Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,496cataloged exploits
34,964CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 13,937VulnCheck XDB 8,510Nuclei 4,239Metasploit 3,468✓ verified onlyrecentpopularrisk
24,443 exploits
Exploit-DB✓ VexDay Proof
DjVu - 'DjVu_ActiveX_MSOffice.dll' ActiveX Component Buffer Overflow (Metasploit)
Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers
50RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe - 'util.printf()' Local Buffer Overflow (Metasploit) (2)
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary c
100RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe - FlateDecode Stream Predictor 02 Integer Overflow (Metasploit) (2)
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows rem
100RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Visual Basic - '.VBP' Local Buffer Overflow (Metasploit)
Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to ex
50RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe - JBIG2Decode Memory Corruption (Metasploit) (2)
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitra
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Works 7 - 'WkImgSrv.dll' WKsPictureInterface() ActiveX (Metasploit)
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and
50RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft HTML Help Workshop 4.74 - '.hhp' Index Buffer Overflow (Metasploit) (3)
Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary
50RISK
open ↗Exploit-DB✓ VexDay Proof
E-Xoopport Samsara 3.1 (eCal Module) - Blind SQL Injection
SQL injection vulnerability in location.php in the eCal module in E-Xoopport Samsara 3.1 and earlier allows remote attac
23RISK
open ↗Exploit-DB✓ VexDay Proof
PointDev IDEAL Migration - Buffer Overflow (Metasploit)
Stack-based buffer overflow in Ideal Administration 2009 9.7.1, and possibly other versions, allows remote attackers to
50RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe CoolType - SING Table 'uniqueName' Local Stack Buffer Overflow (Metasploit) (2)
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows
100RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Excel - Malformed FEATHEADER Record (MS09-067) (Metasploit)
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Conv
100RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft PowerPoint Viewer - TextBytesAtom Stack Buffer Overflow (MS10-004) (Metasploit)
Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code vi
50RISK
open ↗Exploit-DB✓ VexDay Proof
URSoft W32Dasm 8.93 - Disassembler Function Buffer Overflow (Metasploit)
Buffer overflow in the wsprintf function in W32Dasm 8.93 and earlier allows remote attackers to execute arbitrary code v
50RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe - 'Collab.getIcon()' Local Buffer Overflow (Metasploit) (2)
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows r
100RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe - 'Collab.collectEmailInfo()' Local Buffer Overflow (Metasploit)
Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code
100RISK
open ↗Exploit-DB✓ VexDay Proof
SasCam Webcam Server 2.6.5 - 'Get()' Method Buffer Overflow (Metasploit)
Buffer overflow in the XHTTP Module 4.1.0.0 in the ActiveX control for SaschArt SasCam Webcam Server 2.6.5 allows remote
50RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox CSS - font-face Remote Code Execution
Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x befo
23RISK
open ↗Exploit-DB✓ VexDay Proof
ProShow Gold 4.0.2549 - '.psh' Local Stack Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in Photodex ProShow Gold 4.0.2549 allow remote attackers to execute arbitrary code
50RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe - U3D CLODProgressiveMeshDeclaration Array Overrun (Metasploit) (2)
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x befor
100RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe - 'Doc.media.newPlayer' Use-After-Free (Metasploit) (2)
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before
100RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - 'newfunction' Invalid Pointer Use (Metasploit) (2)
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrob
100RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft MPEG Layer-3 Audio Decoder - Division By Zero
Multiple stack-based buffer overflows in the MPEG Layer-3 audio codecs in Microsoft Windows 2000 SP4, XP SP2 and SP3, Se
50RISK
open ↗Exploit-DB
Joomla! Component Elite Experts - SQL Injection
SQL injection vulnerability in the Elite Experts (com_elite_experts) component for Mambo and Joomla! allows remote attac
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linksys WRT54 Access Point - 'apply.cgi' Remote Buffer Overflow (Metasploit)
Buffer overflow in apply.cgi in Linksys WRT54G 3.01.03, 3.03.6, and possibly other versions before 4.20.7, allows remote
60RISK
open ↗Exploit-DB✓ VexDay Proof
FreePBX 2.8.0 - Recordings Interface Allows Remote Code Execution
Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interfa
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Excel - OBJ Record Stack Overflow
Stack-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML F
60RISK
open ↗Exploit-DB✓ VexDay Proof
WAnewsletter 2.1.2 - SQL Injection
SQL injection vulnerability in index.php in WAnewsletter 2.1.2 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader and Flash - 'newfunction' Remote Code Execution
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbi
28RISK
open ↗Exploit-DB
GeekLog 1.3.8 (filemgmt) - SQL Injection
SQL injection vulnerability in filemgmt/singlefile.php in Geeklog 1.3.8 allows remote attackers to execute arbitrary SQL
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Joostina - SQL Injection
SQL injection vulnerability in the Joostina (com_ezautos) component for Joomla! allows remote attackers to execute arbit
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.