Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,524cataloged exploits
37,962CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,284GitHub PoC 15,675VulnCheck XDB 9,136Nuclei 4,441Metasploit 3,506✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
OReilly Software WebSite Professional 2.5.4 - Path Disclosure
O'Reilly Website Professional 2.5.4 and earlier allows remote attackers to determine the physical path to the root direc
23RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris 2.6/7.0/8 - snmpXdmid Buffer Overflow (Metasploit)
Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via
45RISK
open ↗Exploit-DB✓ VexDay Proof
WU-FTPD 2.4/2.5/2.6 / Trolltech ftpd 1.2 / ProFTPd 1.2 / BeroFTPD 1.3.4 FTP - glob Expansion
The glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of servic
35RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris 2.6/7.0/8 - snmpXdmid Buffer Overflow
Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via
45RISK
open ↗Exploit-DB✓ VexDay Proof
FTPFS 0.1.1/0.2.1/0.2.2 - mount Buffer Overflow
Buffer overflow in FTPFS allows local users to gain root privileges via a long user name.
23RISK
open ↗Exploit-DB✓ VexDay Proof
IkonBoard 2.1.7b - Remote File Disclosure
Directory traversal vulnerability in help.cgi in Ikonboard 2.1.7b and earlier allows a remote attacker to read arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
Free Online Dictionary of Computing 1.0 - Remote File Viewing
template.cgi in Free On-Line Dictionary of Computing (FOLDOC) allows remote attackers to read files and execute commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1/5.5/6.0 - Telnet Client File Overwrite
Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web si
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 5.0 - WebDAV Denial of Service
IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests.
35RISK
open ↗Exploit-DB✓ VexDay Proof
Rob Malda ASCDC 0.3 - Local Buffer Overflow (1)
Buffer overflows in ascdc Afterstep while running setuid allows local users to gain root privileges via a long (1) -d op
23RISK
open ↗Exploit-DB✓ VexDay Proof
Rob Malda ASCDC 0.3 - Local Buffer Overflow (2)
Buffer overflows in ascdc Afterstep while running setuid allows local users to gain root privileges via a long (1) -d op
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco IOS 11.x/12.x - HTTP Configuration Arbitrary Administrative Access (3)
HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when lo
50RISK
open ↗Exploit-DB✓ VexDay Proof
jarle aase war ftpd 1.67 b04 - Directory Traversal
Directory traversal vulnerability in War FTP 1.67.04 allows remote attackers to list directory contents and possibly rea
23RISK
open ↗Exploit-DB✓ VexDay Proof
GLIBC 2.1.3 - 'LD_PRELOAD' Local Privilege Escalation
When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libr
23RISK
open ↗Exploit-DB✓ VexDay Proof
sendtemp.pl - Read Access to Files
Directory traversal vulnerability in sendtemp.pl in W3.org Anaya Web development server allows remote attackers to read
23RISK
open ↗Exploit-DB✓ VexDay Proof
WhitSoft SlimServe HTTPd 1.0/1.1 - Directory Traversal
Directory traversal vulnerability in SlimServe HTTPd 1.1a allows remote attackers to read arbitrary files via a ... (mod
23RISK
open ↗Exploit-DB✓ VexDay Proof
IMAP4rev1 12.261/12.264/2000.284 - 'lsub' Remote Overflow
Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via
50RISK
open ↗Exploit-DB✓ VexDay Proof
FreeBSD 3.5.1/4.2 - Ports Package 'xklock' Local Privilege Escalation
Buffer overflow in ja-xklock 2.7.1 and earlier allows local users to gain root privileges.
23RISK
open ↗Exploit-DB✓ VexDay Proof
FreeBSD 3.5.1/4.2 - Ports Package 'elvrec' Local Privilege Escalation
Buffer overflow in ja-elvis and ko-helvis ports of elvis allow local users to gain root privileges.
23RISK
open ↗Exploit-DB✓ VexDay Proof
ISC BIND 8.2.x - 'TSIG' Remote Stack Overflow (4)
Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.
35RISK
open ↗Exploit-DB✓ VexDay Proof
SunFTP 1.0 Build 9 - Unauthorized File Access
Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) cha
23RISK
open ↗Exploit-DB✓ VexDay Proof
Tru64 UNIX 4.0g - '/usr/bin/at' Local Privilege Escalation
Buffer overflow in HP Tru64 UNIX allows local users to execute arbitrary code via a long argument to /usr/bin/at.
23RISK
open ↗Exploit-DB✓ VexDay Proof
ISC BIND 8.2.x - 'TSIG' Remote Stack Overflow (2)
Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.
35RISK
open ↗Exploit-DB✓ VexDay Proof
ISC BIND 8.2.x - 'TSIG' Remote Stack Overflow (1)
Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.
35RISK
open ↗Exploit-DB✓ VexDay Proof
Netwin SurgeFTP 1.0b - Denial of Service
NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command.
23RISK
open ↗Exploit-DB✓ VexDay Proof
ISC BIND 8.2.x - 'TSIG' Remote Stack Overflow (3)
Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.
35RISK
open ↗Exploit-DB✓ VexDay Proof
WhitSoft SlimServe HTTPd 1.1 - 'GET' Denial of Service
Buffer overflow in SlimServe HTTPd 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitr
28RISK
open ↗Exploit-DB✓ VexDay Proof
WhitSoft SlimServe ftpd 1.0/2.0 - Directory Traversal
Directory traversal vulnerability in SlimServe HTTPd 1.1a allows remote attackers to read arbitrary files via a ... (mod
23RISK
open ↗Exploit-DB✓ VexDay Proof
HP OpenView OmniBack II A.03.50 - Command Execution (Metasploit)
Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack c
43RISK
open ↗Exploit-DB✓ VexDay Proof
datawizards ftpxq 2.0.93 - Directory Traversal
Directory traversal vulnerability in FtpXQ FTP server 2.0.93 allows remote attackers to read arbitrary files via a .. (d
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.