Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
80,930cataloged exploits
37,572CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 23,973GitHub PoC 15,478VulnCheck XDB 9,069Nuclei 4,426Metasploit 3,502✓ verified onlyrecentpopularrisk
24,482 exploits
Exploit-DB✓ VexDay Proof
Wireshark 1.4.4 - 'packet-dect.c' Local Stack Buffer Overflow (Metasploit) (1)
Stack-based buffer overflow in the DECT dissector in epan/dissectors/packet-dect.c in Wireshark 1.4.x before 1.4.5 allow
50RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle JD Edwards EnterpriseOne 8.9x Tools Web Runtime SEC - '/jde/JASMafletMafBrowserClose.mafService?jdemafjasLinkTarget' Cross-Site Scripting
Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8.9 GA through 8.98.4.1 and OneWorld Tools through 24
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player < 10.1.53.64 - Action Script Type Confusion (ASLR + DEP Bypass)
Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 o
50RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Tivoli Directory Server SASL - Bind Request Remote Code Execution
Stack-based buffer overflow in the server process in ibmslapd.exe in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.
28RISK
open ↗Exploit-DB✓ VexDay Proof
Wireshark 1.4.1 < 1.4.4 - Local Overflow (SEH)
Stack-based buffer overflow in the DECT dissector in epan/dissectors/packet-dect.c in Wireshark 1.4.x before 1.4.5 allow
50RISK
open ↗Exploit-DB
FiSH-irssi 0.99 - Evil ircd Buffer Overflow
Multiple stack-based buffer overflows in the (1) ExtractRnick and (2) decrypt_topic_332 functions in FiSH allow remote a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player 10.2.153.1 - SWF Memory Corruption (Metasploit)
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; A
100RISK
open ↗Exploit-DB
Microsoft Word 2003 - Record Parsing Buffer Overflow (MS09-027) (Metasploit)
Buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 200
35RISK
open ↗Exploit-DB✓ VexDay Proof
EC Software Help & Manual 5.5.1 Build 1296 - 'ijl15.dll' DLL Loading Arbitrary Code Execution
Untrusted search path vulnerability in Help & Manual 5.5.1 Build 1296 allows local users to gain privileges via a Trojan
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Excel - Remote Buffer Overflow
Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow re
35RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco Security Agent Management Console - 'st_upload' Remote Code Execution
The Management Console (webagent.exe) in Cisco Security Agent 5.1, 5.2, and 6.0 before 6.0.2.145 allows remote attackers
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Host Integration Server 2004-2010 - Remote Denial of Service
Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of
28RISK
open ↗Exploit-DB✓ VexDay Proof
VeryTools VideoSpirit Pro 1.70 - '.visprj' Local Buffer Overflow (Metasploit)
Buffer overflow in VideoSpirit Pro 1.6.8.1, 1.68, and earlier; and VideoSpirit Lite 1.4.0.1 and possibly other versions;
50RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - 'inotify_init1()' Double-Free Local Denial of Service
Double free vulnerability in the inotify subsystem in the Linux kernel before 2.6.39 allows local users to cause a denia
23RISK
open ↗Exploit-DB
tmux 1.3/1.4 - '-S' Option Incorrect SetGID Privilege Escalation
tmux 1.3 and 1.4 does not properly drop group privileges, which allows local users to gain utmp group privileges via a f
23RISK
open ↗Exploit-DB✓ VexDay Proof
MIT Kerberos 5 - kadmind Change Password Feature Remote Code Execution
The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka kr
28RISK
open ↗Exploit-DB✓ VexDay Proof
VeryTools VideoSpirit Pro 1.70 - '.visprj' Local Buffer Overflow (Metasploit)
Buffer overflow in VideoSpirit Pro 1.6.8.1 and possibly earlier versions, and VideoSpirit Lite 1.4.0.1 and possibly othe
50RISK
open ↗Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 1.1.8 - ModPlug ReadS3M Stack Buffer Overflow (Metasploit)
Stack-based buffer overflow in the ReadS3M method in load_s3m.cpp in libmodplug before 0.8.8.2 allows remote attackers t
50RISK
open ↗Exploit-DB
eyeos 2.3 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in framework/source/resource/qx/test/jsonp_primitive.php in QooxDoo 1.3 and pos
23RISK
open ↗Exploit-DB✓ VexDay Proof
Redmine 1.0.1/1.1.1 - 'projects/hg-hellowword/news/' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in app/views/layouts/base.rhtml in Redmine 1.0.1 through 1.1.1 allows remote at
23RISK
open ↗Exploit-DB
eyeos 2.3 - Multiple Vulnerabilities
Directory traversal vulnerability in framework/source/resource/qx/test/part/delay.php in QooxDoo 1.3 and possibly other
23RISK
open ↗Exploit-DB
WordPress Plugin Custom Pages 0.5.0.1 - Local File Inclusion
Directory traversal vulnerability in wp-download.php in the WP Custom Pages module 0.5.0.1 for WordPress allows remote a
43RISK
open ↗Exploit-DB✓ VexDay Proof
python-feedparser 5.0 - '/feedparser/feedparser.py' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser)
23RISK
open ↗Exploit-DB
OpenEMR 4.0.0 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in setup.php in OpenEMR 4 allows remote attackers to inject arbitrary web scrip
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Lotus Domino iCalendar - MAILTO Buffer Overflow (Metasploit)
Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server i
50RISK
open ↗Exploit-DB
Yaws-Wiki 1.88-1 (Erlang) - Persistent / Reflective Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the wiki application in Yaws 1.88 allow remote attackers to injec
23RISK
open ↗Exploit-DB✓ VexDay Proof
Anzeigenmarkt 2011 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in Anzeigenmarkt 2011 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
AWCM 2.x - 'search.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.php in AR Web Content Manager (AWCM) 2.1, 2.2, and possibly other ver
23RISK
open ↗Exploit-DB✓ VexDay Proof
InTerra Blog Machine 1.84 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in actions/add.php in InTerra Blog Machine 1.84, and possibly earlier versions,
23RISK
open ↗Exploit-DB✓ VexDay Proof
IPComp - encapsulation Kernel Memory Corruption
Multiple stack consumption vulnerabilities in the kernel in NetBSD 4.0, 5.0 before 5.0.3, and 5.1 before 5.1.1, when IPs
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.