Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,689cataloged exploits
38,075CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,381GitHub PoC 15,712VulnCheck XDB 9,162Nuclei 4,445Metasploit 3,507✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
gpm 1.18.1/1.19 / Debian 2.x / RedHat 6.x / S.u.S.E 5.3/6.x - gpm Setgid
gpm-root in the gpm package does not properly drop privileges, which allows local users to gain privileges by starting a
23RISK
open ↗Exploit-DB✓ VexDay Proof
vqsoft vqserver for windows 1.9.9 - Directory Traversal
vqSoft vqServer program allows remote attackers to read arbitrary files via a /........../ in the URL, a variation of a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Netscape Enterprise Server 3.0/3.6/3.51 - Directory Indexing
Netscape Enterprise Server with Directory Indexing enabled allows remote attackers to list server directories via web pu
23RISK
open ↗Exploit-DB✓ VexDay Proof
Atrium Software Mercur WebView WebMail-Client 1.0 - Buffer Overflow
Buffer overflow in the MERCUR WebView WebMail server allows remote attackers to cause a denial of service via a long mai
23RISK
open ↗Exploit-DB✓ VexDay Proof
Halloween Linux 4.0 / SuSE Linux 6.0/6.1/6.2/6.3 - 'kreatecd' Local Privilege Escalation
Linux kreatecd trusts a user-supplied path that is used to find the cdrecord program, allowing local users to gain root
23RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Web Listener 4.0.x - for NT Batch File
Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL
28RISK
open ↗Exploit-DB✓ VexDay Proof
Mandrake 6.x / RedHat 6.x / Turbolinux 3.5 b2/4.x/6.0.2 userhelper/PAM - Path (2)
Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a .. (dot dot) att
23RISK
open ↗Exploit-DB✓ VexDay Proof
Generation Terrorists Designs & Concepts Sojourn 2.0 - File Access
Sojourn search engine allows remote attackers to read arbitrary files via a .. (dot dot) attack.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Atrium Software Mercur Mail Server 3.2 - Multiple Buffer Overflows (2)
Buffer overflow in POP3 and IMAP servers in the MERCUR mail server suite allows remote attackers to cause a denial of se
23RISK
open ↗Exploit-DB✓ VexDay Proof
Atrium Software Mercur Mail Server 3.2 - Multiple Buffer Overflows (1)
Buffer overflow in POP3 and IMAP servers in the MERCUR mail server suite allows remote attackers to cause a denial of se
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sam Hawker wmcdplay 1.0 beta1-2 - Local Buffer Overflow (2)
Buffer overflow in the wmcdplay CD player program for the WindowMaker desktop allows local users to gain root privileges
23RISK
open ↗Exploit-DB✓ VexDay Proof
Halloween Linux 4.0 / RedHat Linux 6.1/6.2 - 'imwheel' (1)
Buffer overflow in imwheel allows local users to gain root privileges via the imwheel-solo script and a long HOME enviro
23RISK
open ↗Exploit-DB✓ VexDay Proof
Halloween Linux 4.0 / RedHat Linux 6.1/6.2 - 'imwheel' (2)
Buffer overflow in imwheel allows local users to gain root privileges via the imwheel-solo script and a long HOME enviro
23RISK
open ↗Exploit-DB✓ VexDay Proof
AT Computing atsar_linux 1.4 - File Manipulation
atsadc in the atsar package for Linux does not properly check the permissions of an output file, which allows local user
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sam Hawker wmcdplay 1.0 beta1-2 - Local Buffer Overflow (1)
Buffer overflow in the wmcdplay CD player program for the WindowMaker desktop allows local users to gain root privileges
23RISK
open ↗Exploit-DB✓ VexDay Proof
Michael Sandrof IrcII 4.4-7 - Remote Buffer Overflow
Buffer overflow in ircII 4.4 IRC client allows remote attackers to execute commands via the DCC chat capability.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mirabilis ICQ 0.99/98.0 a/2000.0 A/99a - Remote Denial of Service
ICQ Web Front HTTPd allows remote attackers to cause a denial of service by requesting a URL that contains a "?" charact
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sun StarOffice 5.1 - Arbitrary File Read
StarOffice StarScheduler web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT 4.0 - User Shell Folders
The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify
23RISK
open ↗Exploit-DB✓ VexDay Proof
WorldView 6.5/Wnn4 4.2 - Asian Language Server Remote Buffer Overflow
Buffer overflow in SGI Omron WorldView Wnn allows remote attackers to execute arbitrary commands via long JS_OPEN, JS_MK
28RISK
open ↗Exploit-DB✓ VexDay Proof
GameHouse dldisplay - ActiveX control 0 / Real Server 5.0/7.0 Internal IP Address Disclosure
RealMedia RealServer reveals the real IP address of a Real Server, even if the address is supposed to be private.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Clip Art Gallery 5.0 - Local Buffer Overflow
Buffer overflow in Microsoft Clip Art Gallery allows remote attackers to cause a denial of service or execute commands v
28RISK
open ↗Exploit-DB✓ VexDay Proof
Caldera OpenLinux 2.3 - rpm_query CGI
The default installation of Caldera OpenLinux 2.3 includes the CGI program rpm_query, which allows remote attackers to d
23RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle8i Standard Edition 8.1.5 for Linux Installer - Local Privilege Escalation
The installation of Oracle 8.1.5.x on Linux follows symlinks and creates the orainstRoot.sh file with world-writeable pe
23RISK
open ↗Exploit-DB✓ VexDay Proof
SGI InfoSearch 1.0 / SGI IRIX 6.5.x - fname
SGI InfoSearch CGI program infosrch.cgi allows remote attackers to execute commands via shell metacharacters.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000/95/98/ME/NT 3.5.x/Enterprise Server 4.0/Terminal Server 4.0/Workstation 4.0 Microsoft DoS Device Name - Denial of Service
Microsoft Windows 9x operating systems allow an attacker to cause a denial of service via a pathname that includes file
28RISK
open ↗Exploit-DB✓ VexDay Proof
Matt Kimball and Roger Wolff mtr 0.28/0.41 / Turbolinux 3.5 b2/4.2/4.4/6.0 - mtr (2)
The mtr program only uses a seteuid call when attempting to drop privileges, which could allow local users to gain root
23RISK
open ↗Exploit-DB✓ VexDay Proof
DNSTools Software DNSTools 1.0.8/1.10 - Input Validation
DNSTools CGI applications allow remote attackers to execute arbitrary commands via shell metacharacters.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Corel Linux OS 1.0 - Dosemu Distribution Configuration
The default configuration of Dosemu in Corel Linux 1.0 allows local users to execute the system.com program and gain pri
23RISK
open ↗Exploit-DB✓ VexDay Proof
Axis Communications StorPoint CD - Authentication Bypass
Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a .. (dot dot) attack.
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.