Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,760cataloged exploits
32,083CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,934GitHub PoC 13,235VulnCheck XDB 8,150Nuclei 4,193Metasploit 3,462✓ verified onlyrecentpopularrisk
3,462 exploits
Metasploit600
ProcessMaker Plugin Upload
ProcessMaker < 3.5.4 Authenticated Plugin Upload RCE
36RISK
open ↗Metasploit500
MicroP 0.1.1.1600 (MPPL File) Stack Buffer Overflow
Stack-based buffer overflow in MicroP 0.1.1.1600 allows remote attackers to execute arbitrary code via a crafted .mppl f
50RISK
open ↗Metasploit300
Novell iPrint Client ActiveX Control call-back-url Buffer Overflow
Stack-based buffer overflow in Novell iPrint Client before 5.44 allows remote attackers to execute arbitrary code via a
50RISK
open ↗Metasploit300
A-PDF WAV to MP3 v1.0.0 Buffer Overflow
A-PDF WAV to MP3 Stack-based Buffer Overflow
18RISK
open ↗Metasploit400
Apple QuickTime 7.6.6 Invalid SMIL URI Buffer Overflow
Stack-based buffer overflow in the error-logging functionality in Apple QuickTime before 7.6.7 on Windows allows remote
50RISK
open ↗Metasploit600
Freesshd Authentication Bypass
freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demons
50RISK
open ↗Metasploit300
JBoss Seam 2 File Upload and Execute
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly
100RISK
open ↗Metasploit300
Novell iPrint Client ActiveX Control ExecuteRequest debug Buffer Overflow
The ienipp.ocx ActiveX control in the browser plugin in Novell iPrint Client before 5.42 does not properly validate the
50RISK
open ↗Metasploit300
Amlibweb NetOpacs webquery.dll Stack Buffer Overflow
Amlibweb NetOpacs webquery.dll Stack Buffer Overflow
63RISK
open ↗Metasploit500
HP NNM CGI webappmon.exe OvJavaLocale Buffer Overflow
Stack-based buffer overflow in webappmon.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote at
50RISK
open ↗Metasploit300
WM Downloader 3.1.2.2 Buffer Overflow
WM Downloader 3.1.2.2 Buffer Overflow via Malformed M3U File
36RISK
open ↗Metasploit600
Symantec System Center Alert Management System (hndlrsvc.exe) Arbitrary Command Execution
HDNLRSVC.EXE in the Intel Alert Handler service (aka Symantec Intel Handler service) in Intel Alert Management System (a
30RISK
open ↗Metasploit500
HP OpenView Network Node Manager execvp_nc Buffer Overflow
Stack-based buffer overflow in the execvp_nc function in the ov.dll module in HP OpenView Network Node Manager (OV NNM)
60RISK
open ↗Metasploit300
JBoss Seam 2 Remote Command Execution
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly
100RISK
open ↗Metasploit600
Microsoft Windows Shell LNK Code Execution
Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 all
100RISK
open ↗Metasploit500
Mini-Stream RM-MP3 Converter v3.1.2.1 PLS File Stack Buffer Overflow
Stack-based buffer overflow in Mini-Stream RM-MP3 Converter 3.1.2.1 allows remote attackers to execute arbitrary code vi
50RISK
open ↗Metasploit600
Microsoft Windows Shell LNK Code Execution
Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 all
100RISK
open ↗Metasploit300
Oracle Secure Backup Authentication Bypass/Command Injection Vulnerability
Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote attackers to affect integrity via unknown vecto
50RISK
open ↗Metasploit400
Apache Struts Remote Command Execution
The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fishe
60RISK
open ↗Metasploit600
Oracle Secure Backup Authentication Bypass/Command Injection Vulnerability
Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote attackers to affect integrity via unknown vecto
50RISK
open ↗Metasploit300
Apache Tomcat Transfer-Encoding Information Disclosure and DoS
Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-En
30RISK
open ↗Metasploit300
GSM SIM Editor 5.15 Buffer Overflow
Stack-based buffer overflow in GSM SIM Utility (aka SIM Card Editor) 6.6 allows remote attackers to execute arbitrary co
50RISK
open ↗Metasploit500
EasyFTP Server LIST Command Stack Buffer Overflow
EasyFTP LIST Command denial of service
28RISK
open ↗Metasploit300
MS10-065 Microsoft IIS 5 NTFS Stream Authentication Bypass
Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 on Windows XP SP3, when directory-based B
50RISK
open ↗Metasploit500
HP OpenView Network Node Manager ovwebsnmpsrv.exe ovutil Buffer Overflow
Buffer overflow in ovutil.dll in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remo
50RISK
open ↗Metasploit400
Samba chain_reply Memory Corruption (Linux x86)
Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0
60RISK
open ↗Metasploit500
HP OpenView Network Node Manager ovwebsnmpsrv.exe main Buffer Overflow
Buffer overflow in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers t
50RISK
open ↗Metasploit300
Titan FTP XCRC Directory Traversal Information Disclosure
Directory traversal vulnerability in TitanFTPd in South River Technologies Titan FTP Server 8.10.1125, and probably earl
23RISK
open ↗Metasploit600
UnrealIRCD 3.2.8.1 Backdoor Command Execution
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RISK
open ↗Metasploit600
Microsoft Help Center XSS and Command Execution
The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server
60RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.