Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,500cataloged exploits
34,965CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 13,937VulnCheck XDB 8,510Nuclei 4,243Metasploit 3,468✓ verified onlyrecentpopularrisk
24,443 exploits
Exploit-DB
Adobe Premier Pro CS4 - 'ibfs32.dll' DLL Hijacking
Untrusted search path vulnerability in Adobe Premier Pro CS4 4.0.0 (314 (MC: 160820)) allows local users, and possibly r
28RISK
open ↗Exploit-DB
Adobe Device Central CS5 - 'qtcf.dll' DLL Hijacking
Untrusted search path vulnerability in Adobe Device Central CS5 3.0.0(376), 3.0.1.0 (3027), and probably other versions
28RISK
open ↗Exploit-DB✓ VexDay Proof
CorelDRAW X3 13.0.0.576 - 'crlrib.dll' DLL Hijacking
Multiple untrusted search path vulnerabilities in Corel PHOTO-PAINT and CorelDRAW X5 15.1.0.588 allow local users to gai
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe ExtendedScript Toolkit CS5 3.5.0.52 - 'dwmapi.dll' DLL Hijacking
Untrusted search path vulnerability in Adobe ExtendScript Toolkit (ESTK) CS5 3.5.0.52 allows local users, and possibly r
28RISK
open ↗Exploit-DB
Microsoft PowerPoint 2007 - 'rpawinet.dll' DLL Hijacking
Untrusted search path vulnerability in Microsoft PowerPoint 2010 allows local users, and possibly remote attackers, to e
28RISK
open ↗Exploit-DB
Cisco Packet Tracer 5.2 - 'wintab32.dll' DLL Hijacking
Untrusted search path vulnerability in Cisco Packet Tracer 5.2 allows local users, and possibly remote attackers, to exe
23RISK
open ↗Exploit-DB✓ VexDay Proof
Skype 4.2.0.169 - 'wab32.dll' DLL Hijacking
Untrusted search path vulnerability in Skype 4.2.0.169 and earlier allows local users, and possibly remote attackers, to
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Internet Communication Settings - 'schannel.dll' DLL Hijacking
Untrusted search path vulnerability in Microsoft Windows Internet Communication Settings on Windows XP SP3 allows local
28RISK
open ↗Exploit-DB
Roxio MyDVD 9 - 'HomeUtils9.dll' DLL Hijacking
Untrusted search path vulnerability in Roxio MyDVD 9 allows local users to gain privileges via a Trojan horse HomeUtils9
23RISK
open ↗Exploit-DB✓ VexDay Proof
Corel PHOTO-PAINT X3 13.0.0.576 - 'crlrib.dll' DLL Hijacking
Multiple untrusted search path vulnerabilities in Corel PHOTO-PAINT and CorelDRAW X5 15.1.0.588 allow local users to gai
23RISK
open ↗Exploit-DB
Adobe On Location CS4 - 'ibfs32.dll' DLL Hijacking
Untrusted search path vulnerability in Adobe On Location CS4 Build 315 allows local users, and possibly remote attackers
28RISK
open ↗Exploit-DB
Microsoft Visio 2003 - 'mfc71enu.dll' DLL Hijacking
Untrusted search path vulnerability in Microsoft Visio 2003 SP3 allows local users to gain privileges via a Trojan horse
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - Object Type (MS03-020) (Metasploit)
Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via
60RISK
open ↗Exploit-DB
Roxio Creator DE - 'HomeUtils9.dll' DLL Hijacking
Untrusted search path vulnerability in Roxio Easy Media Creator Home 9.0.136 allows local users to gain privileges via a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Group Convertor - 'imm.dll' DLL Hijacking
Untrusted search path vulnerability in Microsoft Windows Progman Group Converter (grpconv.exe) allows local users, and p
28RISK
open ↗Exploit-DB✓ VexDay Proof
Mercur Messaging 2005 - IMAP Login Buffer Overflow (Metasploit)
Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause
50RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft RRAS Service - RASMAN Registry Overflow (MS06-025) (Metasploit)
Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Serve
60RISK
open ↗Exploit-DB✓ VexDay Proof
SquirrelMail PGP Plugin - Command Execution (SMTP) (Metasploit)
The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via s
43RISK
open ↗Exploit-DB✓ VexDay Proof
NTP daemon readvar - Remote Buffer Overflow (Metasploit)
Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial o
60RISK
open ↗Exploit-DB
Microsoft Office Groove 2007 - 'mso.dll' DLL Hijacking
Multiple untrusted search path vulnerabilities in Microsoft Groove 2007 SP2 allow local users to gain privileges via a T
28RISK
open ↗Exploit-DB
Adobe InDesign CS4 - 'ibfs32.dll' DLL Hijacking
Untrusted search path vulnerability in Adobe InDesign CS4 6.0, InDesign CS5 7.0.2 and earlier, Adobe InDesign Server CS5
28RISK
open ↗Exploit-DB✓ VexDay Proof
Autodesk AutoCAD 2007 - 'color.dll' DLL Hijacking
Multiple untrusted search path vulnerabilities in Autodesk AutoCAD 2010 allow local users to gain privileges via a Troja
23RISK
open ↗Exploit-DB
Adobe Dreamweaver CS4 - 'ibfs32.dll' DLL Hijacking
Untrusted search path vulnerability in Adobe Dreamweaver CS5 11.0 build 4916, build 4909, and probably other versions, a
28RISK
open ↗Exploit-DB
Foxit Reader 4.0 - '.pdf' Multiple Stack Based Buffer Overflow 'Jailbreak'
Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpr
35RISK
open ↗Exploit-DB
Microsoft PowerPoint 2010 - 'pptimpconv.dll' DLL Hijacking
Untrusted search path vulnerability in Microsoft Office PowerPoint 2007 allows local users, and possibly remote attacker
28RISK
open ↗Exploit-DB✓ VexDay Proof
μTorrent (uTorrent) 2.0.3 - 'plugin_dll.dll' DLL Hijacking
Untrusted search path vulnerability in uTorrent 2.0.3 and earlier allows local users, and possibly remote attackers, to
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox 3.6.8 - 'dwmapi.dll' DLL Hijacking
Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 an
28RISK
open ↗Exploit-DB
TeamViewer 5.0.8703 - 'dwmapi.dll' DLL Hijacking
Untrusted search path vulnerability in TeamViewer 5.0.8703 and earlier allows local users, and possibly remote attackers
23RISK
open ↗Exploit-DB
Microsoft Windows 7 - 'wab32res.dll wab.exe' DLL Hijacking
Untrusted search path vulnerability in Microsoft Windows Contacts allows local users, and possibly remote attackers, to
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.