Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,689cataloged exploits
38,075CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,381GitHub PoC 15,712VulnCheck XDB 9,162Nuclei 4,445Metasploit 3,507✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
Omnicron OmniHTTPd 1.1/2.4 Pro - Remote Buffer Overflow
Buffer overflow in OmniHTTPd CGI program imagemap.exe allows remote attackers to execute commands.
23RISK
open ↗Exploit-DB✓ VexDay Proof
SuSE Linux 6.1/6.2 - 'cwdtools' Local Overflow / Local Privilege Escalation
Buffer overflows in Linux cdwtools 093 and earlier allows local users to gain root privileges.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Axent Raptor 6.0 - Denial of Service
Denial of service in Axent Raptor firewall via malformed zero-length IP options.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Washington University WU-FTPD 2.5.0 - 'message' Remote Buffer Overflow
Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables i
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0/4.0.1 - JavaScript URL Redirection (MS99-043)
Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet.
28RISK
open ↗Exploit-DB✓ VexDay Proof
AppleShare IP Mail Server 5.0.3 - Buffer Overflow
Buffer overflow in Apple AppleShare Mail Server 5.0.3 on MacOS 8.1 and earlier allows a remote attacker to cause a denia
23RISK
open ↗Exploit-DB✓ VexDay Proof
OpenLink Software OpenLink 3.2 - Remote Buffer Overflow
Buffer overflow in OpenLink 3.2 allows remote attackers to gain privileges via a long GET request to the web configurato
23RISK
open ↗Exploit-DB✓ VexDay Proof
WU-FTPD 2.4.2/2.5 .0/2.6.0 - Remote Format String Stack Overwrite (1)
The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remo
60RISK
open ↗Exploit-DB✓ VexDay Proof
SCO Open Server 5.0.5 - 'userOsa' Symlink
userOsa in SCO OpenServer allows local users to corrupt files via a symlink attack.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0/4.0.1 - iFrame
Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME.
28RISK
open ↗Exploit-DB✓ VexDay Proof
T. Hauck Jana Server 1.0/1.45/1.46 - Directory Traversal
Directory traversal vulnerability in Jana proxy web server 1.45 allows remote attackers to ready arbitrary files via a .
23RISK
open ↗Exploit-DB✓ VexDay Proof
T. Hauck Jana Server 1.0/1.45/1.46 - Directory Traversal
Directory traversal vulnerability in Jana proxy web server 1.40 allows remote attackers to ready arbitrary files via a "
23RISK
open ↗Exploit-DB✓ VexDay Proof
Hybrid Networks Cable Broadband Access System 1.0 - Remote Configuration
Hybrid Network cable modems do not include an authentication mechanism for administration, allowing remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
teamshare teamtrack 3.0 - Directory Traversal
TeamTrack web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.
23RISK
open ↗Exploit-DB✓ VexDay Proof
True North Software Internet Anywhere Mail Server 2.3.x - Mail Server Multiple Buffer Overflow
Buffer overflow in Internet Anywhere POP3 Mail Server allows remote attackers to cause a denial of service or execute co
23RISK
open ↗Exploit-DB✓ VexDay Proof
MediaHouse Software Statistics Server 4.28/5.1 - 'Server ID' Buffer Overflow
Buffer overflow in Mediahouse Statistics Server allows remote attackers to execute commands.
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM AIX 4.3.2 - 'ftpd' Remote Buffer Overflow
Buffer overflow in AIX ftpd in the libc library.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 4.1/5 - Registration Wizard Buffer Overflow
The Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (imgscan.ocx), (4) Thumb
35RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.2 - Predictable TCP Initial Sequence Number
Predictable TCP sequence numbers allow spoofing.
35RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.2 - Predictable TCP Initial Sequence Number
Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor Models 500/700/1000 and 1100/120
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.2 - Predictable TCP Initial Sequence Number
SonicWALL SOHO uses easily predictable TCP sequence numbers, which allows remote attackers to spoof or hijack sessions.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft MSN Messenger Service 1.0 Setup BBS - ActiveX Control Buffer Overflow
Buffer overflow in MSN Setup BBS 4.71.0.10 ActiveX control (setupbbs.ocx) allows a remote attacker to execute arbitrary
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 4 (Windows 95/NT 4.0) - Setupctl ActiveX Control Buffer Overflow
The Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (imgscan.ocx), (4) Thumb
35RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.2 - Predictable TCP Initial Sequence Number
FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate i
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.2 - Predictable TCP Initial Sequence Number
Thomson SpeedTouch 510 ADSL Router with firmware GV8BAA3.270, and possibly earlier versions, generates predictable TCP I
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.2 - Predictable TCP Initial Sequence Number
Cisco switches and routers running CBOS 2.3.8 and earlier use predictable TCP Initial Sequence Numbers (ISN), which allo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5 - Download Behaviour
The "download behavior" in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirec
35RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.2 - Predictable TCP Initial Sequence Number
WinCE 3.0.9348 generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hija
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 4.1/5 - Registration Wizard Buffer Overflow
Buffer overflow in Registration Wizard ActiveX control (regwizc.dll, InvokeRegWizard) 3.0.0.0 for Internet Explorer 4.01
28RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.2 - Predictable TCP Initial Sequence Number
TCP implementations that use random increments for initial sequence numbers (ISN) can allow remote attackers to perform
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.