Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,760cataloged exploits
32,083CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,934GitHub PoC 13,235VulnCheck XDB 8,150Nuclei 4,193Metasploit 3,462✓ verified onlyrecentpopularrisk
3,462 exploits
Metasploit600
SonicWALL GMS 6 Arbitrary File Upload
An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5
60RISK
open ↗Metasploit300
Irfanview JPEG2000 jp2 Stack Buffer Overflow
Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute a
50RISK
open ↗Metasploit200
HP Diagnostics Server magentservice.exe Overflow
Stack-based buffer overflow in magentservice.exe in the server in HP LoadRunner 11.00 before patch 4 allows remote attac
50RISK
open ↗Metasploit500
HP Easy Printer Care XMLCacheMgr Class ActiveX Control Remote Code Execution
A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to
50RISK
open ↗Metasploit300
NTR ActiveX Control Check() Method Buffer Overflow
Multiple stack-based buffer overflows in the NTR ActiveX control before 2.0.4.8 allow remote attackers to execute arbitr
50RISK
open ↗Metasploit300
NTR ActiveX Control StopModule() Remote Code Execution
The StopModule method in the NTR ActiveX control before 2.0.4.8 allows remote attackers to execute arbitrary code via a
50RISK
open ↗Metasploit300
MS12-004 midiOutPlayNextPolyEvent Heap Overflow
Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows
68RISK
open ↗Metasploit600
MS12-005 Microsoft Office ClickOnce Unsafe Object Package Handling Vulnerability
Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Se
60RISK
open ↗Metasploit600
Apache Struts 2 Developer Mode OGNL Execution
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers
60RISK
open ↗Metasploit600
Apache Struts Remote Command Execution
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during
100RISK
open ↗Metasploit600
OP5 license.php Remote Command Execution
license.php in system-portal before 1.6.2 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execu
60RISK
open ↗Metasploit600
OP5 welcome Remote Command Execution
op5config/welcome in system-op5config before 2.0.3 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers
60RISK
open ↗Metasploit300
Hashtable Collisions
PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions pre
60RISK
open ↗Metasploit300
Hashtable Collisions
Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger ha
60RISK
open ↗Metasploit300
Hashtable Collisions
Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 a
50RISK
open ↗Metasploit300
Hashtable Collisions
Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without r
60RISK
open ↗Metasploit400
CoCSoft StreamDown 6.8.0 Buffer Overflow
Stack-based buffer overflow in CoCSoft Stream Down 6.8.0 allows remote web servers to execute arbitrary code via a long
50RISK
open ↗Metasploit500
FreeBSD Telnet Service Encryption Key ID Buffer Overflow
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RISK
open ↗Metasploit500
Linux BSD-derived Telnet Service Encryption Key ID Buffer Overflow
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RISK
open ↗Metasploit600
HP Managed Printing Administration jobAcct Remote Command Execution
Directory traversal vulnerability in the MPAUploader.Uploader.1.UploadFiles method in HP Managed Printing Administration
50RISK
open ↗Metasploit300
7-Technologies IGSS 9 IGSSdataServer.exe DoS
Buffer overflow in 7-Technologies (7T) Interactive Graphical SCADA System (IGSS) 9.0.0.11200 allows remote attackers to
23RISK
open ↗Metasploit300
Enterasys NetSight nssyslogd.exe Buffer Overflow
Stack-based buffer overflow in the Syslog service (nssyslogd.exe) in Enterasys Network Management Suite (NMS) before 4.1
60RISK
open ↗Metasploit300
MS11-093 Microsoft Windows OLE Object File Handling Remote Code Execution
Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 do not properly handle OLE objects in memory, which allows remote a
60RISK
open ↗Metasploit600
Splunk Search Remote Code Execution
mappy.py in Splunk Web in Splunk 4.2.x before 4.2.5 does not properly restrict use of the mappy command to access Python
43RISK
open ↗Metasploit600
Traq admincp/common.php Remote Code Execution
Traq 2.0–2.3 admincp/common.php RCE
63RISK
open ↗Metasploit300
IpSwitch WhatsUp Gold TFTP Directory Traversal
Directory traversal vulnerability in the TFTP Server 1.0.0.24 in Ipswitch WhatsUp Gold allows remote attackers to read a
50RISK
open ↗Metasploit600
Solarwinds Storage Manager 5.1.0 SQL Injection
SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Prof
50RISK
open ↗Metasploit400
TrendMicro Control Manger CmdProcessor.exe Stack Buffer Overflow
Stack-based buffer overflow in the CGenericScheduler::AddTask function in cmdHandlerRedAlertController.dll in CmdProcess
50RISK
open ↗Metasploit200
Firefox nsSVGValue Out-of-Bounds Access Vulnerability
The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly interact with DOMAtt
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.