Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,697cataloged exploits
36,715CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,475Referência 23,264GitHub PoC 15,172VulnCheck XDB 8,920Nuclei 4,373Metasploit 3,493✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
Adobe - 'Collab.collectEmailInfo()' Local Buffer Overflow (Metasploit)
Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code
100RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Illustrator CS4 14.0.0 - Postscript (.eps) Buffer Overflow (Metasploit)
Buffer overflow in Adobe Illustrator CS4 14.0.0, CS3 13.0.3 and earlier, and CS3 13.0.0 allows remote attackers to execu
60RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox CSS - font-face Remote Code Execution
Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x befo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe - U3D CLODProgressiveMeshDeclaration Array Overrun (Metasploit) (2)
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x befor
100RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft HTML Help Workshop 4.74 - '.hhp' compiled Buffer Overflow (Metasploit) (4)
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft HTML Help Workshop 4.74 - '.hhp' Cotent Buffer Overflow (Metasploit) (2)
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included
60RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe - FlateDecode Stream Predictor 02 Integer Overflow (Metasploit) (2)
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows rem
100RISK
open ↗Exploit-DB✓ VexDay Proof
DjVu - 'DjVu_ActiveX_MSOffice.dll' ActiveX Component Buffer Overflow (Metasploit)
Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers
50RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat - Bundled LibTIFF Integer Overflow (Metasploit)
Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a
100RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe - 'util.printf()' Local Buffer Overflow (Metasploit) (2)
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary c
100RISK
open ↗Exploit-DB✓ VexDay Proof
SasCam Webcam Server 2.6.5 - 'Get()' Method Buffer Overflow (Metasploit)
Buffer overflow in the XHTTP Module 4.1.0.0 in the ActiveX control for SaschArt SasCam Webcam Server 2.6.5 allows remote
50RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft HTML Help Workshop 4.74 - '.hhp' Index Buffer Overflow (Metasploit) (3)
Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary
50RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - 'newfunction' Invalid Pointer Use (Metasploit) (2)
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrob
100RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Excel - Malformed FEATHEADER Record (MS09-067) (Metasploit)
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Conv
100RISK
open ↗Exploit-DB✓ VexDay Proof
ProShow Gold 4.0.2549 - '.psh' Local Stack Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in Photodex ProShow Gold 4.0.2549 allow remote attackers to execute arbitrary code
50RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe - 'Collab.getIcon()' Local Buffer Overflow (Metasploit) (2)
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows r
100RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft MPEG Layer-3 Audio Decoder - Division By Zero
Multiple stack-based buffer overflows in the MPEG Layer-3 audio codecs in Microsoft Windows 2000 SP4, XP SP2 and SP3, Se
50RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Excel - OBJ Record Stack Overflow
Stack-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML F
60RISK
open ↗Exploit-DB✓ VexDay Proof
Linksys WRT54 Access Point - 'apply.cgi' Remote Buffer Overflow (Metasploit)
Buffer overflow in apply.cgi in Linksys WRT54G 3.01.03, 3.03.6, and possibly other versions before 4.20.7, allows remote
60RISK
open ↗Exploit-DB✓ VexDay Proof
FreePBX 2.8.0 - Recordings Interface Allows Remote Code Execution
Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interfa
23RISK
open ↗Exploit-DB✓ VexDay Proof
WAnewsletter 2.1.2 - SQL Injection
SQL injection vulnerability in index.php in WAnewsletter 2.1.2 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader and Flash - 'newfunction' Remote Code Execution
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbi
28RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component TimeTrack 1.2.4 - Multiple SQL Injections
SQL injection vulnerability in the TimeTrack (com_timetrack) component 1.2.4 for Joomla! allows remote attackers to exec
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Joostina - SQL Injection
SQL injection vulnerability in the Joostina (com_ezautos) component for Joomla! allows remote attackers to execute arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Shockwave Director tSAC - Chunk Memory Corruption
Integer signedness error in the DIRAPI module in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to cau
28RISK
open ↗Exploit-DB✓ VexDay Proof
Novell iPrint Client - ActiveX Control call-back-url Buffer Overflow (Metasploit)
Stack-based buffer overflow in Novell iPrint Client before 5.44 allows remote attackers to execute arbitrary code via a
50RISK
open ↗Exploit-DB✓ VexDay Proof
Sun Java - Web Start Plugin Command Line Argument Injection (Metasploit)
Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6
50RISK
open ↗Exploit-DB✓ VexDay Proof
ibPhotohost 1.1.2 - SQL Injection
SQL injection vulnerability in index.php in ibPhotohost 1.1.2 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
Novell iPrint Client - ActiveX Control ExecuteRequest Buffer Overflow (Metasploit)
Stack-based buffer overflow in the Novell iPrint Control ActiveX control in ienipp.ocx in Novell iPrint Client before 4.
50RISK
open ↗Exploit-DB✓ VexDay Proof
@Mail 6.1.9 - 'MailType' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in @mail Webmail before 6.2.0 allows remote attackers to inject ar
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.