Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,967GitHub PoC 13,264VulnCheck XDB 8,156Nuclei 4,201Metasploit 3,462✓ verified onlyrecentpopularrisk
3,462 exploits
Metasploit200
Mercury/32 PH Server Module Buffer Overflow
Buffer overflow in Mercury Mail Transport System 4.01b allows remote attackers to execute arbitrary code via a long requ
50RISK
open ↗Metasploit600
Lyris ListManager MSDE Weak sa Password
The MSDE version of Lyris ListManager 5.0 through 8.9b configures the sa account in the database to use a password with
50RISK
open ↗Metasploit300
MS05-054 Microsoft Internet Explorer JavaScript OnLoad Handler Remote Code Execution
Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to caus
60RISK
open ↗Metasploit200
Novell NetMail IMAP STATUS Buffer Overflow
Stack-based buffer overflow in the IMAP daemon in Novell Netmail 3.5.2 allows remote attackers to execute arbitrary code
50RISK
open ↗Metasploit200
freeFTPd 1.0 Username Overflow
Stack-based buffer overflow in freeFTPd before 1.0.9 with Logging enabled, allows remote attackers to cause a denial of
60RISK
open ↗Metasploit300
FileZilla FTP Server Admin Interface Denial of Service
Buffer overflow in FileZilla Server Terminal 0.9.4d may allow remote attackers to cause a denial of service (terminal cr
50RISK
open ↗Metasploit400
Microsoft IIS ISAPI RSA WebAgent Redirect Overflow
Stack-based buffer overflow in IISWebAgentIF.dll in RSA Authentication Agent for Web (aka SecurID Web Agent) 5.2 and 5.3
50RISK
open ↗Metasploit400
Snort Back Orifice Pre-Preprocessor Buffer Overflow
Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to exec
60RISK
open ↗Metasploit200
CA iTechnology iGateway Debug Mode Buffer Overflow
Buffer overflow in Computer Associates (CA) iGateway 3.0 and 4.0 before 4.0.050623, when running in debug mode, allows r
50RISK
open ↗Metasploit500
MailEnable IMAPD W3C Logging Buffer Overflow
Buffer overflow in the W3C logging for MailEnable Enterprise 1.1 and Professional 1.6 allows remote attackers to execute
50RISK
open ↗Metasploit600
TWiki History Function Arbitrary Command Execution
The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary co
60RISK
open ↗Metasploit500
Linksys WRT54 Access Point apply.cgi Buffer Overflow
Buffer overflow in apply.cgi in Linksys WRT54G 3.01.03, 3.03.6, and possibly other versions before 4.20.7, allows remote
60RISK
open ↗Metasploit600
Barracuda IMG.PL Remote Command Execution
img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to execute arbitrary comman
50RISK
open ↗Metasploit600
Simple PHP Blog Remote Command Execution
upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which cou
50RISK
open ↗Metasploit600
HP Openview connectedNodes.ovpl Remote Command Execution
HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metach
100RISK
open ↗Metasploit500
CA CAM log_security() Stack Buffer Overflow (Win32)
Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1
60RISK
open ↗Metasploit600
Google Appliance ProxyStyleSheet Command Execution
The Saxon XSLT parser in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to
50RISK
open ↗Metasploit500
eDirectory 8.7.3 iMonitor Remote Stack Buffer Overflow
Buffer overflow in dhost.exe in iMonitor for Novell eDirectory 8.7.3 on Windows allows attackers to cause a denial of se
50RISK
open ↗Metasploit400
MS05-039 Microsoft Plug and Play Service Overflow
Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1
60RISK
open ↗Metasploit600
WordPress cache_lastpostdate Arbitrary Code Execution
Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP co
50RISK
open ↗Metasploit200
CA BrightStor Agent for Microsoft SQL Overflow
Stack-based buffer overflow in the Backup Agent for Microsoft SQL Server in BrightStor ARCserve Backup Agent for SQL Ser
50RISK
open ↗Metasploit200
Sybase EAServer 5.2 Remote Stack Buffer Overflow
Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to e
60RISK
open ↗Metasploit500
SlimFTPd LIST Concatenation Overflow
Buffer overflow in SlimFTPd 3.15 and 3.16 allows remote authenticated users to execute arbitrary code via a long directo
50RISK
open ↗Metasploit500
MailEnable IMAPD (1.54) STATUS Request Buffer Overflow
Stack-based buffer overflow in the IMAP daemon (imapd) in MailEnable Professional 1.54 allows remote authenticated users
60RISK
open ↗Metasploit300
Mozilla Suite/Firefox compareTo() Code Execution
Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of serv
50RISK
open ↗Metasploit200
SoftiaCom WMailserver 1.0 Buffer Overflow
SoftiaCom wMailServer 1.0 and 2.0 allows remote attackers to cause a denial of service (application crash) via a large T
50RISK
open ↗Metasploit600
PHP XML-RPC Arbitrary Code Execution
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PH
60RISK
open ↗Metasploit500
Veritas Backup Exec Windows Remote Agent Overflow
Stack-based buffer overflow in VERITAS Backup Exec Remote Agent 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.3
60RISK
open ↗Metasploit300
MS05-030 Microsoft Outlook Express NNTP Response Parsing Buffer Overflow
Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows rem
60RISK
open ↗Metasploit200
FutureSoft TFTP Server 2000 Transfer-Mode Overflow
Multiple stack-based buffer overflows in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allow remote attackers to exe
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.