Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,453cataloged exploits
37,908CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,237GitHub PoC 15,653VulnCheck XDB 9,134Nuclei 4,441Metasploit 3,506✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
CDRDAO 1.1.x - Home Directory Configuration File Symbolic Link (1)
CDRDAO 1.1.4 and 1.1.5 allows local users to overwrite arbitrary files via a symlink attack on the $HOME/.cdrdao configu
23RISK
open ↗Exploit-DB✓ VexDay Proof
CDRDAO 1.1.x - Home Directory Configuration File Symbolic Link (4)
CDRDAO 1.1.4 and 1.1.5 allows local users to overwrite arbitrary files via a symlink attack on the $HOME/.cdrdao configu
23RISK
open ↗Exploit-DB✓ VexDay Proof
CDRDAO 1.1.x - Home Directory Configuration File Symbolic Link (3)
CDRDAO 1.1.4 and 1.1.5 allows local users to overwrite arbitrary files via a symlink attack on the $HOME/.cdrdao configu
23RISK
open ↗Exploit-DB✓ VexDay Proof
CDRDAO 1.1.x - Home Directory Configuration File Symbolic Link (2)
CDRDAO 1.1.4 and 1.1.5 allows local users to overwrite arbitrary files via a symlink attack on the $HOME/.cdrdao configu
23RISK
open ↗Exploit-DB✓ VexDay Proof
IMLib2 - Home Environment Variable Buffer Overflow
Buffer overflow in Eterm of Enlightenment Imlib2 1.0.4 and earlier allows local users to execute arbitrary code via a lo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Snort 1.8.3 - ICMP Denial of Service
Snort 1.8.3 does not properly define the minimum ICMP header size, which allows remote attackers to cause a denial of se
23RISK
open ↗Exploit-DB✓ VexDay Proof
EServ 2.9x - Password-Protected File Access
Etype Eserv 2.97 allows remote attackers to view password protected files via /./ in the URL.
23RISK
open ↗Exploit-DB✓ VexDay Proof
YaBB 9.1.2000 - Cross-Agent Scripting
Cross-site scripting vulnerability in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 and earlier allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
X-Chat 1.x - CTCP Ping Remote IRC Command Execution
XChat 1.8.7 and earlier, including default configurations of 1.4.2 and 1.4.3, allows remote attackers to execute arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ultimate Bulletin Board 5.4/6.0/6.2 - Cross-Agent Scripting
Cross-site scripting vulnerability in Infopop Ultimate Bulletin Board (UBB) 6.2.0 Beta Release 1.0 allows remote attacke
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cacheflow CacheOS 3.1/4.0 Web Administration - Arbitrary Cached Page Code Leakage
Web administration interface in CacheFlow CacheOS 4.0.13 and earlier allows remote attackers to obtain sensitive informa
23RISK
open ↗Exploit-DB✓ VexDay Proof
Boozt 0.9.8 - Remote Buffer Overflow
Buffer overflow in index.cgi administration interface for Boozt! Standard 0.9.8 allows local users to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Nuke AddOn PHPToNuke.php 1.0 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in phptonuke.php for PHP-Nuke allows remote attackers to inject arbitrary web s
23RISK
open ↗Exploit-DB✓ VexDay Proof
RealPlayer 7.0/8.0 - Media File Buffer Overflow
Buffer overflow in Real Networks RealPlayer 8.0 and earlier allows remote attackers to execute arbitrary code via a head
23RISK
open ↗Exploit-DB✓ VexDay Proof
BrowseFTP Client 1.62 - Remote Buffer Overflow
Buffer overflow in BrowseFTP 1.62 client allows remote FTP servers to execute arbitrary code via a long FTP "220" messag
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache 1.3.20 (Win32) - 'PHP.exe' Remote File Disclosure
PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arb
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5 - JavaScript Local File Enumeration (1)
Internet Explorer 5.0, 5.0.1 and 5.5 with JavaScript execution enabled allows remote attackers to determine the existenc
28RISK
open ↗Exploit-DB✓ VexDay Proof
Net-SNMP 4.2.3 - snmpnetstat Remote Heap Overflow
Heap-based buffer overflow in snmpnetstat for ucd-snmp 4.2.3 and earlier, and net-snmp, allows remote attackers to execu
23RISK
open ↗Exploit-DB✓ VexDay Proof
BSCW 3.4/4.0 - Insecure Default Installation
The default configuration of BSCW (Basic Support for Cooperative Work) 3.x and possibly version 4 enables user self regi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5 - JavaScript Local File Enumeration (2)
Internet Explorer 5.0, 5.0.1 and 5.5 with JavaScript execution enabled allows remote attackers to determine the existenc
28RISK
open ↗Exploit-DB✓ VexDay Proof
WikkiTikkiTavi 0.x - Remote File Inclusion
PHP remote file inclusion vulnerability in WikkiTikkiTavi before 0.21 allows remote attackers to execute arbitrary PHP c
23RISK
open ↗Exploit-DB✓ VexDay Proof
AOL Instant Messenger 4.x - Remote Buffer Overflow
Buffer overflow in AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, and other versions allows remote attackers to execute
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5/6 - GetObject File Disclosure
Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObj
35RISK
open ↗Exploit-DB✓ VexDay Proof
rsync 2.5.1 - Remote (1)
Multiple signedness errors (mixed signed and unsigned numbers) in the I/O functions of rsync 2.4.6, 2.3.2, and other ver
35RISK
open ↗Exploit-DB✓ VexDay Proof
rsync 2.5.1 - Remote (2)
Multiple signedness errors (mixed signed and unsigned numbers) in the I/O functions of rsync 2.4.6, 2.3.2, and other ver
35RISK
open ↗Exploit-DB✓ VexDay Proof
OpenBSD - 'ftp' Local Overflow
FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings tha
35RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris 2/7/8/9 cachefsd - Remote Heap Overflow
Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code
28RISK
open ↗Exploit-DB✓ VexDay Proof
Abe Timmerman - 'zml.cgi' File Disclosure
Directory traversal vulnerability in zml.cgi allows remote attackers to read arbitrary files via a .. (dot dot) in the f
23RISK
open ↗Exploit-DB✓ VexDay Proof
DeleGate 7.7.1 - Cross-Site Scripting
Cross-site scripting vulnerability in DeleGate 7.7.0 and 7.7.1 does not quote scripting commands within a "403 Forbidden
23RISK
open ↗Exploit-DB✓ VexDay Proof
STunnel 3.x - Client Negotiation Protocol Format String
Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows re
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.