Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,967GitHub PoC 13,264VulnCheck XDB 8,156Nuclei 4,201Metasploit 3,462✓ verified onlyrecentpopularrisk
3,462 exploits
Metasploit300
Macrovision InstallShield Update Service Buffer Overflow
Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXn
50RISK
open ↗Metasploit300
GOM Player ActiveX Control Buffer Overflow
Buffer overflow in the GomManager (GomWeb Control) ActiveX control in GomWeb3.dll 1.0.0.12 in Gretech Online Movie Playe
60RISK
open ↗Metasploit600
Macrovision InstallShield Update Service ActiveX Unsafe Method
Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXn
50RISK
open ↗Metasploit300
RealPlayer ierpplug.dll ActiveX Control Playlist Name Buffer Overflow
Stack-based buffer overflow in the Database Component in MPAMedia.dll in RealNetworks RealPlayer 10.5 and 11 beta, and e
50RISK
open ↗Metasploit300
Oracle DB SQL Injection via SYS.LT.FINDRICSET Evil Cursor Method
SQL injection vulnerability in Workspace Manager for Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.
50RISK
open ↗Metasploit600
TikiWiki tiki-graph_formula Remote PHP Code Execution
tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f ar
60RISK
open ↗Metasploit300
Electronic Arts SnoopyCtrl ActiveX Control Buffer Overflow
Multiple stack-based buffer overflows in Electronic Arts (EA) SnoopyCtrl ActiveX control (NPSnpy.dll) allow remote attac
50RISK
open ↗Metasploit600
HPLIP hpssd.py From Address Arbitrary Command Execution
hpssd in Hewlett-Packard Linux Imaging and Printing Project (hplip) 1.x and 2.x before 2.7.10 allows context-dependent a
50RISK
open ↗Metasploit400
Borland InterBase SVC_attach() Buffer Overflow
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RISK
open ↗Metasploit300
Kazaa Altnet Download Manager ActiveX Control Buffer Overflow
Stack-based buffer overflow in the ADM4 ActiveX control in adm4.dll in Altnet Download Manager 4.0.0.6, as used in (1) K
43RISK
open ↗Metasploit400
Borland InterBase PWD_db_aliased() Buffer Overflow
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RISK
open ↗Metasploit400
Borland InterBase open_marker_file() Buffer Overflow
Stack-based buffer overflow in Borland InterBase LI 8.0.0.53 through 8.1.0.253 on Linux, and possibly unspecified versio
50RISK
open ↗Metasploit400
Borland InterBase isc_attach_database() Buffer Overflow
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RISK
open ↗Metasploit400
Borland InterBase INET_connect() Buffer Overflow
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RISK
open ↗Metasploit400
Borland InterBase jrd8_create_database() Buffer Overflow
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RISK
open ↗Metasploit400
Borland InterBase isc_create_database() Buffer Overflow
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RISK
open ↗Metasploit200
Firebird Relational Database isc_create_database() Buffer Overflow
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RISK
open ↗Metasploit200
Firebird Relational Database SVC_attach() Buffer Overflow
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RISK
open ↗Metasploit200
Firebird Relational Database isc_attach_database() Buffer Overflow
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RISK
open ↗Metasploit500
CA BrightStor HSM Buffer Overflow
Multiple stack-based buffer overflows in Computer Associates (CA) BrightStor Hierarchical Storage Manager (HSM) before r
50RISK
open ↗Metasploit200
Xitami 2.5c2 Web Server If-Modified-Since Overflow
Multiple buffer overflows in iMatix Xitami Web Server 2.5c2 allow remote attackers to execute arbitrary code via a long
60RISK
open ↗Metasploit300
Ask.com Toolbar askBar.dll ActiveX Control Buffer Overflow
Stack-based buffer overflow in the AskJeevesToolBar.SettingsPlugin.1 ActiveX control in askBar.dll in IAC Search & Media
50RISK
open ↗Metasploit400
IBM Tivoli Storage Manager Express CAD Service Buffer Overflow
Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1
60RISK
open ↗Metasploit300
Intersil (Boa) HTTPd Basic Authentication Password Reset
The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent st
50RISK
open ↗Metasploit0
Alcatel-Lucent OmniPCX Enterprise masterCGI Arbitrary Command Execution
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows rem
100RISK
open ↗Metasploit400
Microsoft Visual Basic VBP Stack Buffer Overflow
Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to ex
50RISK
open ↗Metasploit300
Yahoo! Messenger YVerInfo.dll ActiveX Control Buffer Overflow
Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo!
50RISK
open ↗Metasploit600
ClamAV Milter Blackhole-Mode Remote Code Execution
clamav-milter in ClamAV before 0.91.2, when run in black hole mode, allows remote attackers to execute arbitrary command
60RISK
open ↗Metasploit500
Mercury Mail SMTP AUTH CRAM-MD5 Buffer Overflow
Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, all
50RISK
open ↗Metasploit300
2Wire Cross-Site Request Forgery Password Reset Vulnerability
Cross-site request forgery (CSRF) vulnerability in /xslt in 2wire 1701HG and 2071 Gateway routers, with 3.17.5 and 5.29.
18RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.