Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,453cataloged exploits
37,908CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,237GitHub PoC 15,653VulnCheck XDB 9,134Nuclei 4,441Metasploit 3,506✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
MyHelpDesk 20020509 - SQL Injection
SQL injection vulnerability in index.php for MyHelpDesk 20020509, and possibly other versions, allows remote attackers t
23RISK
open ↗Exploit-DB✓ VexDay Proof
Geeklog 1.3.5 - Calendar Event Form Script Injection
Cross-site scripting vulnerabilities in GeekLog 1.3.5 and earlier allow remote attackers to execute arbitrary script via
23RISK
open ↗Exploit-DB✓ VexDay Proof
Seanox DevWex Windows Binary 1.2002.520 - File Disclosure
Directory traversal vulnerability in SeaNox Devwex before 1.2002.0601 allows remote attackers to read arbitrary files vi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5/6 - FTP Web View Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when running on Windows 2000 with
28RISK
open ↗Exploit-DB✓ VexDay Proof
Voxel Dot Net CBms 0.x - Multiple Code Injection Vulnerabilities
Vulnerabilities in Voxel Dot Net CBMS 0.7 and earlier allow remote attackers to conduct unauthorized operations as other
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebScripts WebBBS 4.x/5.0 - Remote Command Execution
webbbs_post.pl in WebBBS 4 and 5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the
28RISK
open ↗Exploit-DB✓ VexDay Proof
Splatt Forum 3.0 - Image Tag HTML Injection
Cross-site scripting vulnerability in Splatt Forum 3.0 allows remote attackers to execute arbitrary script as other user
23RISK
open ↗Exploit-DB✓ VexDay Proof
Telindus 1100 Series Router - Administration Password Leak
Telindus 1100 series ADSL router allows remote attackers to gain privileges to the device via a certain packet to UDP po
23RISK
open ↗Exploit-DB✓ VexDay Proof
Nullsoft SHOUTcast 1.8.9 - Remote Buffer Overflow
Buffer overflow in SHOUTcast 1.8.9 and other versions before 1.8.12 allows a remote authenticated DJ to execute arbitrar
23RISK
open ↗Exploit-DB✓ VexDay Proof
Slurp 1.10 - SysLog Remote Format String
Format string vulnerability in log_doit function of Slurp NNTP client 1.1.0 allows a malicious news server to execute ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
QNX RTOS 4.25/6.1 - 'phgrafx' Local Privilege Escalation
The (1) phrafx and (2) phgrafx-startup programs in QNX realtime operating system (RTOS) 4.25 and 6.1.0 do not properly d
23RISK
open ↗Exploit-DB✓ VexDay Proof
Teekai Tracking Online 1.0 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in userlog.php in TeeKai Tracking Online 1.0 allows remote attackers to inject
23RISK
open ↗Exploit-DB✓ VexDay Proof
QNX RTOS 4.25/6.1 - su Password Hash Disclosure
/bin/su in QNX realtime operating system (RTOS) 4.25 and 6.1.0 allows local users to obtain sensitive information from c
23RISK
open ↗Exploit-DB✓ VexDay Proof
QNX 6.x - 'ptrace()' Arbitrary Process Modification
ptrace in the QNX realtime operating system (RTOS) 4.25 and 6.1.0 allows programs to attach to privileged processes, whi
23RISK
open ↗Exploit-DB✓ VexDay Proof
QNX RTOS 6.1 - 'PKG-Installer' Local Buffer Overflow
Multiple buffer overflows in realtime operating system (RTOS) 6.1.0 allows local users to execute arbitrary code via (1)
23RISK
open ↗Exploit-DB✓ VexDay Proof
QNX RTOS 6.1 - '/usr/photon/bin/phlocale' Environment Variable Buffer Overflow
Multiple buffer overflows in realtime operating system (RTOS) 6.1.0 allows local users to execute arbitrary code via (1)
23RISK
open ↗Exploit-DB✓ VexDay Proof
QNX RTOS 4.25/6.1 - 'phgrafx-startup' Local Privilege Escalation
The (1) phrafx and (2) phgrafx-startup programs in QNX realtime operating system (RTOS) 4.25 and 6.1.0 do not properly d
23RISK
open ↗Exploit-DB✓ VexDay Proof
Evolvable Shambala Server 4.5 - Web Server Denial of Service
Web server for Shambala 4.5 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request.
23RISK
open ↗Exploit-DB✓ VexDay Proof
QNX RTOS 4.25 - dumper Arbitrary File Modification
Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrit
23RISK
open ↗Exploit-DB✓ VexDay Proof
QNX RTOS 4.25 - monitor Arbitrary File Modification
Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrit
23RISK
open ↗Exploit-DB✓ VexDay Proof
QNX RTOS 4.25 - 'CRTTrap' File Disclosure
Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrit
23RISK
open ↗Exploit-DB✓ VexDay Proof
CGIScript.net - 'csPassword.cgi' 1.0 Information Disclosure
CGIScript.net csPassword.cgi allows remote authenticated users to modify the .htaccess file and gain privileges via newl
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Informix SE 7.25 sqlexec - Local Buffer Overflow (2)
Buffer overflow in sqlexec for Informix SE-7.25 allows local users to gain root privileges via a long INFORMIXDIR enviro
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Informix SE 7.25 sqlexec - Local Buffer Overflow (1)
Buffer overflow in sqlexec for Informix SE-7.25 allows local users to gain root privileges via a long INFORMIXDIR enviro
23RISK
open ↗Exploit-DB✓ VexDay Proof
CGIScript.net - 'csPassword.cgi' 1.0 Information Disclosure
CGIScript.net csPassword.cgi leaks sensitive information such as the pathname of the server in debug messages that are p
23RISK
open ↗Exploit-DB✓ VexDay Proof
CGIScript.net - 'csPassword.cgi' 1.0 HTAccess File Modification
CGIScript.net csPassword.cgi allows remote authenticated users to modify the .htaccess file and gain privileges via newl
23RISK
open ↗Exploit-DB✓ VexDay Proof
Caldera OpenServer 5.0.5/5.0.6 - SCOAdmin Symbolic Link
scoadmin for Caldera/SCO OpenServer 5.0.5 and 5.0.6 allows local users to overwrite arbitrary files via a symlink attack
23RISK
open ↗Exploit-DB✓ VexDay Proof
Gafware CFXImage 1.6.4/1.6.6 - ShowTemp File Disclosure
showtemp.cfm for Gafware CFXImage 1.6.6 allows remote attackers to read arbitrary files via (1) a .. or (2) a C: style p
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 3.2.3/3.2.4 - Example Files Web Root Full Path Disclosure
The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system informatio
35RISK
open ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 3.2.3/3.2.4 - 'Source.jsp' Information Disclosure
The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system informatio
35RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.