Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
24,695 exploits
Exploit-DB✓ VexDay Proof
Free Download Manager 3.0 Build 844 - Torrent Parsing Buffer Overflow (Metasploit)
Multiple buffer overflows in the torrent parsing implementation in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Bui
43RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe - 'Collab.collectEmailInfo()' Local Buffer Overflow (Metasploit)
Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code
100RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft HTML Help Workshop 4.74 - '.hhp' compiled Buffer Overflow (Metasploit) (4)
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included
60RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe - 'Collab.getIcon()' Local Buffer Overflow (Metasploit) (2)
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows r
100RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat - Bundled LibTIFF Integer Overflow (Metasploit)
Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a
100RISK
open ↗Exploit-DB✓ VexDay Proof
E-Xoopport Samsara 3.1 (eCal Module) - Blind SQL Injection
SQL injection vulnerability in location.php in the eCal module in E-Xoopport Samsara 3.1 and earlier allows remote attac
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft HTML Help Workshop 4.74 - '.hhp' Index Buffer Overflow (Metasploit) (3)
Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary
50RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe CoolType - SING Table 'uniqueName' Local Stack Buffer Overflow (Metasploit) (2)
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows
100RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Visual Basic - '.VBP' Local Buffer Overflow (Metasploit)
Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to ex
50RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe - 'util.printf()' Local Buffer Overflow (Metasploit) (2)
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary c
100RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe - 'Doc.media.newPlayer' Use-After-Free (Metasploit) (2)
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before
100RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft PowerPoint Viewer - TextBytesAtom Stack Buffer Overflow (MS10-004) (Metasploit)
Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code vi
50RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - 'newfunction' Invalid Pointer Use (Metasploit) (2)
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrob
100RISK
open ↗Exploit-DB✓ VexDay Proof
PointDev IDEAL Migration - Buffer Overflow (Metasploit)
Stack-based buffer overflow in Ideal Administration 2009 9.7.1, and possibly other versions, allows remote attackers to
50RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox CSS - font-face Remote Code Execution
Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x befo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft HTML Help Workshop 4.74 - '.hhp' Cotent Buffer Overflow (Metasploit) (2)
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included
60RISK
open ↗Exploit-DB✓ VexDay Proof
Linksys WRT54 Access Point - 'apply.cgi' Remote Buffer Overflow (Metasploit)
Buffer overflow in apply.cgi in Linksys WRT54G 3.01.03, 3.03.6, and possibly other versions before 4.20.7, allows remote
60RISK
open ↗Exploit-DB✓ VexDay Proof
FreePBX 2.8.0 - Recordings Interface Allows Remote Code Execution
Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interfa
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Excel - OBJ Record Stack Overflow
Stack-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML F
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft MPEG Layer-3 Audio Decoder - Division By Zero
Multiple stack-based buffer overflows in the MPEG Layer-3 audio codecs in Microsoft Windows 2000 SP4, XP SP2 and SP3, Se
50RISK
open ↗Exploit-DB✓ VexDay Proof
WAnewsletter 2.1.2 - SQL Injection
SQL injection vulnerability in index.php in WAnewsletter 2.1.2 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader and Flash - 'newfunction' Remote Code Execution
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbi
28RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component TimeTrack 1.2.4 - Multiple SQL Injections
SQL injection vulnerability in the TimeTrack (com_timetrack) component 1.2.4 for Joomla! allows remote attackers to exec
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Shockwave Director tSAC - Chunk Memory Corruption
Integer signedness error in the DIRAPI module in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to cau
28RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Joostina - SQL Injection
SQL injection vulnerability in the Joostina (com_ezautos) component for Joomla! allows remote attackers to execute arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
Novell iPrint Client - ActiveX Control call-back-url Buffer Overflow (Metasploit)
Stack-based buffer overflow in Novell iPrint Client before 5.44 allows remote attackers to execute arbitrary code via a
50RISK
open ↗Exploit-DB✓ VexDay Proof
@Mail 6.1.9 - 'MailType' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in @mail Webmail before 6.2.0 allows remote attackers to inject ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
Novell iPrint Client - ActiveX Control ExecuteRequest Buffer Overflow (Metasploit)
Stack-based buffer overflow in the Novell iPrint Control ActiveX control in ienipp.ocx in Novell iPrint Client before 4.
50RISK
open ↗Exploit-DB✓ VexDay Proof
mountall 2.15.2 (Ubuntu 10.04/10.10) - Local Privilege Escalation
mountall.c in mountall before 2.15.2 uses 0666 permissions for the root.rules file, which allows local users to gain pri
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sun Java - Web Start Plugin Command Line Argument Injection (Metasploit)
Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.