Exploit-DB✓ VexDay Proof
BolinTech DreamFTP Server 1.2 (1.02/TryFTP 1.0.0.1) - Remote User Name Format String
Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string
50RISK
open ↗Exploit-DB✓ VexDay Proof
BosDev BosDates 3.x - SQL Injection
SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Monkey HTTP Daemon 0.x - Missing Host Field Denial of Service
The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial
23RISK
open ↗Exploit-DB✓ VexDay Proof
Maxwebportal 1.3x - 'down.asp' HTTP_REFERER Cross-Site Scripting
Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web scri
23RISK
open ↗Exploit-DB✓ VexDay Proof
Maxwebportal 1.3x - Personal Message 'SendTo' Cross-Site Scripting
Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web scri
23RISK
open ↗Exploit-DB✓ VexDay Proof
EvolutionX - Multiple Remote Buffer Overflow Vulnerabilities
Multiple buffer overflows in EvolutionX 3921 and 3935 allow remote attackers to cause a denial of service (hang) via (1)
23RISK
open ↗Exploit-DB✓ VexDay Proof
ClamAV Daemon 0.65 - UUEncoded Message Denial of Service
libclamav in Clam AntiVirus 0.65 allows remote attackers to cause a denial of service (crash) via a uuencoded e-mail mes
28RISK
open ↗Exploit-DB✓ VexDay Proof
Nadeo Game Engine - Remote Denial of Service
Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service
23RISK
open ↗Exploit-DB✓ VexDay Proof
Red-M Red-Alert 3.1 - Remote Denial of Service
Red-M Red-Alert 2.7.5 with software 3.1 build 24 allows remote attackers to cause a denial of service (reboot and loss o
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 6.x/7.x 'Reviews' Module - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitr
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.