Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,524cataloged exploits
37,962CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,284GitHub PoC 15,675VulnCheck XDB 9,136Nuclei 4,441Metasploit 3,506✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
Vixie Cron crontab 3.0 - Privilege Lowering Failure (2)
crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification ope
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cobalt Raq3 PopRelayD - Arbitrary SMTP Relay
poprelayd script before 2.0 in Cobalt RaQ3 servers allows remote attackers to bypass authentication for relaying by caus
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - Device File Local Denial of Service
Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial o
45RISK
open ↗Exploit-DB✓ VexDay Proof
Lmail 2.7 - Temporary File Race Condition
Lmail 2.7 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - Device File Remote Denial of Service
Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial o
45RISK
open ↗Exploit-DB✓ VexDay Proof
Citrix Nfuse 1.51 - Webroot Disclosure
Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Xvt 2.1 - Local Buffer Overflow
Buffer overflow in Xvt 2.1 in Debian Linux 2.2 allows local users to execute arbitrary code via long (1) -name and (2) -
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP 4.x - SafeMode Arbitrary File Execution
PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows lo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Active Classifieds 1.0 - Arbitrary Code Execution
admin.cgi in Active Classifieds Free Edition 1.0, and possibly commercial versions, allows remote attackers to modify th
23RISK
open ↗Exploit-DB✓ VexDay Proof
Xinetd 2.1.8 - Remote Buffer Overflow
Buffer overflow in Linux xinetd 2.1.8.9pre11-1 and earlier may allow remote attackers to execute arbitrary code via a lo
28RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco IOS 11.x/12.x - HTTP Configuration Arbitrary Administrative Access (1)
HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when lo
50RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco IOS 11.x/12.x - HTTP Configuration Arbitrary Administrative Access (4)
HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when lo
50RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco IOS 11.x/12.x - HTTP Configuration Arbitrary Administrative Access (2)
HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when lo
50RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris 8 libsldap - Local Buffer Overflow (2)
Buffer overflow in the LDAP naming services library (libsldap) in Sun Solaris 8 allows local users to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris 8 libsldap - Local Buffer Overflow (1)
Buffer overflow in the LDAP naming services library (libsldap) in Sun Solaris 8 allows local users to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10 - nidump Password File Disclosure
nidump on MacOS X before 10.3 allows local users to read the encrypted passwords from the password file by specifying pa
23RISK
open ↗Exploit-DB✓ VexDay Proof
Icecast 1.1.x/1.3.x - Directory Traversal
Directory traversal vulnerability in Icecast 1.3.10 and earlier allows remote attackers to read arbitrary files via a mo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Icecast 1.1.x/1.3.x - Slash File Name Denial of Service
Icecast 1.3.7, and other versions before 1.3.11 with HTTP server file streaming support enabled allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
XFree86 X11R6 3.3 XDM - Session Cookie Guessing
XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth
23RISK
open ↗Exploit-DB✓ VexDay Proof
Samba 2.0.x/2.2 - Arbitrary File Creation
Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remot
28RISK
open ↗Exploit-DB✓ VexDay Proof
GNU groff 1.1x - xploitation Via LPD
Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote att
28RISK
open ↗Exploit-DB✓ VexDay Proof
teTeX 1.0.7 - Filters Temporary File Race Condition
teTeX filter before 1.0.7 allows local users to gain privileges via a symlink attack on temporary files that are produce
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Visual Studio RAD Support - Remote Buffer Overflow
Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attack
28RISK
open ↗Exploit-DB✓ VexDay Proof
Cerberus FTP Server 1.x - Buffer Overflow (Denial of Service) (PoC)
Cerberus FTP 1.5 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code,
23RISK
open ↗Exploit-DB✓ VexDay Proof
1C: Arcadia Internet Store 1.0 - Arbitrary File Disclosure
Directory traversal vulnerability in tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to read arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
1C: Arcadia Internet Store 1.0 - Path Disclosure
tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to discover the full path to the working directory v
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sun SunVTS 4.x - PTExec Buffer Overflow
Buffer overflow in ptexec in the Sun Validation Test Suite 4.3 and earlier allows a local user to gain privileges via a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Visual Studio RAD Support - Remote Buffer Overflow (MS03-051) (Metasploit)
Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attack
28RISK
open ↗Exploit-DB✓ VexDay Proof
cfingerd 1.4.1/1.4.2/1.4.3 Utilities - Local Buffer Overflow (1)
Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
eXtremail 1.x/2.1 - Remote Format String (2)
Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privile
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.