Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,497GitHub PoC 13,627VulnCheck XDB 8,198Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
24,443 exploits
Exploit-DB✓ VexDay Proof
Apple Mac OSX Entitlements - 'Rootpipe' Local Privilege Escalation (Metasploit)
Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allow
38RISK
open ↗Exploit-DB✓ VexDay Proof
Boxoft WAV to MP3 Converter - 'convert' Local Buffer Overflow
Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly
50RISK
open ↗Exploit-DB
Ganglia Web Frontend < 3.5.1 - PHP Code Execution
Unspecified vulnerability in Ganglia Web before 3.5.1 allows remote attackers to execute arbitrary PHP code via unknown
23RISK
open ↗Exploit-DB
Cyberoam Firewall CR500iNG-XP 10.6.2 MR-1 - Blind SQL Injection
SQL injection vulnerability in the Sophos Cyberoam CR500iNG-XP firewall appliance with CyberoamOS 10.6.2 MR-1 and earlie
23RISK
open ↗Exploit-DB✓ VexDay Proof
PCMan FTP Server 2.0.7 - 'RENAME' Remote Buffer Overflow
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RISK
open ↗Exploit-DB
Wolf CMS - Arbitrary File Upload / Execution
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/
28RISK
open ↗Exploit-DB
Wolf CMS - Arbitrary File Upload / Execution
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/
28RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle GlassFish Server 4.1 - Directory Traversal
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Trave
60RISK
open ↗Exploit-DB
Invision Power Board (IP.Board) 4.x - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB,
23RISK
open ↗Exploit-DB✓ VexDay Proof
QEMU - Programmable Interrupt Timer Controller Heap Overflow
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read
23RISK
open ↗Exploit-DB
Magento eCommerce - Remote Code Execution
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Communit
35RISK
open ↗Exploit-DB
Linux Kernel < 3.5.0-23 (Ubuntu 12.04.2 x64) - 'SOCK_DIAG' SMEP Bypass Local Privilege Escalation
Array index error in the __sock_diag_rcv_msg function in net/core/sock_diag.c in the Linux kernel before 3.7.10 allows l
23RISK
open ↗Exploit-DB✓ VexDay Proof
vBulletin 3.6.0 < 4.2.3 - 'ForumRunner' SQL Injection
SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 bef
50RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Office 2007 - Malformed Document Stack Buffer Overflow
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Automation Services in SharePoint Server 2010, Web Applica
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Office 2007 - OneTableDocumentStream Invalid Object
Microsoft Word 2007 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruptio
35RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox - 'pdf.js' Privileged JavaScript Injection (Metasploit)
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource
50RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox - 'pdf.js' Privileged JavaScript Injection (Metasploit)
Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl
50RISK
open ↗Exploit-DB
Pligg CMS 2.0.2 - Cross-Site Request Forgery (Add Admin)
Cross-site request forgery (CSRF) vulnerability in Pligg CMS 2.0.2 allows remote attackers to hijack the authentication
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'ATMFD.dll' CharString Stream Out-of-Bounds Reads (MS15-021)
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
35RISK
open ↗Exploit-DB
Netsweeper 3.0.6 - Authentication Bypass
Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'ATMFD.dll' CFF table (ATMFD+0x3440b / ATMFD+0x3440e) Invalid Memory Access
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
35RISK
open ↗Exploit-DB
WordPress Plugin MDC Private Message 1.0.0 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the MDC Private Message plugin 1.0.0 for WordPress allows remote authenticat
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'ATMFD.DLL' CFF table (ATMFD+0x34072 / ATMFD+0x3407b) Invalid Memory Access
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
35RISK
open ↗Exploit-DB
Netsweeper 4.0.4 - SQL Injection
SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1
23RISK
open ↗Exploit-DB
Netsweeper 4.0.8 - SQL Injection / Authentication Bypass
WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass aut
23RISK
open ↗Exploit-DB✓ VexDay Proof
Konica Minolta FTP Utility 1.0 - Remote Denial of Service (PoC)
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code or cause a denial of
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla - Maintenance Service Log File Overwrite Privilege Escalation
Race condition in the Mozilla Maintenance Service in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Win
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'win32k.sys' TTF Font Processing win32k!fsc_BLTHoriz Out-of-Bounds Pool Write
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
35RISK
open ↗Exploit-DB
Netsweeper 2.6.29.8 - SQL Injection
Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL co
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Office 2007 - MSPTLS Heap Index Integer Underflow (MS15-081)
Integer underflow in Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office for Mac 201
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.