Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,643cataloged exploits
38,069CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,380GitHub PoC 15,693VulnCheck XDB 9,136Nuclei 4,445Metasploit 3,507✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
L-Soft Listserv 1.8 - Web Archives Buffer Overflow
Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary comman
23RISK
open ↗Exploit-DB✓ VexDay Proof
SuSE Linux 6.3/6.4 Gnomelib - Local Buffer Overflow
Buffer overflow in Gnomelib in SuSE Linux 6.3 allows local users to execute arbitrary commands via the DISPLAY environme
23RISK
open ↗Exploit-DB✓ VexDay Proof
Qualcomm Eudora 4.2/4.3 - Warning Message Circumvention
Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by
23RISK
open ↗Exploit-DB✓ VexDay Proof
Qualcomm Eudora 4.2/4.3 - Warning Message Circumvention
Qualcomm Eudora 5.2.1 allows remote attackers to read arbitrary files via an email message with a carriage return (CR) c
23RISK
open ↗Exploit-DB✓ VexDay Proof
McMurtrey/Whitaker & Associates Cart32 2.6/3.0 - Remote Administration Password
A backdoor password in Cart32 3.0 and earlier allows remote attackers to execute arbitrary commands.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco IOS 11.x/12.x - HTTP %%
The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a deni
50RISK
open ↗Exploit-DB✓ VexDay Proof
Symantec pcAnywhere 8.0.1/8.0.2/9.0/9.2 - Port Scan Denial of Service
pcAnywhere 8.x and 9.0 allows remote attackers to cause a denial of service via a TCP SYN scan, e.g. by nmap.
23RISK
open ↗Exploit-DB✓ VexDay Proof
RedHat 6.2 Piranha Virtual Server Package - Default Account and Password
The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password tha
60RISK
open ↗Exploit-DB✓ VexDay Proof
Zone Labs ZoneAlarm 2.1 Personal Firewall - Port 67
ZoneAlarm 2.1.10 and earlier does not filter UDP packets with a source port of 67, which allows remote attackers to bypa
23RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris 2.6/7.0 - 'lpset -r' Local Buffer Overflow (3)
Buffer overflow in Solaris 7 lpset allows local users to gain root privileges via a long -r option.
23RISK
open ↗Exploit-DB✓ VexDay Proof
3R Soft MailStudio 2000 2.0 - 'userreg.cgi' Arbitrary Command Execution
userreg.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to execute arbitrary commands via she
23RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris 7.0/8 - Xsun Buffer Overrun
Buffer overflow in Xsun X server in Solaris 7 allows local users to gain root privileges via a long -dev parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris 2.6/7.0 - 'lpset -r' Local Buffer Overflow (2)
Buffer overflow in Solaris 7 lpset allows local users to gain root privileges via a long -r option.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris 2.6/7.0 - 'lpset -r' Local Buffer Overflow (1)
Buffer overflow in Solaris 7 lpset allows local users to gain root privileges via a long -r option.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris 2.6/7.0 - lp -d Option Buffer Overflow
Buffer overflow in Solaris 7 lp allows local users to gain root privileges via a long -d option.
23RISK
open ↗Exploit-DB✓ VexDay Proof
CVS 1.10.7 - Local Denial of Service
Concurrent Versions Software (CVS) uses predictable temporary file names for locking, which allows local users to cause
23RISK
open ↗Exploit-DB✓ VexDay Proof
LCDProc 0.4 - Remote Buffer Overflow
Buffer overflow in LCDproc allows remote attackers to gain root privileges via the screen_add command.
23RISK
open ↗Exploit-DB✓ VexDay Proof
PostgreSQL 6.3.2/6.5.3 - Cleartext Passwords
PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with suff
23RISK
open ↗Exploit-DB✓ VexDay Proof
OpenLDAP 1.2.7/1.2.8/1.2.9/1.2.10 - '/usr/tmp/' Symlink
Linux OpenLDAP server allows local users to modify arbitrary files via a symlink attack.
23RISK
open ↗Exploit-DB✓ VexDay Proof
SuSE Linux 6.x - Arbitrary File Deletion
aaa_base in SuSE Linux 6.3, and cron.daily in earlier versions, allow local users to delete arbitrary files by creating
23RISK
open ↗Exploit-DB✓ VexDay Proof
RealNetworks Real Server 7.0 / GameHouse dldisplay ActiveX control 0 - Denial of Service
RealNetworks RealServer allows remote attackers to cause a denial of service by sending malformed input to the server at
28RISK
open ↗Exploit-DB✓ VexDay Proof
Novell Netware 5.1 - Remote Administration Buffer Overflow
Buffer overflow in the NetWare remote web administration utility allows remote attackers to cause a denial of service or
23RISK
open ↗Exploit-DB✓ VexDay Proof
FrontPage 97/98 - Server Image Mapper Buffer Overflow
Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activi
28RISK
open ↗Exploit-DB✓ VexDay Proof
Qualcomm qpopper 2.53/3.0 / RedHat imap 4.5 -4 / UoW imap 4.5 popd - Lock File Denial of Service
qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for
23RISK
open ↗Exploit-DB✓ VexDay Proof
Panda Security 3.0 - Multiple Vulnerabilities
Panda Security 3.0 with registry editing disabled allows users to edit the registry and gain privileges by directly exec
23RISK
open ↗Exploit-DB✓ VexDay Proof
University of Washington - imap LSUB Buffer Overflow (Metasploit)
Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via
50RISK
open ↗Exploit-DB✓ VexDay Proof
RedHat Linux 6.x - X Font Server Buffer Overflow (Denial of Service)
The X font server xfs in Red Hat Linux 6.x allows an attacker to cause a denial of service via a malformed request.
23RISK
open ↗Exploit-DB✓ VexDay Proof
UoW IMAPd Server 10.234/12.264 - LSUB Buffer Overflow (Metasploit)
Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via
50RISK
open ↗Exploit-DB✓ VexDay Proof
UoW IMAPd Serve 10.234/12.264 - COPY Buffer Overflow (Metasploit)
Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via
50RISK
open ↗Exploit-DB✓ VexDay Proof
RedHat Linux 6.x - X Font Server Buffer Overflow (Denial of Service)
X fontserver xfs allows local users to cause a denial of service via malformed input to the server.
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.