Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,104GitHub PoC 15,075VulnCheck XDB 8,883Nuclei 4,365Metasploit 3,493✓ verified onlyrecentpopularrisk
24,695 exploits
Exploit-DB✓ VexDay Proof
SonicWALL SSL-VPN - NetExtender ActiveX Control Buffer Overflow (Metasploit)
Stack-based buffer overflow in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x
50RISK
open ↗Exploit-DB✓ VexDay Proof
PSOProxy 0.91 - Stack Buffer Overflow (Metasploit)
Buffer overflow in PSOProxy 0.91 allows remote attackers to cause a denial of service and possibly execute arbitrary cod
50RISK
open ↗Exploit-DB✓ VexDay Proof
mIRC - IRC URL Buffer Overflow (Metasploit)
Buffer overflow in mIRC before 6.11 allows remote attackers to execute arbitrary code via a long irc:// URL.
50RISK
open ↗Exploit-DB✓ VexDay Proof
Alibaba Clone 3.0 (Special) - SQL Injection
SQL injection vulnerability in offers_buy.php in Alibaba Clone 3.0 allows remote attackers to execute arbitrary SQL comm
23RISK
open ↗Exploit-DB✓ VexDay Proof
Novell iPrint Client - ActiveX Control Date/Time Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in Novell iPrint Client 4.38, 5.30, and possibly other versions before 5.32 allow
50RISK
open ↗Exploit-DB✓ VexDay Proof
Facebook Photo Uploader 4 - ActiveX Control Buffer Overflow (Metasploit)
Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to
50RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Media Encoder 9 - 'wmex.dll' ActiveX Buffer Overflow (MS08-053) (Metasploit)
Stack-based buffer overflow in the WMEncProfileManager ActiveX control in wmex.dll in Microsoft Windows Media Encoder 9
50RISK
open ↗Exploit-DB✓ VexDay Proof
eFront 3.x - 'ask_chat.php' SQL Injection
SQL injection vulnerability in ask_chat.php in eFront 3.6.2 and earlier allows remote attackers to execute arbitrary SQL
23RISK
open ↗Exploit-DB✓ VexDay Proof
SHTTPD 1.34 (Windows x86) - URI-Encoded POST Request Overflow (Metasploit)
Stack-based buffer overflow in Sergey Lyubka Simple HTTPD (shttpd) 1.34 allows remote attackers to execute arbitrary cod
50RISK
open ↗Exploit-DB✓ VexDay Proof
MySQL yaSSL (Windows) - SSL Hello Message Buffer Overflow (Metasploit)
Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attacke
60RISK
open ↗Exploit-DB✓ VexDay Proof
MySQL yaSSL (Linux) - SSL Hello Message Buffer Overflow (Metasploit)
Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attacke
60RISK
open ↗Exploit-DB✓ VexDay Proof
Medal of Honor Allied Assault - getinfo Stack Buffer Overflow (Metasploit)
Buffer overflow in Medal of Honor (1) Allied Assault 1.11v9 and earlier, (2) Breakthrough 2.40b and earlier, and (3) Spe
50RISK
open ↗Exploit-DB✓ VexDay Proof
iseemedia / Roxio / MGI Software LPViewer - ActiveX Control Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in MGI Software LPViewer ActiveX control (LPControl.dll), as acquired by Roxio and
43RISK
open ↗Exploit-DB✓ VexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'OpenView5.exe' CGI Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allow remote att
50RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Workstation Service - NetAddAlternateComputerName Overflow (MS03-049) (Metasploit)
Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers t
60RISK
open ↗Exploit-DB✓ VexDay Proof
YahooPOPs (YPOPS) 0.6 - Remote Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in YPOPs! (aka YahooPOPS) 0.4 through 0.6 allow remote attackers to cause a denial
60RISK
open ↗Exploit-DB✓ VexDay Proof
Apple QuickTime 7.3 - RTSP Response Header Buffer Overflow (Metasploit)
Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac
50RISK
open ↗Exploit-DB✓ VexDay Proof
SapLPD 6.28 - Remote Buffer Overflow (Metasploit)
Buffer overflow in SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to
60RISK
open ↗Exploit-DB✓ VexDay Proof
GoodTech Telnet Server 5.0.6 - Remote Buffer Overflow (Metasploit)
Buffer overflow in the administration web server for GoodTech Telnet Server 4.0 and 5.0, and possibly all versions befor
50RISK
open ↗Exploit-DB✓ VexDay Proof
Ask.com Toolbar - 'askBar.dll' ActiveX Control Buffer Overflow (Metasploit)
Stack-based buffer overflow in the AskJeevesToolBar.SettingsPlugin.1 ActiveX control in askBar.dll in IAC Search & Media
50RISK
open ↗Exploit-DB✓ VexDay Proof
D-Link TFTP 1.0 - 'Filename' Remote Buffer Overflow (Metasploit)
Buffer overflow in D-Link TFTP Server 1.0 allows remote attackers to cause a denial of service (crash) via a long (1) GE
50RISK
open ↗Exploit-DB✓ VexDay Proof
Symantec Remote Management - Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitr
60RISK
open ↗Exploit-DB✓ VexDay Proof
RealNetworks RealPlayer - '.SMIL' Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in the CSmil1Parser::testAttributeFailed function in smlparse.cpp for RealNetworks RealPlaye
50RISK
open ↗Exploit-DB✓ VexDay Proof
SAP AG SAPgui EAI WebViewer3D - Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in EAI WebViewer3D ActiveX control (webviewer3d.dll) in SAP AG SAPgui before 7.10 Patch Leve
50RISK
open ↗Exploit-DB✓ VexDay Proof
Orbit Downloader - Connecting Log Creation Buffer Overflow (Metasploit)
Stack-based buffer overflow in Orbit Downloader 2.8.2 and 2.8.3, and possibly other versions before 2.8.5, allows remote
50RISK
open ↗Exploit-DB✓ VexDay Proof
Creative Software AutoUpdate Engine - ActiveX Control Buffer Overflow (Metasploit)
Stack-based buffer overflow in the Creative Software AutoUpdate Engine ActiveX control in CTSUEng.ocx allows remote atta
50RISK
open ↗Exploit-DB✓ VexDay Proof
CA BrightStor ARCserve - Tape Engine Buffer Overflow (Metasploit)
Buffer overflow in the Tape Engine (tapeeng.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 an
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Outlook Express - NNTP Response Parsing Buffer Overflow (MS05-030) (Metasploit)
Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows rem
60RISK
open ↗Exploit-DB✓ VexDay Proof
Easy File Sharing FTP Server 2.0 - PASS Overflow (Metasploit)
Stack-based buffer overflow in EFS Software Easy File Sharing FTP Server 2.0 allows remote attackers to execute arbitrar
50RISK
open ↗Exploit-DB✓ VexDay Proof
freeFTPd 1.0.10 - Key Exchange Algorithm String Buffer Overflow (Metasploit)
Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other produc
60RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.