Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,270cataloged exploits
37,818CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,178GitHub PoC 15,557VulnCheck XDB 9,108Nuclei 4,440Metasploit 3,505✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
IBM Informix Dynamic Server 9.40/Informix Extended Parallel Server 8.40 - Multiple Vulnerabilities (2)
Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, wit
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'RPC DCOM' Remote (Universal)
The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and loc
35RISK
open ↗Exploit-DB✓ VexDay Proof
man-db 2.4.1 - 'open_cat_stream()' Local uid=man
man-db 2.3.12 and 2.3.18 to 2.4.1 uses certain user-controlled DEFINE directives from the ~/.manpath file, even when run
23RISK
open ↗Exploit-DB✓ VexDay Proof
vBulletin 3.0 - 'register.php' HTML Injection
Cross-site scripting (XSS) vulnerability in register.php for vBulletin 3.0 Beta 2 allows remote attackers to inject arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
WU-FTPD 2.6.0/2.6.1/2.6.2 - 'realpath()' Off-by-One Buffer Overflow
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to exe
45RISK
open ↗Exploit-DB✓ VexDay Proof
IBM DB2 - Shared Library Injection
IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM DB2 db2job - File Overwrite
IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and g
23RISK
open ↗Exploit-DB✓ VexDay Proof
Postfix 1.1.x - Denial of Service (2)
The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1
28RISK
open ↗Exploit-DB✓ VexDay Proof
Postfix 1.1.x - Denial of Service (1)
The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1
28RISK
open ↗Exploit-DB✓ VexDay Proof
WU-FTPD 2.6.2 - Off-by-One Remote Command Execution
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to exe
45RISK
open ↗Exploit-DB✓ VexDay Proof
Symantec Norton AntiVirus 2002/2003 - Device Driver Memory Overwrite
The DeviceIoControl function in the Norton Device Driver (NAVAP.sys) in Symantec Norton AntiVirus 2002 allows local user
23RISK
open ↗Exploit-DB✓ VexDay Proof
WU-FTPD 2.6.2 - 'realpath()' Off-by-One Buffer Overflow
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to exe
45RISK
open ↗Exploit-DB✓ VexDay Proof
CDRTools 2.0 - RSCSI Debug File Arbitrary Local File Manipulation
rscsi in cdrtools 2.01 and earlier allows local users to overwrite arbitrary files and gain root privileges by specifyin
23RISK
open ↗Exploit-DB✓ VexDay Proof
xtokkaetama 1.0b (RedHat 9.0) - Local Game
Multiple buffer overflows in xtokkaetama 1.0 allow local users to gain privileges via a long (1) -display command line a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Trillian 0.74 - Remote Denial of Service
The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) by
28RISK
open ↗Exploit-DB✓ VexDay Proof
FreeBSD 4.8 - 'realpath()' Off-by-One Buffer Overflow
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to exe
45RISK
open ↗Exploit-DB✓ VexDay Proof
XGalaga 2.0.34 (RedHat 9.0) - Local Game
Multiple buffer overflows in xgalaga 2.0.34 and earlier allow local users to gain privileges via a long HOME environment
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'RPC DCOM' Remote (2)
The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and loc
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'RPC DCOM' Remote (1)
The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and loc
35RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.4.20 - 'decode_fh' Denial of Service
Integer signedness error in the decode_fh function of nfs3xdr.c in Linux kernel before 2.4.21 allows remote attackers to
28RISK
open ↗Exploit-DB✓ VexDay Proof
ManDB Utility 2.3/2.4 - Local Buffer Overflow
Multiple buffer overflows in man-db 2.4.1 and earlier, when installed setuid, allow local users to gain privileges via (
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco Aironet AP1x00 - GET Denial of Service
The web server for Cisco Aironet AP1x00 Series Wireless devices running certain versions of IOS 12.2 allow remote attack
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache 1.3.x mod_mylo - Remote Code Execution
Buffer overflow in the mylo_log logging function for mod_mylo 0.2.1 and earlier allows remote attackers to execute arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
Gallery 1.2/1.3.x - Search Engine Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.php of Gallery 1.1 through 1.3.4 allows remote attackers to insert ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000 - 'RPC DCOM' Remote (MS03-026)
The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and loc
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'RPC DCOM' Remote Buffer Overflow
The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and loc
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows SQL Server - Remote Denial of Service (MS03-031)
Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local P
23RISK
open ↗Exploit-DB✓ VexDay Proof
Novell Netware Enterprise Web Server 5.1/6.0 - 'CGI2Perl.NLM' Buffer Overflow (PoC)
Buffer overflow in the CGI2PERL.NLM PERL handler in Novell Netware 5.1 and 6.0 allows remote attackers to cause a denial
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft SQL Server 7.0/2000 / MSDE - Named Pipe Denial of Service (MS03-031)
Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or
35RISK
open ↗Exploit-DB✓ VexDay Proof
xfstt 1.2/1.4 - Memory Disclosure
Off-by-one error in certain versions of xfstt allows remote attackers to read potentially sensitive memory via a malform
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.