Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,521cataloged exploits
37,961CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,284GitHub PoC 15,672VulnCheck XDB 9,136Nuclei 4,441Metasploit 3,506✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5 - Zone Spoofing (MS01-055)
Internet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via malformed URLs that contain d
28RISK
open ↗Exploit-DB✓ VexDay Proof
Progress Database 8.3/9.1 - Multiple Buffer Overflows
Buffer overflow in Progress database 8.3D and 9.1C could allow a local user to execute arbitrary code via (1) _proapsv,
23RISK
open ↗Exploit-DB✓ VexDay Proof
Amtote Homebet - Account Information Brute Force
AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are pro
23RISK
open ↗Exploit-DB✓ VexDay Proof
AmTote Homebet - World Accessible Log
AmTote International homebet program stores the homebet.log file in the homebet/ virtual directory, which allows remote
23RISK
open ↗Exploit-DB✓ VexDay Proof
3Com OfficeConnect DSL Router 812 1.1.7/840 1.1.7 - HTTP Port Router Denial of Service
3COM OfficeConnect 812 and 840 ADSL Router 4.2, running OCR812 router software 1.1.9 and earlier, allows remote attacker
23RISK
open ↗Exploit-DB✓ VexDay Proof
FreeBSD 4.3/4.4 - Login Capabilities Privileged File Reading
libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Index Server 2.0 - File Information / Full Path Disclosure
SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as th
35RISK
open ↗Exploit-DB✓ VexDay Proof
Stalker Internet Mail Server 1.6 - Remote Buffer Overflow
Stalker Internet Mail Server 1.6 allows a remote attacker to cause a denial of service (crash) via a long HELO command.
23RISK
open ↗Exploit-DB✓ VexDay Proof
EFTP Server 2.0.7.337 - Directory Existence / File Existence
Directory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a
23RISK
open ↗Exploit-DB✓ VexDay Proof
EFTP 2.0.7 337 - Remote Buffer Overflow Code Execution / Denial of Service
Buffer overflow in EFTP 2.0.7.337 allows remote attackers to execute arbitrary code by uploading a .lnk file containing
28RISK
open ↗Exploit-DB✓ VexDay Proof
RedHat Linux 7.0 Apache - Remote Username Enumeration
Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists a
50RISK
open ↗Exploit-DB✓ VexDay Proof
CGIEmail 1.6 - Remote Buffer Overflow
Buffer overflow in cgicso.c for cgiemail 1.6 allows remote attackers to cause a denial of service (crash) and possibly e
23RISK
open ↗Exploit-DB✓ VexDay Proof
SpeechD 0.1/0.2 - Privileged Command Execution
speechd 0.54 and earlier, with the Festival or rsynth speech synthesis package, allows attackers to execute arbitrary co
23RISK
open ↗Exploit-DB✓ VexDay Proof
Digital Unix 4.0 - MSGCHK MH_PROFILE Symbolic Link
msgchk in Digital UNIX 4.0G and earlier allows a local user to read the first line of arbitrary files via a symlink atta
23RISK
open ↗Exploit-DB✓ VexDay Proof
Hassan Consulting Shopping Cart 1.23 - Arbitrary Command Execution
shop.pl in Hassan Consulting Shopping Cart 1.23 allows remote attackers to execute arbitrary commands via shell metachar
23RISK
open ↗Exploit-DB✓ VexDay Proof
Taylor UUCP 1.0.6 - Argument Handling Privilege Escalation
uuxqt in Taylor UUCP package does not properly remove dangerous long options, which allows local users to gain privilege
23RISK
open ↗Exploit-DB✓ VexDay Proof
Merit AAA RADIUS Server 3.8 - rlmadmin Symbolic Link
rlmadmin RADIUS management utility in Merit AAA Server 3.8M, 5.01, and possibly other versions, allows local users to re
23RISK
open ↗Exploit-DB✓ VexDay Proof
Power Up HTML 0.8033 Beta - Directory Traversal Arbitrary File Disclosure
Directory traversal vulnerability in r.pl (aka r.cgi) of Randy Parker Power Up HTML 0.8033beta allows remote attackers t
28RISK
open ↗Exploit-DB✓ VexDay Proof
AOLServer 3 - 'Authentication String' Remote Buffer Overflow (2)
Buffer overflow in AOLserver 3.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary co
28RISK
open ↗Exploit-DB✓ VexDay Proof
Digital Unix 4.0 - MSGCHK Buffer Overflow
Buffer overflow in msgchk in Digital UNIX 4.0G and earlier allows local users to execute arbitrary code via a long comma
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco Secure IDS 2.0/3.0 / Snort 1.x / ISS RealSecure 5/6 / NFR 5.0 - Encoded IIS Detection Evasion
Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000
23RISK
open ↗Exploit-DB✓ VexDay Proof
HP-UX 11.0 - SWVerify Buffer Overflow
Buffer overflow in swverify in HP-UX 11.0, and possibly other programs, allows local users to gain privileges via a long
23RISK
open ↗Exploit-DB✓ VexDay Proof
Irix LPD tagprinter - Command Execution (Metasploit)
lpsched in IRIX 6.5.13f and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.
50RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris 8.0 LPD - Command Execution (Metasploit)
lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request wit
60RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris 2.x/7.0/8 LPD - Remote Command Execution
lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request wit
60RISK
open ↗Exploit-DB✓ VexDay Proof
SIX-webboard 2.01 - File Retrieval
generate.cgi in SIX-webboard 2.01 and before allows remote attackers to read arbitrary files via a dot dot (..) in the c
23RISK
open ↗Exploit-DB✓ VexDay Proof
RedHat 6.2/7.0/7.1 Lpd - Remote Command Execution via DVI Printfilter Configuration Error
The default configuration of the DVI print filter (dvips) in Red Hat Linux 7.0 and earlier does not run dvips in secure
23RISK
open ↗Exploit-DB✓ VexDay Proof
UltraEdit 8.2 - FTP Client Weak Password Encryption
UltraEdit uses weak encryption to record FTP passwords in the uedit32.ini file, which allows local users who can read th
23RISK
open ↗Exploit-DB✓ VexDay Proof
Respondus for WebCT 1.1.2 - Weak Password Encryption
Respondus 1.1.2 for WebCT uses weak encryption to remember usernames and passwords, which allows local users who can rea
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco CBOS 2.x - Multiple TCP Connection Denial of Service Vulnerabilities
Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via mul
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.