Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,542cataloged exploits
34,971CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 13,947VulnCheck XDB 8,542Nuclei 4,243Metasploit 3,468✓ verified onlyrecentpopularrisk
24,443 exploits
Exploit-DB✓ VexDay Proof
Samba 3.0.24 (Linux) - 'lsa_io_trans_names' Heap Overflow (Metasploit)
Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers
60RISK
open ↗Exploit-DB✓ VexDay Proof
IPSwitch WhatsUp Gold 8.03 - Remote Buffer Overflow (Metasploit)
Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to
50RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Excel - 0x5D record Stack Overflow (MS10-038)
Stack-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML F
60RISK
open ↗Exploit-DB
Struts2/XWork < 2.2.0 - Remote Command Execution
The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fishe
60RISK
open ↗Exploit-DB✓ VexDay Proof
Samba 2.2.8 (Linux x86) - 'trans2open' Remote Overflow (Metasploit)
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Solaris - 'rdist' Privilege Escalation
Unspecified vulnerability in Oracle OpenSolaris 10 allows local users to affect confidentiality, integrity, and availabi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Free Download Manager 2.5 Build 758 - Remote Control Server Buffer Overflow (Metasploit)
Stack-based buffer overflow in Remote Control Server in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allo
50RISK
open ↗Exploit-DB✓ VexDay Proof
eDirectory 8.7.3 - iMonitor Remote Stack Buffer Overflow (Metasploit)
Buffer overflow in dhost.exe in iMonitor for Novell eDirectory 8.7.3 on Windows allows attackers to cause a denial of se
50RISK
open ↗Exploit-DB
AJ Article 3.0 - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AJ Square AJ Article 3.0 allow remote attackers to i
23RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Solaris - 'nfslogd' Insecure Temporary File Creation
Unspecified vulnerability in Oracle Solaris 8, 9, and 10, and OpenSolaris, allows local users to affect confidentiality
23RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle WebLogic Server 10.3.3 - Encoded URL
Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server componen
23RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Business Process Management 10.3.2 - Cross-Site Scripting
Unspecified vulnerability in the Oracle Business Process Management component in Oracle Fusion Middleware 5.7 MP3, 6.0 M
23RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Solaris Management Console - WBEM Insecure Temporary File Creation
Unspecified vulnerability in Oracle Solaris 9 and 10 allows local users to affect confidentiality and integrity via unkn
23RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Solaris 8/9/10 - 'flar' Insecure Temporary File Creation
Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows local users to affect confidentiality and integrity via
23RISK
open ↗Exploit-DB✓ VexDay Proof
NaviCOPA Web Server 2.0.1 - URL Handling Buffer Overflow (Metasploit)
Buffer overflow in InterVations NaviCOPA Web Server 2.01 allows remote attackers to execute arbitrary code via a long HT
50RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - Style getElementsByTagName Memory Corruption (MS09-072) (Metasploit)
Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory that (1) were not properly initialized or
60RISK
open ↗Exploit-DB✓ VexDay Proof
Linux PAM 1.1.0 (Ubuntu 9.10/10.04) - MOTD File Tampering Privilege Escalation (2)
pam_motd (aka the MOTD module) in libpam-modules before 1.1.0-2ubuntu1.1 in PAM on Ubuntu 9.10 and libpam-modules before
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - 'Aurora' Memory Corruption (MS10-002) (Metasploit)
Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and S
100RISK
open ↗Exploit-DB✓ VexDay Proof
Grafik CMS 1.1.2 - Multiple Cross-Site Request Forgery Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in admin/admin.php in Grafik CMS 1.1.2, and possibly earlier, allow
23RISK
open ↗Exploit-DB✓ VexDay Proof
LibTIFF 3.9.4 - Out-Of-Order Tag Type Mismatch Remote Denial of Service
The TIFFReadDirectory function in LibTIFF 3.9.0 does not properly validate the data types of codec-specific tags that ha
23RISK
open ↗Exploit-DB✓ VexDay Proof
Blue Coat WinProxy - Host Header Overflow (Metasploit)
Buffer overflow in BlueCoat (a) WinProxy before 6.1a and (b) the web console access functionality in ProxyAV before 2.4.
50RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 7 - CFunctionPointer Uninitialized Memory Corruption (MS09-002) (Metasploit)
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RISK
open ↗Exploit-DB
TomatoCMS 2.0.5 - Multiple Cross-Site Request Forgery Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in TomatoCMS 2.0.6 allows remote attackers to hijack the authentication
23RISK
open ↗Exploit-DB
My Kazaam Address & Contact ORGanizer - SQL Injection
SQL injection vulnerability in address_book/contacts.php in My Kazaam Address & Contact Organizer allows remote attacker
23RISK
open ↗Exploit-DB✓ VexDay Proof
My Kazaam Notes Management System - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in notes.php in My Kazaam Notes Management System allows remote attackers to in
23RISK
open ↗Exploit-DB
Joomla! Component redSHOP 1.0 - 'pid' SQL Injection
SQL injection vulnerability in the redSHOP Component (com_redshop) 1.0 for Joomla! allows remote attackers to execute ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
My Kazaam Notes Management System - Multiple Vulnerabilities
SQL injection vulnerability in notes.php in My Kazaam Notes Management System allows remote attackers to execute arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
Edgephp ClickBank Affiliate Marketplace Script - Multiple Vulnerabilities
SQL injection vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allows remote atta
23RISK
open ↗Exploit-DB✓ VexDay Proof
Edgephp ClickBank Affiliate Marketplace Script - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allow
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft - 'MSHTML.dll' CTIMEOUTEVENTLIST::INSERTINTOTIMEOUTLIST Memory Leak
The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of pr
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.