Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,607cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 13,974VulnCheck XDB 8,571Nuclei 4,248Metasploit 3,472✓ verified onlyrecentpopularrisk
24,443 exploits
Exploit-DB✓ VexDay Proof
phpscripte24 Live Shopping Multi Portal System - SQL Injection
SQL injection vulnerability in index.php in Hi Web Wiesbaden Live Shopping Multi Portal System allows remote attackers t
23RISK
open ↗Exploit-DB✓ VexDay Proof
MySQL yaSSL (Windows) - SSL Hello Message Buffer Overflow (Metasploit)
Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attacke
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft RRAS Service - Remote Overflow (MS06-025) (Metasploit)
Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Serve
60RISK
open ↗Exploit-DB✓ VexDay Proof
Novell iPrint Client - ActiveX Control target-frame Buffer Overflow (Metasploit)
Stack-based buffer overflow in ienipp.ocx in Novell iPrint Client 5.30, and possibly other versions before 5.32, allows
50RISK
open ↗Exploit-DB✓ VexDay Proof
Alibaba Clone 3.0 (Special) - SQL Injection
SQL injection vulnerability in offers_buy.php in Alibaba Clone 3.0 allows remote attackers to execute arbitrary SQL comm
23RISK
open ↗Exploit-DB✓ VexDay Proof
iseemedia / Roxio / MGI Software LPViewer - ActiveX Control Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in MGI Software LPViewer ActiveX control (LPControl.dll), as acquired by Roxio and
43RISK
open ↗Exploit-DB✓ VexDay Proof
SonicWALL SSL-VPN - NetExtender ActiveX Control Buffer Overflow (Metasploit)
Stack-based buffer overflow in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x
50RISK
open ↗Exploit-DB✓ VexDay Proof
Novell NetMail 3.52d - IMAP Subscribe Buffer Overflow (Metasploit)
Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated u
50RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Workstation Service - NetAddAlternateComputerName Overflow (MS03-049) (Metasploit)
Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers t
60RISK
open ↗Exploit-DB✓ VexDay Proof
Kazaa Altnet Download Manager - ActiveX Control Buffer Overflow (Metasploit)
Stack-based buffer overflow in the ADM4 ActiveX control in adm4.dll in Altnet Download Manager 4.0.0.6, as used in (1) K
43RISK
open ↗Exploit-DB✓ VexDay Proof
Amaya Browser 11.0 - bdo tag Overflow (Metasploit)
Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 and 11.0 allow remote attackers to execute arbitrary
50RISK
open ↗Exploit-DB✓ VexDay Proof
IA WebMail Server 3.x - Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in IA WebMail Server 3.1.0 allows remote attackers to execute arbitrary code via a long GET
50RISK
open ↗Exploit-DB✓ VexDay Proof
CA BrightStor ARCserve - Tape Engine Buffer Overflow (Metasploit)
Buffer overflow in the Tape Engine (tapeeng.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 an
60RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Secure Backup - NDMP_CONNECT_CLIENT_AUTH Buffer Overflow (Metasploit)
Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers
50RISK
open ↗Exploit-DB✓ VexDay Proof
freeSSHd 1.0.9 - Key Exchange Algorithm String Buffer Overflow (Metasploit)
Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other produc
60RISK
open ↗Exploit-DB✓ VexDay Proof
CA BrightStor Discovery Service - Remote Stack Buffer Overflow (Metasploit)
Stack-based buffer overflow in the Discovery Service for BrightStor ARCserve Backup 11.1 and earlier allows remote attac
50RISK
open ↗Exploit-DB✓ VexDay Proof
Sentinel LM - UDP Buffer Overflow (Metasploit)
Buffer overflow in the Sentinel LM (Lservnt) service in the Sentinel License Manager 7.2.0.2 allows remote attackers to
60RISK
open ↗Exploit-DB✓ VexDay Proof
Creative Software AutoUpdate Engine - ActiveX Control Buffer Overflow (Metasploit)
Stack-based buffer overflow in the Creative Software AutoUpdate Engine ActiveX control in CTSUEng.ocx allows remote atta
50RISK
open ↗Exploit-DB✓ VexDay Proof
WinDVD7 - 'IASystemInfo.dll' ActiveX Control Buffer Overflow (Metasploit)
Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio Ci
50RISK
open ↗Exploit-DB✓ VexDay Proof
Orbit Downloader - Connecting Log Creation Buffer Overflow (Metasploit)
Stack-based buffer overflow in Orbit Downloader 2.8.2 and 2.8.3, and possibly other versions before 2.8.5, allows remote
50RISK
open ↗Exploit-DB✓ VexDay Proof
Web 2.0 Social Network Freunde Community System - 'user.php' SQL Injection
SQL injection vulnerability in user.php in Hi Web Wiesbaden Web 2.0 Social Network Freunde Community System allows remot
23RISK
open ↗Exploit-DB✓ VexDay Proof
TFTPGUI 1.4.5 - Long Transport Mode Overflow Denial of Service (Metasploit)
Buffer overflow in k23productions TFTPUtil GUI (aka TFTPGUI) 1.4.5 allows remote attackers to cause a denial of service
28RISK
open ↗Exploit-DB✓ VexDay Proof
Consona - 'n6plugindestructor.asp' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - SMB2 Negotiate Protocol '0x72' Response Denial of Service
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISK
open ↗Exploit-DB✓ VexDay Proof
gdomap - Multiple Local Information Disclosure Vulnerabilities
Tools/gdomap.c in gdomap in GNUstep Base before 1.20.0 allows local users to read arbitrary files via a (1) -c or (2) -a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Paint - Integer Overflow (Denial of Service) (MS10-005)
Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to
35RISK
open ↗Exploit-DB
OCS Inventory NG Server 1.3.1 - 'LOGIN' Remote Authentication Bypass
Multiple unspecified vulnerabilities in the Server component in OCS Inventory NG before 1.02 have unknown impact and att
23RISK
open ↗Exploit-DB✓ VexDay Proof
DeluxeBB 1.x - 'newpost.php' SQL Injection
SQL injection vulnerability in newpost.php in DeluxeBB 1.3 and earlier, when magic_quotes_gpc is disabled, allows remote
23RISK
open ↗Exploit-DB
PHP-Nuke 7.0/8.1/8.1.35 - Wormable Remote Code Execution
viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrase
60RISK
open ↗Exploit-DB✓ VexDay Proof
VMware View 3.1.x - URL Processing Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in VMware View (formerly Virtual Desktop Manager or VDM) 3.1.x before 3.1.3 bui
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.