Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
24,695 exploits
Exploit-DB✓ VexDay Proof
Blue Coat Authentication and Authorization Agent (BCAAA) 5 - Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in the BCAAA component before build 60258, as used by Blue Coat ProxySG 4.2.3 through 6.1 an
50RISK
open ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 3.x - Swekey Remote Code Injection
libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4
28RISK
open ↗Exploit-DB✓ VexDay Proof
Symantec Backup Exec 12.5 - Man In The Middle
Symantec Backup Exec 11.0, 12.0, 12.5, 13.0, and 13.0 R2 does not validate identity information sent between the media s
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 3.x - Swekey Remote Code Injection
setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restric
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpMyAdmin3 (pma3) - Remote Code Execution
setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restric
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpMyAdmin3 (pma3) - Remote Code Execution
libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4
28RISK
open ↗Exploit-DB✓ VexDay Proof
MicroP 0.1.1.1600 - '.mppl' Local Stack Buffer Overflow (Metasploit)
Stack-based buffer overflow in MicroP 0.1.1.1600 allows remote attackers to execute arbitrary code via a crafted .mppl f
50RISK
open ↗Exploit-DB✓ VexDay Proof
vsftpd 2.3.4 - Backdoor Command Execution (Metasploit)
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open ↗Exploit-DB✓ VexDay Proof
HP OmniInet.exe Opcode 20 - Remote Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RISK
open ↗Exploit-DB✓ VexDay Proof
PHP 5.3.6 - Local Buffer Overflow (ROP)
Stack-based buffer overflow in the socket_connect function in ext/sockets/sockets.c in PHP 5.3.3 through 5.3.6 might all
28RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Reader 5.1 - XFDF Buffer Overflow (SEH)
Stack-based buffer overflow in the OutputDebugString function for Adobe Acrobat Reader 5.1 allows remote attackers to ex
28RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Reader X 10.0.0 < 10.0.1 - Atom Type Confusion
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; A
100RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Office 2010 - '.RTF' Header Stack Overflow
Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2
100RISK
open ↗Exploit-DB✓ VexDay Proof
HP Data Protector 6.11 - Remote Buffer Overflow (DEP Bypass)
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RISK
open ↗Exploit-DB✓ VexDay Proof
HP - 'OmniInet.exe' Opcode 27 Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component mDigg 2.2.8 - SQL Injection
SQL injection vulnerability in the mDigg (com_mdigg) component 2.2.8 for Joomla! allows remote attackers to execute arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
HP Data Protector 6.20 - EXEC_CMD Buffer Overflow
Buffer overflow in omniinet.exe in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allows remot
28RISK
open ↗Exploit-DB✓ VexDay Proof
HP Data Protector 6.20 - Multiple Vulnerabilities
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Visio - 'VISIODWG.dll .DXF' File Handling (MS10-028) (Metasploit)
Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to ex
50RISK
open ↗Exploit-DB✓ VexDay Proof
AzeoTech DaqFactory - Denial of Service
AzeoTech DAQFactory before 5.85 (Build 1842) does not perform authentication for certain signals, which allows remote at
23RISK
open ↗Exploit-DB✓ VexDay Proof
ManageEngine Support Center Plus 7.8 Build 7801 - Directory Traversal
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remot
50RISK
open ↗Exploit-DB✓ VexDay Proof
ManageEngine Support Center Plus 7.8 Build 7801 - Directory Traversal
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remo
35RISK
open ↗Exploit-DB✓ VexDay Proof
ManageEngine ServiceDesk Plus 8.0 - Directory Traversal
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remo
35RISK
open ↗Exploit-DB✓ VexDay Proof
ManageEngine ServiceDesk Plus 8.0 - Directory Traversal
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remot
50RISK
open ↗Exploit-DB✓ VexDay Proof
Lotus Notes 8.0.x < 8.5.2 FP2 - Autonomy Keyview ('.lzh' Attachment) (Metasploit)
Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers
50RISK
open ↗Exploit-DB✓ VexDay Proof
DreamBox DM800 - Arbitrary File Download
Directory traversal vulnerability in file in DreamBox DM800 1.6rc3, 1.5rc1, and earlier allows remote attackers to read
23RISK
open ↗Exploit-DB✓ VexDay Proof
Black Ice Cover Page - ActiveX Control Arbitrary File Download (Metasploit)
The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to for
50RISK
open ↗Exploit-DB✓ VexDay Proof
Sielco Sistemi Winlog - Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in Sielco Sistemi Winlog Pro 2.07.00 and earlier, when Run TCP/IP server is enabled, allows
50RISK
open ↗Exploit-DB✓ VexDay Proof
Black Ice Cover Page SDK - Insecure Method 'DownloadImageFileURL()' (Metasploit)
The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to for
50RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox - 'nsTreeRange' Dangling Pointer (2)
Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange da
60RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.