Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,453cataloged exploits
37,908CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,237GitHub PoC 15,653VulnCheck XDB 9,134Nuclei 4,441Metasploit 3,506✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
Powie PForum 1.1x - 'Username' Cross-Site Scripting
Cross-site scripting vulnerability in edituser.php for pforum 1.14 and earlier allows remote attackers to execute script
23RISK
open ↗Exploit-DB✓ VexDay Proof
Squid 2.0-4 - Cache FTP Proxy URL Buffer Overflow
Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache 1.3 - Artificially Long Slash Path Directory Listing (2)
The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview in
45RISK
open ↗Exploit-DB✓ VexDay Proof
Tarantella Enterprise 3 - Symbolic Link
The installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the
23RISK
open ↗Exploit-DB✓ VexDay Proof
GNUJSP 1.0 - File Disclosure
gnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass acce
23RISK
open ↗Exploit-DB✓ VexDay Proof
Phusion WebServer 1.0 - Directory Traversal (1)
Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (t
23RISK
open ↗Exploit-DB✓ VexDay Proof
Icecast 1.x - AVLLib Buffer Overflow
Buffer overflows in icecast 1.3.11 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET req
23RISK
open ↗Exploit-DB✓ VexDay Proof
Phusion WebServer 1.0 - Directory Traversal (2)
Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (t
23RISK
open ↗Exploit-DB✓ VexDay Proof
Phusion WebServer 1.0 - Long URL Denial of Service
Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary cod
28RISK
open ↗Exploit-DB✓ VexDay Proof
Phusion WebServer 1.0 - 'URL' Remote Buffer Overflow
Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary cod
28RISK
open ↗Exploit-DB✓ VexDay Proof
Ettercap 0.6.3.1 - Large Packet Buffer Overflow
Buffer overflow in various decoders in Ettercap 0.6.3.1 and earlier, when running on networks with an MTU greater than 2
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco IOS 11/12 - SNMP Message Denial of Service
Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause
35RISK
open ↗Exploit-DB✓ VexDay Proof
Sawmill 6.2.x - Admin Password Insecure Default Permissions
Sawmill for Solaris 6.2.14 and earlier creates the AdminPassword file with world-writable permissions, which allows loca
23RISK
open ↗Exploit-DB✓ VexDay Proof
EZNE.NET Ezboard 2000 - Remote Buffer Overflow
Buffer overflow in EasyBoard 2000 1.27 (aka EZboard) allows remote attackers to execute arbitrary code via a long bounda
28RISK
open ↗Exploit-DB✓ VexDay Proof
HP AdvanceStack Switch - Authentication Bypass
Web configuration utility in HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier, allow
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple QuickTime 5.0 - Content-Type Remote Buffer Overflow
Buffer overflow in Apple QuickTime Player 5.01 and 5.02 allows remote web servers to execute arbitrary code via a respon
28RISK
open ↗Exploit-DB✓ VexDay Proof
Tarantella Enterprise 3 - gunzip Race Condition
Race condition in the installation script for Tarantella Enterprise 3 3.01 through 3.20 creates a world-writeable tempor
23RISK
open ↗Exploit-DB✓ VexDay Proof
OS/400 - User Account Name Disclosure
The System Request menu in IBM AS/400 allows local users to list valid user accounts by viewing the object names that ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
Hanterm 3.3 - Local Buffer Overflow (1)
Buffer overflow in hanterm 3.3.1 and earlier allows local users to execute arbitrary code via a long string in the (1) -
23RISK
open ↗Exploit-DB✓ VexDay Proof
Caldera UnixWare 7.1.1 - Message Catalog Environment Variable Format String
Format string vulnerability in the message catalog library functions in UnixWare 7.1.1 allows local users to gain privil
23RISK
open ↗Exploit-DB✓ VexDay Proof
Hanterm 3.3 - Local Buffer Overflow (2)
Buffer overflow in hanterm 3.3.1 and earlier allows local users to execute arbitrary code via a long string in the (1) -
23RISK
open ↗Exploit-DB✓ VexDay Proof
AtheOS 0.3.7 - Change Root Directory Escaping
Directory traversal vulnerability in chroot function in AtheOS 0.3.7 allows attackers to escape the jail via a .. (dot d
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sambar Server 5.1 - Sample Script Denial of Service
cgitest.exe in Sambar Server 5.1 before Beta 4 allows remote attackers to cause a denial of service, and possibly execut
28RISK
open ↗Exploit-DB✓ VexDay Proof
Thunderstone TEXIS 3.0 - Full Path Disclosure
Thunderstone Texis CGI script allows remote attackers to obtain the full path of the web root via a request for a nonexi
23RISK
open ↗Exploit-DB✓ VexDay Proof
ICQ For Mac OSX 2.6 Client - Denial of Service
Buffer overflow in ICQ 2.6x for MacOS X 10.0 through 10.1.2 allows remote attackers to cause a denial of service and pos
23RISK
open ↗Exploit-DB✓ VexDay Proof
Portix-PHP 0.4 - 'index.php' Directory Traversal
Directory traversal vulnerability in index.php of Portix 0.4.02 allows remote attackers to read arbitrary files via a ..
23RISK
open ↗Exploit-DB✓ VexDay Proof
Faq-O-Matic 2.6/2.7 - Cross-Site Scripting
Cross-site scripting vulnerability in fom.cgi of Faq-O-Matic 2.712 allows remote attackers to execute arbitrary Javascri
23RISK
open ↗Exploit-DB✓ VexDay Proof
Portix-PHP 0.4 - 'view.php' Directory Traversal
Directory traversal vulnerability in index.php of Portix 0.4.02 allows remote attackers to read arbitrary files via a ..
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP 4.x/5.x MySQL Library - 'Safe_mode' Filesystem Circumvention (3)
Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP 4.x/5.x MySQL Library - 'Safe_mode' Filesystem Circumvention (2)
Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.