Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,453cataloged exploits
37,908CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,237GitHub PoC 15,653VulnCheck XDB 9,134Nuclei 4,441Metasploit 3,506✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
Geeklog 1.3.7 - 'users.php?uid' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7 allow remote attackers to inject arbitrary web scri
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHPPass 2 - 'AccessControl.php' SQL Injection
SQL injection vulnerability in accesscontrol.php in PhpPass 2 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
Opera 6.0/7.0 - opera.PluginContext Native Method Denial of Service
The PluginContext object of Opera 6.05 and 7.0 allows remote attackers to cause a denial of service (crash) via an HTTP
23RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris 2.x/7.0/8 - Derived 'login' Remote Buffer Overflow
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary comman
60RISK
open ↗Exploit-DB✓ VexDay Proof
TANne 0.6.17 - Session Manager SysLog Format String
Multiple format string vulnerabilities in the logger function in netzio.c for Tanne 0.6.17 allows remote attackers to ex
28RISK
open ↗Exploit-DB✓ VexDay Proof
S8Forum 3.0 - Remote Command Execution
register.php in S8Forum 3.0 allows remote attackers to execute arbitrary PHP commands by creating a user whose name ends
23RISK
open ↗Exploit-DB✓ VexDay Proof
OpenTopic 2.3.1 - Private Message HTML Injection
Cross-site scripting vulnerability (XSS) in OpenTopic 2.3.1 allows remote attackers to execute arbitrary script as other
23RISK
open ↗Exploit-DB✓ VexDay Proof
H-Sphere WebShell 2.4 - Remote Command Execution
Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL c
23RISK
open ↗Exploit-DB✓ VexDay Proof
H-Sphere WebShell 2.4 - Local Privilege Escalation
Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL c
23RISK
open ↗Exploit-DB✓ VexDay Proof
E-theni - Remote File Inclusion Command Execution
aff_liste_langue.php in E-theni allows remote attackers to execute arbitrary PHP code by modifying the rep_include param
23RISK
open ↗Exploit-DB✓ VexDay Proof
AN HTTPD 1.41 e - Cross-Site Scripting
Cross-site scripting vulnerability (XSS) in AN HTTP 1.41e allows remote attackers to execute arbitrary web script or HTM
23RISK
open ↗Exploit-DB✓ VexDay Proof
EType EServ 1.9x - NNTP Remote Denial of Service
The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote atta
23RISK
open ↗Exploit-DB✓ VexDay Proof
EType EServ 2.9x - FTP Remote Denial of Service
The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote atta
23RISK
open ↗Exploit-DB✓ VexDay Proof
EType EServ 2.9x - POP3 Remote Denial of Service
The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote atta
23RISK
open ↗Exploit-DB✓ VexDay Proof
EType EServ 2.9x - SMTP Remote Denial of Service
The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote atta
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - Lanman Denial of Service (2)
LANMAN service on Microsoft Windows 2000 allows remote attackers to cause a denial of service (CPU/memory exhaustion) vi
35RISK
open ↗Exploit-DB✓ VexDay Proof
Sun Solaris 2.5.1/2.6/7.0/8/9 Wall - Spoofed Message Origin
rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on users that appear to
23RISK
open ↗Exploit-DB✓ VexDay Proof
iCal 3.7 - HTTP Request Denial of Service
ICAL.EXE in iCal 3.7 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request, possibly
23RISK
open ↗Exploit-DB✓ VexDay Proof
iCal 3.7 - Remote Buffer Overflow (PoC)
ICAL.EXE in iCal 3.7 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request, possibly
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Pocket Internet Explorer 3.0 - Denial of Service
Pocket Internet Explorer (PIE) 3.0 allows remote attackers to cause a denial of service (crash) via a Javascript functio
28RISK
open ↗Exploit-DB✓ VexDay Proof
N/X Web Content Management System 2002 Prerelease 1 - 'datasets.php?c_path' Local File Inclusion
The (1) menu.inc.php, (2) datasets.php and (3) mass_operations.inc.php (mistakenly referred to as mass_opeations.inc.php
23RISK
open ↗Exploit-DB✓ VexDay Proof
N/X Web Content Management System 2002 Prerelease 1 - 'menu.inc.php?c_path' Remote File Inclusion
The (1) menu.inc.php, (2) datasets.php and (3) mass_operations.inc.php (mistakenly referred to as mass_opeations.inc.php
23RISK
open ↗Exploit-DB✓ VexDay Proof
PEEL 1.0b - Remote File Inclusion
haut.php in PEEL 1.0b allows remote attackers to execute arbitrary PHP code by modifying the dirroot parameter to refere
23RISK
open ↗Exploit-DB✓ VexDay Proof
Emacs 2.1 - Local Variable Arbitrary Command Execution
Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file,
23RISK
open ↗Exploit-DB✓ VexDay Proof
Melange Chat Server 1.10 - Remote Buffer Overflow
Buffer overflow in Melange Chat System 1.10 allows remote attackers to cause a denial of service (chat server crash) and
23RISK
open ↗Exploit-DB✓ VexDay Proof
W-Agora 4.1.6 - 'EditForm.php' Cross-Site Scripting
Cross-site scripting vulnerability (XSS) in editform.php for w-Agora 4.1.5 allows remote attackers to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
CHETCPASSWD 1.12 - Shadow File Disclosure
chetcpasswd.cgi in Pedro Lineu Orso chetcpasswd before 2.1 allows remote attackers to read the last line of the shadow f
23RISK
open ↗Exploit-DB✓ VexDay Proof
RealServer 7-9 - Describe Buffer Overflow (Metasploit)
Multiple buffer overflows in RealNetworks Helix Universal Server 9.0 (9.0.2.768) allow remote attackers to execute arbit
60RISK
open ↗Exploit-DB✓ VexDay Proof
CUPS 1.1.x - Negative Length HTTP Header
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) an
28RISK
open ↗Exploit-DB✓ VexDay Proof
GoAhead Web Server 2.1.x - '.ASP' File Source Code Disclosure
GoAhead Web Server 2.1.7 and earlier allows remote attackers to obtain the source code of ASP files via a URL terminated
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.