Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,524cataloged exploits
37,962CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,284GitHub PoC 15,675VulnCheck XDB 9,136Nuclei 4,441Metasploit 3,506✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
Juergen Weigert screen 3.9 - User Supplied Format String
Format string vulnerability in screen 3.9.5 and earlier allows local users to gain root privileges via format characters
23RISK
open ↗Exploit-DB✓ VexDay Proof
Immunix OS 6.2 - LC glibc format string
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which
28RISK
open ↗Exploit-DB✓ VexDay Proof
Libc locale - Local Privilege Escalation (1)
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which
28RISK
open ↗Exploit-DB✓ VexDay Proof
Libc locale - Local Privilege Escalation (2)
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which
28RISK
open ↗Exploit-DB✓ VexDay Proof
AIX 4.2/4.3 - netstat -Z Statistic Clearing
netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network inte
23RISK
open ↗Exploit-DB✓ VexDay Proof
QSSL Voyager 2.0 1B - Arbitrary File Access
Directory traversal vulnerability in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to r
23RISK
open ↗Exploit-DB✓ VexDay Proof
QSSL Voyager 2.0 1B - '.photon' Directory Information Disclosure
Voyager web server 2.01B in the demo disks for QNX 405 stores sensitive web client information in the .photon directory
23RISK
open ↗Exploit-DB✓ VexDay Proof
eEye Digital Security IRIS 1.0.1 / SpyNet CaptureNet 3.0.12 - Remote Buffer Overflow
eEye IRIS 1.01 beta allows remote attackers to cause a denial of service via a large number of UDP connections.
23RISK
open ↗Exploit-DB✓ VexDay Proof
GNOME esound 0.2.19 - Unix Domain Socket Race Condition
Race condition in the creation of a Unix domain socket in GNOME esound 0.2.19 and earlier allows a local user to change
23RISK
open ↗Exploit-DB✓ VexDay Proof
CGI Script Center Auction Weaver 1.0.2 - Remote Command Execution
Auction Weaver CGI script 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacter
28RISK
open ↗Exploit-DB✓ VexDay Proof
Ipswitch IMail 6.x - File Attachment
The web server in IPSWITCH IMail 6.04 and earlier allows remote attackers to read and delete arbitrary files via a .. (d
23RISK
open ↗Exploit-DB✓ VexDay Proof
GWScripts News Publisher 1.0 - 'author.file' Write
news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which
23RISK
open ↗Exploit-DB✓ VexDay Proof
RobTex Viking Server 1.0.6 Build 355 - Remote Buffer Overflow
Buffer overflow in RobTex Viking server earlier than 1.06-370 allows remote attackers to cause a denial of service or ex
23RISK
open ↗Exploit-DB✓ VexDay Proof
Gert Doering mgetty 1.1.19/1.1.20/1.1.21/1.22.8 - Symbolic Link Traversal
The faxrunq and faxrunqd in the mgetty package allows local users to create or modify arbitrary files via a symlink atta
23RISK
open ↗Exploit-DB✓ VexDay Proof
User-Mode Linux (Linux Kernel 2.4.17-8) - Memory Access Privilege Escalation
User-mode Linux (UML) 2.4.17-8 does not restrict access to kernel address space, which allows local users to execute arb
23RISK
open ↗Exploit-DB✓ VexDay Proof
PragmaSys TelnetServer 2000 - rexec Buffer Overflow
Buffer overflow in Pragma Systems TelnetServer 2000 version 4.0 allows remote attackers to cause a denial of service via
23RISK
open ↗Exploit-DB✓ VexDay Proof
PragmaSys TelnetServer 2000 - rexec Buffer Overflow
POP3 daemon in Stalker CommuniGate Pro 3.3.2 generates different error messages for invalid usernames versus invalid pas
23RISK
open ↗Exploit-DB✓ VexDay Proof
CGI Script Center Account Manager 1.0 LITE / PRO - Administrative Password Alteration (2)
Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote a
23RISK
open ↗Exploit-DB✓ VexDay Proof
CGI Script Center Subscribe Me Lite 2.0 - Administrative Password Alteration (2)
Subscribe Me LITE does not properly authenticate attempts to change the administrator password, which allows remote atta
23RISK
open ↗Exploit-DB✓ VexDay Proof
CGI Script Center Account Manager 1.0 LITE / PRO - Administrative Password Alteration (1)
Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote a
23RISK
open ↗Exploit-DB✓ VexDay Proof
CGI Script Center Subscribe Me Lite 2.0 - Administrative Password Alteration (1)
Subscribe Me LITE does not properly authenticate attempts to change the administrator password, which allows remote atta
23RISK
open ↗Exploit-DB✓ VexDay Proof
HP-UX 11.0 - net.init RC Script
The net.init rc script in HP-UX 11.00 (S008net.init) allows local users to overwrite arbitrary files via a symlink attac
23RISK
open ↗Exploit-DB✓ VexDay Proof
Darxite 0.4 - Login Buffer Overflow
Buffer overflow in Darxite 0.4 and earlier allows a remote attacker to execute arbitrary commands via a long username or
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 1.0/2.5 - Administrative Privileges
admin.php3 in PHP-Nuke does not properly verify the PHP-Nuke administrator password, which allows remote attackers to ga
28RISK
open ↗Exploit-DB✓ VexDay Proof
UMN Gopherd 2.x - Halidate Function Buffer Overflow
Buffer overflow in University of Minnesota (UMN) gopherd 2.x allows remote attackers to execute arbitrary commands via a
28RISK
open ↗Exploit-DB✓ VexDay Proof
vqSoft vqServer 1.4.49 - Denial of Service
Buffer overflow in vqSoft vqServer 1.4.49 allows remote attackers to cause a denial of service or possibly gain privileg
23RISK
open ↗Exploit-DB✓ VexDay Proof
Minicom 1.82/1.83 - Capture-file Group Ownership
Minicom 1.82.1 and earlier on some Linux systems allows local users to create arbitrary files owned by the uucp user via
23RISK
open ↗Exploit-DB✓ VexDay Proof
X-Chat 1.2/1.3/1.4/1.5 - Command Execution via URLs
IRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell meta
23RISK
open ↗Exploit-DB✓ VexDay Proof
netwin netauth 4.2 - Directory Traversal
netauth.cgi program in Netwin Netauth 4.2e and earlier allows remote attackers to read arbitrary files via a .. (dot dot
23RISK
open ↗Exploit-DB✓ VexDay Proof
David Bagley xlock 4.16 - User Supplied Format String (1)
xlockmore and xlockf do not properly cleanse user-injected format strings, which allows local users to gain root privile
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.