Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,559cataloged exploits
34,978CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 13,960VulnCheck XDB 8,542Nuclei 4,243Metasploit 3,472✓ verified onlyrecentpopularrisk
24,443 exploits
Exploit-DB✓ VexDay Proof
Banner Management Script - SQL Injection
SQL injection vulnerability in trackads.php in YourFreeWorld Banner Management allows remote attackers to execute arbitr
23RISK
open ↗Exploit-DB✓ VexDay Proof
H264WebCam - Boundary Condition Error
H264WebCam 3.7 allows remote attackers to cause a denial of service (crash) via a long URI in a GET request, which trigg
23RISK
open ↗Exploit-DB✓ VexDay Proof
PowerZip 7.21 (Build 4010) - Stack Buffer Overflow
Stack-based buffer overflow in the UpdateFrameTitleForDocument method in the CFrameWnd class in mfc42.dll in the Microso
28RISK
open ↗Exploit-DB✓ VexDay Proof
Spring Framework - Arbitrary code Execution
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote at
35RISK
open ↗Exploit-DB✓ VexDay Proof
BlazeDVD 5.1 (Windows 7) - '.plf' File Stack Buffer Overflow (ASLR + DEP Bypass)
Stack-based buffer overflow in BlazeVideo BlazeDVD Standard and Professional 5.0, and possibly earlier, allows remote at
50RISK
open ↗Exploit-DB✓ VexDay Proof
File Sharing Wizard 1.5.0 - Remote Overflow (SEH)
Stack-based buffer overflow in iSharer File Sharing Wizard 1.5.0 allows remote attackers to execute arbitrary code via a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Netware - SMB Remote Stack Overflow (PoC)
Stack-based buffer overflow in the CIFS.NLM driver in Netware SMB 1.0 for Novell Netware 6.5 SP8 and earlier allows remo
28RISK
open ↗Exploit-DB✓ VexDay Proof
Batch Audio Converter Lite Edition 1.0.0.0 - Local Stack Buffer Overflow (SEH)
Stack-based buffer overflow in Batch Audio Converter Lite Edition 1.0.0.0 and earlier allows remote attackers to execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
Samba 2.2.8 (BSD x86) - 'trans2open' Remote Overflow (Metasploit)
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RISK
open ↗Exploit-DB✓ VexDay Proof
2DayBiz Online Classified System - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in products/classified/headersearch.php in 2daybiz Online Classified Script all
23RISK
open ↗Exploit-DB✓ VexDay Proof
Rosoft Audio Converter 4.4.4 - Local Buffer Overflow
Buffer overflow in Rosoft Audio Converter 4.4.4 allows remote attackers to execute arbitrary code via a long playlist en
23RISK
open ↗Exploit-DB
EZPX Photoblog 1.2 Beta - Remote File Inclusion
PHP remote file inclusion vulnerability in system/application/views/public/commentform.php in EZPX Photoblog 1.2 beta al
23RISK
open ↗Exploit-DB✓ VexDay Proof
2DayBiz ybiz Network Community Script - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in view_photo.php in 2daybiz Network Community Script allows remote attackers to execute arb
23RISK
open ↗Exploit-DB
Nakid CMS 0.5.2 - Remote File Inclusion
PHP remote file inclusion vulnerability in modules/catalog/upload_photo.php in Nakid CMS 0.5.2, when magic_quotes_gpc is
23RISK
open ↗Exploit-DB✓ VexDay Proof
2DayBiz Online Classified System - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in view_photo.php in 2daybiz Online Classified Script allows remote attackers to execute arb
23RISK
open ↗Exploit-DB✓ VexDay Proof
RealPlayer - 'rmoc3260.dll' ActiveX Control Heap Corruption (Metasploit)
The RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll in RealNetworks RealPlayer Enterprise, RealPlayer 10, Rea
50RISK
open ↗Exploit-DB✓ VexDay Proof
EnjoySAP SAP GUI - ActiveX Control Buffer Overflow (Metasploit)
Stack-based buffer overflow in the kweditcontrol.kwedit.1 ActiveX control in FrontEnd\SapGui\kwedit.dll in the EnjoySAP
50RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe - JBIG2Decode Memory Corruption (Metasploit) (1)
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitra
60RISK
open ↗Exploit-DB✓ VexDay Proof
Mercury/32 < 4.01b - PH Server Module Buffer Overflow (Metasploit)
Buffer overflow in Mercury Mail Transport System 4.01b allows remote attackers to execute arbitrary code via a long requ
50RISK
open ↗Exploit-DB✓ VexDay Proof
CA BrightStor ARCserve Backup - 'AddColumn()' ActiveX Buffer Overflow (Metasploit)
Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including Br
50RISK
open ↗Exploit-DB✓ VexDay Proof
Quick TFTP Server Pro 2.1 - Transfer-Mode Overflow (Metasploit)
Stack-based buffer overflow in TallSoft Quick TFTP Server Pro 2.1 allows remote attackers to cause a denial of service o
50RISK
open ↗Exploit-DB✓ VexDay Proof
Alt-N MDaemon 9.6.4 - IMAPD FETCH Buffer Overflow (Metasploit)
Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to
50RISK
open ↗Exploit-DB✓ VexDay Proof
CUPS 1.4.2 - Web Interface Information Disclosure
The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X
23RISK
open ↗Exploit-DB✓ VexDay Proof
Smart ASP Survey - Cross-Site Scripting / SQL Injection
Cross-site scripting (XSS) vulnerability in poll/default.asp in Smart ASP Survey allows remote attackers to inject arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
PuTTy.exe 0.53 - Remote Buffer Overflow (Metasploit)
Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 5.0 - IDQ Path Overflow (MS01-033) (Metasploit)
Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier a
60RISK
open ↗Exploit-DB✓ VexDay Proof
File Sharing Wizard 1.5.0 - Buffer Overflow (PoC)
Stack-based buffer overflow in iSharer File Sharing Wizard 1.5.0 allows remote attackers to cause a denial of service (c
28RISK
open ↗Exploit-DB✓ VexDay Proof
MailEnable - IMAPD W3C Logging Buffer Overflow (Metasploit)
Buffer overflow in the W3C logging for MailEnable Enterprise 1.1 and Professional 1.6 allows remote attackers to execute
50RISK
open ↗Exploit-DB✓ VexDay Proof
Yahoo! Messenger 8.1.0.249 - ActiveX Control Buffer Overflow (Metasploit)
Buffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.