Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,453cataloged exploits
37,908CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,237GitHub PoC 15,653VulnCheck XDB 9,134Nuclei 4,441Metasploit 3,506✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
Zeroo HTTP Server 1.5 - Directory Traversal (2)
Directory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot
23RISK
open ↗Exploit-DB✓ VexDay Proof
vBulletin 2.0/2.2.x - 'memberlist.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin before 3.0 allows remote attackers to inject arbitrary web
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Java Virtual Machine 3802 Series - Bytecode Verifier
The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Int
35RISK
open ↗Exploit-DB✓ VexDay Proof
Symantec Java! JustInTime Compiler 210.65 - Command Execution
Symantec Java! JIT (Just-In-Time) Compiler for Netscape Communicator 4.0 through 4.8 allows remote attackers to execute
28RISK
open ↗Exploit-DB✓ VexDay Proof
TFTPD32 2.50 - 'Filename' Remote Buffer Overflow
Buffer overflow in tftpd of TFTP32 2.21 and earlier allows remote attackers to execute arbitrary code via a long filenam
50RISK
open ↗Exploit-DB✓ VexDay Proof
Mhonarc 2.5.x - Mail Header HTML Injection
Cross-site scripting vulnerability (XSS) in MHonArc 2.5.12 and earlier allows remote attackers to insert script or HTML
23RISK
open ↗Exploit-DB✓ VexDay Proof
TFTPD32 2.50 - Arbitrary File Download/Upload
tftpd32 2.50 and 2.50.2 allows remote attackers to read or write arbitrary files via a full pathname in GET and PUT requ
23RISK
open ↗Exploit-DB✓ VexDay Proof
MailEnable 1.501x - Email Server Buffer Overflow
MailEnable 1.5 015 through 1.5 018 allows remote attackers to cause a denial of service (crash) via a long USER string,
23RISK
open ↗Exploit-DB✓ VexDay Proof
Lonerunner Zeroo HTTP Server 1.5 - Remote Buffer Overflow
Buffer overflow in the HttpGetRequest function in Zeroo HTTP server 1.5 allows remote attackers to execute arbitrary cod
28RISK
open ↗Exploit-DB✓ VexDay Proof
Perception LiteServe 2.0 - CGI Source Disclosure
Perception LiteServe 2.0 through 2.0.1 allows remote attackers to obtain the source code of CGI scripts via an HTTP requ
23RISK
open ↗Exploit-DB✓ VexDay Proof
IISPop 1.161/1.181 - Remote Buffer Overflow (Denial of Service) (PoC)
Buffer overflow in IISPop email server 1.161 and 1.181 allows remote attackers to cause a denial of service (crash) via
23RISK
open ↗Exploit-DB✓ VexDay Proof
Key Focus KF Web Server 1.0.8 - Directory Traversal
Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recog
23RISK
open ↗Exploit-DB✓ VexDay Proof
LibHTTPD 1.2 - POST Buffer Overflow
Buffer overflow in the httpdProcessRequest function in LibHTTPD 1.2 allows remote attackers to cause a denial of service
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpBB Advanced Quick Reply Hack 1.0/1.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows re
23RISK
open ↗Exploit-DB✓ VexDay Proof
Light HTTPd 0.1 - 'GET' Buffer Overflow (2)
Buffer overflow in Light HTTPd (lhttpd) 0.1 allows remote attackers to execute arbitrary code via a long HTTP GET reques
28RISK
open ↗Exploit-DB✓ VexDay Proof
ISC BIND 8.3.x - OPT Record Large UDP Denial of Service
BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via
23RISK
open ↗Exploit-DB✓ VexDay Proof
Light HTTPd 0.1 - 'GET' Buffer Overflow (1)
Buffer overflow in Light HTTPd (lhttpd) 0.1 allows remote attackers to execute arbitrary code via a long HTTP GET reques
28RISK
open ↗Exploit-DB✓ VexDay Proof
W3Mail 1.0.6 - File Disclosure
Directory traversal vulnerability in viewAttachment.cgi in W3Mail 1.0.6 allows remote attackers to read arbitrary files
23RISK
open ↗Exploit-DB✓ VexDay Proof
Traceroute-nanog 6 - Local Buffer Overflow
Buffer overflow in the get_origin function in traceroute-nanog allows attackers to execute arbitrary code via long WHOIS
23RISK
open ↗Exploit-DB✓ VexDay Proof
Hotfoon Dialer 4.0 - Buffer Overflow (PoC)
Buffer overflow in hotfoon4.exe in Hotfoon 4.0 allows remote attackers to cause a denial of service (crash) and possibly
23RISK
open ↗Exploit-DB✓ VexDay Proof
EZ Systems HTTPBench 1.1 - Information Disclosure
ezhttpbench.php in eZ httpbench 1.1 allows remote attackers to read arbitrary files via a full pathname in the AnalyseSi
23RISK
open ↗Exploit-DB✓ VexDay Proof
QNX RTOS 6.2 - Application Packager Non-Explicit Path Execution
QNX Neutrino RTOS 6.2.0 uses the PATH environment variable to find and execute the cp program while operating at raised
23RISK
open ↗Exploit-DB✓ VexDay Proof
Perception LiteServe 2.0.1 - Directory Query String Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1 allows remote attackers to execute arbitrary web
23RISK
open ↗Exploit-DB✓ VexDay Proof
Simple Web Server 0.5.1 - File Disclosure
Peter Sandvik's Simple Web Server 0.5.1 and earlier allows remote attackers to bypass access restrictions for files via
23RISK
open ↗Exploit-DB✓ VexDay Proof
Perception LiteServe 2.0.1 - DNS Wildcard Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1 allows remote attackers to execute arbitrary web
23RISK
open ↗Exploit-DB✓ VexDay Proof
Zeus Web Server 4.0/4.1 - Admin Interface Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Zeus Administration Server in Zeus Web Server 4.0 through 4.1r2 allows remot
23RISK
open ↗Exploit-DB✓ VexDay Proof
Pine 4.x - 'From:' Heap Corruption
Pine 4.44 and earlier allows remote attackers to cause a denial of service (core dump and failed restart) via an email m
23RISK
open ↗Exploit-DB✓ VexDay Proof
Lotus Domino 5.0.8-9 - Non-Existent NSF Database Banner Information Disclosure
Lotus Domino 5.0.9a and earlier, even when configured with the 'DominoNoBanner=1' option, allows remote attackers to obt
23RISK
open ↗Exploit-DB✓ VexDay Proof
CuteCast 1.2 - User Credential Disclosure
ArtsCore Studios CuteCast Forum 1.2 stores passwords in plaintext under the web document root, which allows remote attac
23RISK
open ↗Exploit-DB✓ VexDay Proof
QNX 6.1 - 'TimeCreate' Local Denial of Service
The timer implementation in QNX RTOS 6.1.0 allows local users to cause a denial of service (hang) and possibly execute a
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.