Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,760cataloged exploits
32,083CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,934GitHub PoC 13,235VulnCheck XDB 8,150Nuclei 4,193Metasploit 3,462✓ verified onlyrecentpopularrisk
3,462 exploits
Metasploit600
Sun Java Web Start BasicServiceImpl Code Execution
Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote
60RISK
open ↗Metasploit400
FTPGetter Standard v3.55.0.05 Stack Buffer Overflow (PWD)
FTPGetter Standard v.5.97.0.177 allows remote code execution when a user initiates an FTP connection to an attacker-cont
50RISK
open ↗Metasploit500
Sun Java Runtime New Plugin docbase Buffer Overflow
Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows r
60RISK
open ↗Metasploit400
AASync v2.2.1.0 (Win32) Stack Buffer Overflow (LIST)
AASync.com AASync Stack-based Buffer Overflow
18RISK
open ↗Metasploit400
32bit FTP Client Stack Buffer Overflow
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a
43RISK
open ↗Metasploit400
FileWrangler 5.30 Stack Buffer Overflow
FileWrangler <= 5.30 Stack Buffer Overflow
36RISK
open ↗Metasploit400
Gekko Manager FTP Client Stack Buffer Overflow
Gekko Manager FTP Client <= 0.77 Stack Buffer Overflow
36RISK
open ↗Metasploit400
Seagull FTP v3.3 Build 409 Stack Buffer Overflow
Seagull FTP v3.3 Build 409 Stack Buffer Overflow
36RISK
open ↗Metasploit600
Oracle VM Server Virtual Server Agent Command Injection
Unspecified vulnerability in the OracleVM component in Oracle VM 2.2.1 allows remote authenticated users to affect confi
50RISK
open ↗Metasploit300
Windows Escalate NtUserLoadKeyboardLayoutEx Privilege Escalation
The kernel-mode drivers in Microsoft Windows XP SP3 do not properly perform indexing of a function-pointer table during
43RISK
open ↗Metasploit400
FTPShell 5.1 Stack Buffer Overflow
Remote Code Execution was discovered in FTPShell Client 6.53. By default, the client sends a PWD command to the FTP serv
50RISK
open ↗Metasploit400
Odin Secure FTP 4.1 Stack Buffer Overflow (LIST)
Odin Secure FTP <= 4.1 Stack Buffer Overflow via LIST Response
36RISK
open ↗Metasploit400
FTP Synchronizer Professional 4.0.73.274 Stack Buffer Overflow
FTP Synchronizer Professional <= 4.0.73.274 Stack Buffer Overflow
36RISK
open ↗Metasploit300
Barracuda Multiple Product "locale" Directory Traversal
Barracuda Spam & Virus Firewall "locale" Path Traversal
36RISK
open ↗Metasploit200
CA BrightStor ARCserve Tape Engine 0x8A Buffer Overflow
Buffer overflow in the Tape Engine (tapeeng.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 an
60RISK
open ↗Metasploit300
Digital Music Pad Version 8.2.3.3.4 Stack Buffer Overflow
Digital Music Pad <= 8.2.3.3.4 Stack Buffer Overflow
36RISK
open ↗Metasploit400
BACnet OPC Client Buffer Overflow
Stack-based buffer overflow in WTclient.dll in SCADA Engine BACnet OPC Client before 1.0.25 allows user-assisted remote
50RISK
open ↗Metasploit600
MS10-061 Microsoft Print Spooler Service Impersonation Vulnerability
The Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windo
60RISK
open ↗Metasploit300
IBM Lotus Domino iCalendar MAILTO Buffer Overflow
Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server i
50RISK
open ↗Metasploit300
Microsoft IIS 6.0 ASP Stack Exhaustion Denial of Service
Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0
50RISK
open ↗Metasploit600
Windows Escalate Task Scheduler XML Privilege Escalation
The Windows Task Scheduler in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7
43RISK
open ↗Metasploit400
Audiotran PLS File Stack Buffer Overflow
Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedi
50RISK
open ↗Metasploit300
HP Data Protector DtbClsLogin Buffer Overflow
Unspecified vulnerability in HP Data Protector Express, and Data Protector Express Single Server Edition (SSE), 3.x befo
38RISK
open ↗Metasploit500
Adobe CoolType SING Table "uniqueName" Stack Buffer Overflow
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows
100RISK
open ↗Metasploit500
Adobe CoolType SING Table "uniqueName" Stack Buffer Overflow
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows
100RISK
open ↗Metasploit500
Race River Integard Home/Pro LoginAdmin Password Stack Buffer Overflow
The web server in Integard Pro and Home before 2.0.0.9037 and 2.2.x before 2.2.0.9037 has a buffer overflow via a long p
23RISK
open ↗Metasploit500
Apple QuickTime 7.6.7 _Marshaled_pUnk Code Execution
The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x before 7.6.8, and other versions all
50RISK
open ↗Metasploit600
ProcessMaker Plugin Upload
ProcessMaker < 3.5.4 Authenticated Plugin Upload RCE
36RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.