Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
80,095cataloged exploits
36,945CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,476Referência 23,442GitHub PoC 15,312VulnCheck XDB 8,970Nuclei 4,393Metasploit 3,502✓ verified onlyrecentpopularrisk
24,476 exploits
Exploit-DB✓ VexDay Proof
Kaspersky Anti-Virus File Server 8.0.3.297 - Multiple Vulnerabilities
There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Mai
23RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Solaris 11.1/11.3 (RSH) - 'Stack Clash' Local Privilege Escalation
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions t
38RISK
open ↗Exploit-DB✓ VexDay Proof
Kaspersky Anti-Virus File Server 8.0.3.297 - Multiple Vulnerabilities
In Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312), the scriptNa
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft MsMpEng - mpengine x86 Emulator Heap Corruption in VFS API
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on 32-bit versions of Micr
35RISK
open ↗Exploit-DB✓ VexDay Proof
GLPI 0.90.4 - SQL Injection
Multiple SQL injection vulnerabilities in GLPI 0.90.4 allow an authenticated remote attacker to execute arbitrary SQL co
23RISK
open ↗Exploit-DB✓ VexDay Proof
LAME 3.99.5 - 'III_dequantize_sample' Stack Buffer Overflow
The III_dequantize_sample function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products,
23RISK
open ↗Exploit-DB✓ VexDay Proof
Netgear DGN2200 - 'dnslookup.cgi' Command Injection (Metasploit)
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute ar
100RISK
open ↗Exploit-DB
IBM DB2 9.7/10.1/10.5/11.1 - Command Line Processor Buffer Overflow
IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a stack-bas
23RISK
open ↗Exploit-DB✓ VexDay Proof
Symantec Messaging Gateway 10.6.2-7 - Remote Code Execution (Metasploit)
The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an i
60RISK
open ↗Exploit-DB✓ VexDay Proof
LAME 3.99.5 - 'II_step_one' Buffer Overflow
The II_step_one function in layer2.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows rem
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'USP10!ttoGetTableData' Uniscribe Font Processing Out-of-Bounds Memory Read
Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'USP10!otlSinglePosLookup::getCoverageTable' Uniscribe Font Processing Out-of-Bounds Memory Read
Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'USP10!NextCharInLiga' Uniscribe Font Processing Out-of-Bounds Memory Read
Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'USP10!SubstituteNtoM' Uniscribe Font Processing Out-of-Bounds Memory Read
Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'USP10!CreateIndexTable' Uniscribe Font Processing Out-of-Bounds Memory Read
Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'USP10!otlReverseChainingLookup::apply' Uniscribe Font Processing Out-of-Bounds Memory Read
Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash - ATF Parser Heap Corruption
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the Adobe Text
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'USP10!otlValueRecord::adjustPos' Uniscribe Font Processing Out-of-Bounds Memory Read
Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'nt!NtQueryInformationWorkerFactory (WorkerFactoryBasicInformation)' Kernel Stack Memory Disclosure
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Image Decoding Out-of-Bounds Read
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the PNG image
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'USP10!MergeLigRecords' Uniscribe Font Processing Heap Memory Corruption
Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Edge - 'CssParser::RecordProperty' Type Confusion
Microsoft Edge in Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the context of
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'ATMFD.DLL' Out-of-Bounds Read due to Malformed Name INDEX in the CFF Table
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'nt!NtQueryInformationResourceManager (information class 0)' Kernel Stack Memory Disclosure
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash - AVC Edge Processing Out-of-Bounds Read
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the MPEG-4 AVC
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'nt!NtQueryInformationTransaction (information class 1)' Kernel Stack Memory Disclosure
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'win32k!NtGdiGetRealizationInfo' Kernel Stack Memory Disclosure
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, an
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'nt!NtQueryInformationJobObject (information class 12)' Kernel Stack Memory Disclosure
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'nt!NtQueryInformationJobObject (BasicLimitInformation_ ExtendedLimitInformation)' Kernel Stack Memory Disclosure
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'win32k!NtGdiExtGetObjectW' Kernel Stack Memory Disclosure
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2,
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.