Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
80,646cataloged exploits
37,382CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 23,825GitHub PoC 15,392VulnCheck XDB 9,029Nuclei 4,416Metasploit 3,502✓ verified onlyrecentpopularrisk
24,482 exploits
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - execCommand Use-After-Free (MS12-063) (Metasploit)
Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 al
100RISK
open ↗Exploit-DB✓ VexDay Proof
NTR - ActiveX Control 'Check()' Method Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in the NTR ActiveX control before 2.0.4.8 allow remote attackers to execute arbitr
50RISK
open ↗Exploit-DB✓ VexDay Proof
OpenX 2.8.10 - 'plugin-index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admin/plugin-index.php in OpenX 2.8.10 before revision 81823 allows remote a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple iOS Mobile Mail - LibTIFF Buffer Overflow (Metasploit)
Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a
100RISK
open ↗Exploit-DB
PLIB 1.8.5 - 'ssg/ssgParser.cxx' Local Buffer Overflow
Stack-based buffer overflow in the error function in ssg/ssgParser.cxx in PLIB 1.8.5 allows remote attackers to execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple iOS Mobile Mail - LibTIFF Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and othe
50RISK
open ↗Exploit-DB✓ VexDay Proof
Apple iOS Mobile Safari - LibTIFF Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and othe
50RISK
open ↗Exploit-DB✓ VexDay Proof
Apple iOS Mobile Safari - LibTIFF Buffer Overflow (Metasploit)
Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a
100RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 3.2.x - 'uname()' System Call Local Information Disclosure
The override_release function in kernel/sys.c in the Linux kernel before 3.4.16 allows local users to obtain sensitive i
23RISK
open ↗Exploit-DB
Template CMS 2.1.1 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in Template CMS 2.1.1 and earlier allows remote attackers to inject arbitrary w
23RISK
open ↗Exploit-DB
XnView 1.99.1 - '.JLS' File Decompression Heap Overflow
Heap-based buffer overflow in the xjpegls.dll (aka JLS, JPEG-LS, or JPEG lossless) format plugin in XnView 1.99 and 1.99
23RISK
open ↗Exploit-DB
Template CMS 2.1.1 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in Template CMS 2.1.1 and earlier allow remote attackers to h
23RISK
open ↗Exploit-DB✓ VexDay Proof
JPEGsnoop 1.5.2 - WriteAV Crash (PoC)
A vulnerability exists in JPEGsnoop 1.5.2 due to an unspecified issue in JPEG file handling, which could let a malicious
23RISK
open ↗Exploit-DB
Novell Sentinel Log Manager 1.2.0.2 - Retention Policy
Novell Sentinel Log Manager before 1.2.0.3 allows remote attackers to create data retention policies via a crafted text/
23RISK
open ↗Exploit-DB✓ VexDay Proof
PowerTCP WebServer for - ActiveX Denial of Service
Stack consumption vulnerability in dartwebserver.dll 1.9 and earlier, as used in Dart PowerTCP WebServer for ActiveX and
23RISK
open ↗Exploit-DB✓ VexDay Proof
Trend Micro Control Manager 5.5/6.0 AdHocQuery - (Authenticated) Blind SQL Injection
SQL injection vulnerability in the ad hoc query module in Trend Micro Control Manager (TMCM) before 5.5.0.1823 and 6.0 b
23RISK
open ↗Exploit-DB
JAMF Casper Suite MDM - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in editAccount.html in the JAMF Software Server (JSS) interfa
23RISK
open ↗Exploit-DB
Cisco DPC2100 - Denial of Service
Unspecified vulnerability in Cisco Wireless LAN Controller (WLC) software 6.0 before 6.0.200.0, 7.0 before 7.0.98.216, a
28RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin MF Gig Calendar - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the MF Gig Calendar plugin 0.9.2 for WordPress allows remote attackers to in
38RISK
open ↗Exploit-DB
Netsweeper WebAdmin Portal - Multiple Vulnerabilities
Unspecified vulnerability in the WebAdmin Portal in Netsweeper has unknown impact and attack vectors, a different vulner
23RISK
open ↗Exploit-DB✓ VexDay Proof
Novell Groupwise 8.0.2 HP3 and 2012 - Integer Overflow
Integer overflow in the WebConsole component in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 befo
28RISK
open ↗Exploit-DB✓ VexDay Proof
CoSoSys Endpoint Protector - Predictable Password Generation
The CoSoSys Endpoint Protector 4 appliance establishes an EPProot password based entirely on the appliance serial number
23RISK
open ↗Exploit-DB
Trend Micro Interscan Messaging Security Suite - Persistent Cross-Site Scripting / Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in saveAccountSubTab.imss in Trend Micro InterScan Messaging Security Su
23RISK
open ↗Exploit-DB
Trend Micro Interscan Messaging Security Suite - Persistent Cross-Site Scripting / Cross-Site Request Forgery
Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro InterScan Messaging Security Suite 7.1-Build_Win32_13
23RISK
open ↗Exploit-DB✓ VexDay Proof
Google Chrome for Android - Local Application Handling Cookie Theft
Google Chrome before 18.0.1025308 on Android allows remote attackers to obtain cookie information via a crafted applicat
23RISK
open ↗Exploit-DB✓ VexDay Proof
Google Chrome for Android - Same-origin Policy Bypass Local Symlink
Google Chrome before 18.0.1025308 on Android allows remote attackers to bypass the Same Origin Policy and obtain access
23RISK
open ↗Exploit-DB
Ezylog Photovoltaic Management Server - Multiple Vulnerabilities
Sinapsi eSolar Improper Authentication
48RISK
open ↗Exploit-DB
Ezylog Photovoltaic Management Server - Multiple Vulnerabilities
Sinapsi eSolar SQL Injection
41RISK
open ↗Exploit-DB✓ VexDay Proof
Google Chrome for Android - Multiple 'file::' URL Handler Local Downloaded Content Disclosure Vulnerabilities
Google Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which allows remote attack
23RISK
open ↗Exploit-DB
Ezylog Photovoltaic Management Server - Multiple Vulnerabilities
Sinapsi eSolar Hard-Coded Password
53RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.