Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,760cataloged exploits
32,083CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,934GitHub PoC 13,235VulnCheck XDB 8,150Nuclei 4,193Metasploit 3,462✓ verified onlyrecentpopularrisk
3,462 exploits
Metasploit600
Exim4 string_format Function Heap Buffer Overflow
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to exe
100RISK
open ↗Metasploit600
Exim4 string_format Function Heap Buffer Overflow
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specif
91RISK
open ↗Metasploit600
ProFTPD 1.3.3c Backdoor Command Execution
ProFTPD 1.3.3c Backdoor Command Execution
63RISK
open ↗Metasploit600
Pandora FMS v3.1 Auth Bypass and Arbitrary File Upload Vulnerability
The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which al
50RISK
open ↗Metasploit400
MS11-003 Microsoft Internet Explorer CSS Recursive Import Use After Free
Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in msh
60RISK
open ↗Metasploit500
Xion Audio Player 1.0.126 Unicode Stack Buffer Overflow
Xion Audio Player ≤ 1.0.126 Unicode Stack Buffer Overflow
36RISK
open ↗Metasploit500
DATAC RealWin SCADA Server SCPC_TXTEVENT Buffer Overflow
Multiple stack-based buffer overflows in DATAC RealWin 2.0 Build 6.1.8.10 and earlier allow remote attackers to cause a
50RISK
open ↗Metasploit600
SystemTap MODPROBE_OPTIONS Privilege Escalation
The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allow
38RISK
open ↗Metasploit300
Novell iPrint Client ActiveX Control Buffer Overflow
Stack-based buffer overflow in an ActiveX control in ienipp.ocx in Novell iPrint Client 5.52 allows remote attackers to
50RISK
open ↗Metasploit600
CakePHP Cache Corruption Code Execution
The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows re
50RISK
open ↗Metasploit300
RealNetworks RealPlayer CDDA URI Initialization Vulnerability
An ActiveX control in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterpr
50RISK
open ↗Metasploit500
Foxit PDF Reader v4.1.1 Title Stack Buffer Overflow
Foxit PDF Reader < 4.2.0.0928 Title Stack Buffer Overflow
36RISK
open ↗Metasploit500
MS10-087 Microsoft Word RTF pFragments Stack Buffer Overflow (File Format)
Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2
100RISK
open ↗Metasploit500
FreeNAS exec_raw.php Arbitrary Command Execution
FreeNAS < 0.7.2 rev 5543 exec_raw.php Arbitrary Command Execution
43RISK
open ↗Metasploit400
MS10-090 Microsoft Internet Explorer CSS SetUserClip Memory Corruption
Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary cod
100RISK
open ↗Metasploit500
ProFTPD 1.3.2rc3 - 1.3.3b Telnet IAC Buffer Overflow (Linux)
Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow rem
60RISK
open ↗Metasploit500
ProFTPD 1.3.2rc3 - 1.3.3b Telnet IAC Buffer Overflow (FreeBSD)
Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow rem
60RISK
open ↗Metasploit300
Adobe Flash Player "Button" Remote Code Execution
Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 o
50RISK
open ↗Metasploit300
Mozilla Firefox Interleaved document.write/appendChild Memory Corruption
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, a
100RISK
open ↗Metasploit300
Adobe Shockwave rcsL Memory Corruption
The Director module (dirapi.dll) in Adobe Shockwave Player before 11.5.9.615 allows remote attackers to execute arbitrar
60RISK
open ↗Metasploit500
MOXA Device Manager Tool 2.1 Buffer Overflow
Stack-based buffer overflow in MDMUtil.dll in MDMTool.exe in MDM Tool before 2.3 in Moxa Device Manager allows remote MD
43RISK
open ↗Metasploit500
Reliable Datagram Sockets (RDS) rds_page_copy_user Privilege Escalation
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the
91RISK
open ↗Metasploit200
MOXA MediaDBPlayback ActiveX Control Buffer Overflow
Stack-based buffer overflow in a certain ActiveX control in MediaDBPlayback.DLL 2.2.0.5 in the Moxa ActiveX SDK allows r
50RISK
open ↗Metasploit600
glibc '$ORIGIN' Expansion Privilege Escalation
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not pro
38RISK
open ↗Metasploit600
glibc LD_AUDIT Arbitrary DSO Load Privilege Escalation
ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use
43RISK
open ↗Metasploit600
glibc LD_AUDIT Arbitrary DSO Load Privilege Escalation
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not pro
38RISK
open ↗Metasploit300
Fat Player Media Player 0.6b0 Buffer Overflow
Stack-based buffer overflow in Fat Player 0.6b allows remote attackers to execute arbitrary code via a long string in a
50RISK
open ↗Metasploit500
DATAC RealWin SCADA Server SCPC_INITIALIZE Buffer Overflow
Multiple stack-based buffer overflows in DATAC RealWin 2.0 Build 6.1.8.10 and earlier allow remote attackers to cause a
50RISK
open ↗Metasploit500
DATAC RealWin SCADA Server SCPC_INITIALIZE_RF Buffer Overflow
Multiple stack-based buffer overflows in DATAC RealWin 2.0 Build 6.1.8.10 and earlier allow remote attackers to cause a
50RISK
open ↗Metasploit300
Oracle DB SQL Injection via SYS.DBMS_CDC_PUBLISH.CREATE_CHANGE_SET
Unspecified vulnerability in the Change Data Capture component in Oracle Database Server 10.1.0.5, 10.2.0.4, 11.1.0.7, a
18RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.