Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,689cataloged exploits
38,075CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,381GitHub PoC 15,712VulnCheck XDB 9,162Nuclei 4,445Metasploit 3,507✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
Resolv+ 'RESOLV_HOST_CONF' - Linux Library Command Execution
glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variabl
23RISK
open ↗Exploit-DB✓ VexDay Proof
John S.2 Roberts AnyForm 1.0/2.0 - CGI Semicolon
AnyForm CGI remote execution.
53RISK
open ↗Exploit-DB✓ VexDay Proof
IRIX 5.2/6.0 - Permissions File Manipulation
SGI Desktop Permissions Tool in IRIX 6.0.1 and earlier allows local users to modify permissions for arbitrary files and
23RISK
open ↗Exploit-DB✓ VexDay Proof
NCSA HTTPd 1.x - Remote Buffer Overflow (2)
Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.
23RISK
open ↗Exploit-DB✓ VexDay Proof
NCSA HTTPd 1.x - Remote Buffer Overflow (2)
Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution.
28RISK
open ↗Exploit-DB✓ VexDay Proof
SGI IRIX 6.0.1 - 'colorview' Read Files
colorview in Silicon Graphics IRIX 5.1, 5.2, and 6.0 allows local attackers to read arbitrary files via the -text argume
23RISK
open ↗Exploit-DB✓ VexDay Proof
Majordomo 1.89/1.90 - 'lists' Command Execution
Remote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sendmail 8.6.9 IDENT - Remote Command Execution
Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.
23RISK
open ↗Exploit-DB✓ VexDay Proof
HP-UX 10/11/ IRIX 3/4/5/6 / OpenSolaris build snv / Solaris 8/9/10 / SunOS 4.1 - 'rpc.ypupdated' Command Execution (1)
rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.
28RISK
open ↗Exploit-DB✓ VexDay Proof
HP-UX 10/11/ IRIX 3/4/5/6 / OpenSolaris build snv / Solaris 8/9/10 / SunOS 4.1 - 'rpc.ypupdated' Command Execution (2)
rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.
28RISK
open ↗Exploit-DB✓ VexDay Proof
SGI IRIX 5.2/5.3 - 'serial_ports' Local Privilege Escalation
serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execut
23RISK
open ↗Exploit-DB✓ VexDay Proof
SunOS 4.1.4 - arp(8c) Memory Dump
Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse prope
23RISK
open ↗Exploit-DB✓ VexDay Proof
Digital Ultrix 4.0/4.1 - '/usr/bin/chroot' Local Privilege Escalation
chroot in Digital Ultrix 4.1 and 4.0 is insecurely installed, which allows local users to gain privileges.
23RISK
open ↗Exploit-DB✓ VexDay Proof
SunView (SunOS 4.1.1) - 'selection_svc' Remote File Read
The SunView (SunTools) selection_svc facility allows remote users to read files.
50RISK
open ↗Exploit-DB✓ VexDay Proof
Intel Corporation Express 8100 ISDN Router - Fragmented ICMP
The Intel express 8100 ISDN router allows remote attackers to cause a denial of service via oversized or fragmented ICMP
23RISK
open ↗Exploit-DB✓ VexDay Proof
Berkeley Sendmail 5.58 - Debug
The debug command in Sendmail is enabled, allowing attackers to execute commands as root.
28RISK
open ↗← previouspage 636 / 636
We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.