Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,967GitHub PoC 13,264VulnCheck XDB 8,156Nuclei 4,201Metasploit 3,462✓ verified onlyrecentpopularrisk
3,462 exploits
Metasploit400
VUPlayer M3U Buffer Overflow
Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long st
50RISK
open ↗Metasploit500
Linux Kernel Sendpage Local Privilege Escalation
The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socke
43RISK
open ↗Metasploit300
Microsoft OWC Spreadsheet HTMLURL Buffer Overflow
Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3,
50RISK
open ↗Metasploit400
BlazeDVD 6.1 PLF Buffer Overflow
Stack-based buffer overflow in BlazeVideo BlazeDVD Standard and Professional 5.0, and possibly earlier, allows remote at
50RISK
open ↗Metasploit500
SAP Business One License Manager 2005 Buffer Overflow
Stack-based buffer overflow in NT_Naming_Service.exe in SAP Business One 2005 A 6.80.123 and 6.80.320 allows remote atta
50RISK
open ↗Metasploit500
Millenium MP3 Studio 2.0 (PLS File) Stack Buffer Overflow
Millenium MP3 Studio <= 2.0 .pls File Stack-Based Buffer Overflow
36RISK
open ↗Metasploit600
Joomla 1.5.12 TinyBrowser File Upload Code Execution
TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
50RISK
open ↗Metasploit600
DD-WRT HTTP Daemon Arbitrary Command Execution
httpd.c in httpd in the management GUI in DD-WRT 24 sp1, and other versions before build 12533, allows remote attackers
60RISK
open ↗Metasploit300
Firefox 3.5 escape() Return Value Memory Corruption
js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1
50RISK
open ↗Metasploit300
Microsoft OWC Spreadsheet msDataSourceObject Memory Corruption
The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 an
50RISK
open ↗Metasploit600
Wyse Rapport Hagent Fake Hserver Command Execution
hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attacker
50RISK
open ↗Metasploit200
AwingSoft Winds3D Player SceneURL Buffer Overflow
Heap-based buffer overflow in the WindsPlayerIE.View.1 ActiveX control in WindsPly.ocx 3.5.0.0 Beta, 3.0.0.5, and earlie
50RISK
open ↗Metasploit300
Microsoft DirectShow (msvidctl.dll) MPEG-2 Memory Corruption
Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in
100RISK
open ↗Metasploit600
ColdFusion 8.0.1 Arbitrary File Upload and Execute
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISK
open ↗Metasploit300
Media Jukebox 8.0.400 Buffer Overflow (SEH)
Heap-based buffer overflow in Sorcerer Software MultiMedia Jukebox 4.0 Build 020124 allows remote attackers to cause a d
50RISK
open ↗Metasploit400
HT-MP3Player 1.0 HT3 File Parsing Buffer Overflow
Stack-based buffer overflow in HT-MP3Player 1.0 allows remote attackers to execute arbitrary code via a long string in a
50RISK
open ↗Metasploit500
Timbuktu PlughNTCommand Named Pipe Buffer Overflow
Stack-based buffer overflow in Motorola Timbuktu Pro 8.6.5 on Windows allows remote attackers to execute arbitrary code
50RISK
open ↗Metasploit500
VideoLAN Client (VLC) Win32 smb:// URI Buffer Overflow
Stack-based buffer overflow in the Win32AddConnection function in modules/access/smb.c in VideoLAN VLC media player 0.9.
50RISK
open ↗Metasploit600
Nagios3 statuswml.cgi Ping Command Execution
statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in t
60RISK
open ↗Metasploit400
Bopup Communications Server Buffer Overflow
Stack-based buffer overflow in B Labs Bopup Communication Server 3.2.26.5460 allows remote attackers to execute arbitrar
50RISK
open ↗Metasploit300
Slowloris Denial of Service Attack
Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-En
30RISK
open ↗Metasploit500
ToolTalk rpc.ttdbserverd _tt_internal_realpath Buffer Overflow (AIX)
Stack-based buffer overflow in the _tt_internal_realpath function in the ToolTalk library (libtt.a) in IBM AIX 5.2.0, 5.
43RISK
open ↗Metasploit300
Slowloris Denial of Service Attack
The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP
40RISK
open ↗Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
On BIG-IP versions 11.6.0-11.6.2 (fixed in 11.6.2 HF1), 12.0.0-12.1.2 HF1 (fixed in 12.1.2 HF2), or 13.0.0-13.0.0 HF2 (f
23RISK
open ↗Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Up
30RISK
open ↗Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build
23RISK
open ↗Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550
23RISK
open ↗Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. Thi
23RISK
open ↗Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
BouncyCastle JCE TLS Bleichenbacher/ROBOT
41RISK
open ↗Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
wolfSSL Bleichenbacher/ROBOT
41RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.