Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,814cataloged exploits
32,125CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,967GitHub PoC 13,248VulnCheck XDB 8,150Nuclei 4,201Metasploit 3,462✓ verified onlyrecentpopularrisk
3,462 exploits
Metasploit600
Java RMIConnectionImpl Deserialization Privilege Escalation
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18
60RISK
open ↗Metasploit600
Java Statement.invoke() Trusted Method Chain Privilege Escalation
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18,
100RISK
open ↗Metasploit500
Java MixerSequencer Object GM_Song Structure Handling Vulnerability
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4
60RISK
open ↗Metasploit300
Novell ZENworks Configuration Management Preboot Service 0x21 Buffer Overflow
Directory traversal vulnerability in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1
23RISK
open ↗Metasploit600
Novell ZENworks Configuration Management Remote Execution
Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration M
60RISK
open ↗Metasploit600
Adobe PDF Embedded EXE Social Engineering
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RISK
open ↗Metasploit600
Adobe PDF Escape EXE Social Engineering (No JavaScript)
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RISK
open ↗Metasploit300
Shadow Stream Recorder 3.0.1.7 Buffer Overflow
Multiple stack-based buffer overflows in Mini-stream Ripper 3.0.1.1 allow remote attackers to execute arbitrary code via
50RISK
open ↗Metasploit400
Steinberg MyMP3Player 3.0 Buffer Overflow
Steinberg MyMP3Player <= 3.0.0.67 Buffer Overflow
36RISK
open ↗Metasploit500
VariCAD 2010-2.05 EN (DWB File) Stack Buffer Overflow
VariCAD EN <= 2010-2.05 .dwb File Stack Buffer Overflow
36RISK
open ↗Metasploit400
MS10-018 Microsoft Internet Explorer DHTML Behaviors Use After Free
Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, an
100RISK
open ↗Metasploit400
MS10-018 Microsoft Internet Explorer Tabular Data Control ActiveX Memory Corruption
The Tabular Data Control (TDC) ActiveX control in Microsoft Internet Explorer 5.01 SP4, 6 on Windows XP SP2 and SP3, and
60RISK
open ↗Metasploit600
Energizer DUO USB Battery Charger Arucer.dll Trojan Code Execution
UsbCharger.dll in the Energizer DUO USB battery charger software contains a backdoor that is implemented through the Aru
43RISK
open ↗Metasploit300
Apache mod_isapi Dangling Pointer
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2
60RISK
open ↗Metasploit300
Viscom Image Viewer CP Pro 8.0/Gold 6.0 ActiveX Control
Stack-based buffer overflow in the TIFMergeMultiFiles function in the SCRIBBLE.ScribbleCtrl.1 ActiveX control (ImageView
50RISK
open ↗Metasploit500
Orbital Viewer ORB File Parsing Buffer Overflow
Stack-based buffer overflow in Orbital Viewer 1.04 allows user-assisted remote attackers to execute arbitrary code via a
50RISK
open ↗Metasploit500
MS10-022 Microsoft Internet Explorer Winhlp32.exe MsgBox Code Execution
vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when
60RISK
open ↗Metasploit500
EasyFTP Server list.html path Stack Buffer Overflow
EasyFTP Server list.html path Stack Buffer Overflow
63RISK
open ↗Metasploit500
EasyFTP Server CWD Command Stack Buffer Overflow
EasyFTP Server <= 1.7.0.11 CWD Command Stack Buffer Overflow
63RISK
open ↗Metasploit400
Adobe Acrobat Bundled LibTIFF Integer Overflow
Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a
100RISK
open ↗Metasploit400
Hyleos ChemView ActiveX Control Stack Buffer Overflow
Multiple stack-based buffer overflows in the HyleosChemView.HLChemView ActiveX control (HyleosChemView.ocx) in Hyleos Ch
50RISK
open ↗Metasploit400
MS10-004 Microsoft PowerPoint Viewer TextBytesAtom Stack Buffer Overflow
Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code vi
50RISK
open ↗Metasploit300
Oracle DB 10gR2, 11gR1/R2 DBMS_JVM_EXP_PERMS OS Command Execution
Unspecified vulnerability in the JavaVM component in Oracle Database 11.1.0.7 and 11.2.0.1 allows remote authenticated u
23RISK
open ↗Metasploit300
Oracle DB 11g R1/R2 DBMS_JVM_EXP_PERMS OS Code Execution
Unspecified vulnerability in the JavaVM component in Oracle Database 11.1.0.7 and 11.2.0.1 allows remote authenticated u
23RISK
open ↗Metasploit500
Wireshark LWRES Dissector getaddrsbyname_request Buffer Overflow (loop)
Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote
60RISK
open ↗Metasploit500
Wireshark LWRES Dissector getaddrsbyname_request Buffer Overflow
Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote
60RISK
open ↗Metasploit400
MySQL yaSSL CertDecoder::GetName Buffer Overflow
Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.
50RISK
open ↗Metasploit500
S.O.M.P.L 1.0 Player Buffer Overflow
Simple Web Server Connection Header Buffer Overflow
63RISK
open ↗Metasploit300
MS10-002 Microsoft Internet Explorer Object Memory Use-After-Free
Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers
68RISK
open ↗Metasploit200
AOL 9.5 Phobos.Playlist Import() Stack-based Buffer Overflow
AOL <= 9.5 Phobos.Playlist 'Import()' Stack-Based Buffer Overflow
36RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.