Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,967GitHub PoC 13,264VulnCheck XDB 8,156Nuclei 4,201Metasploit 3,462✓ verified onlyrecentpopularrisk
3,462 exploits
Metasploit200
Novell NetWare LSASS CIFS.NLM Driver Stack Buffer Overflow
Unknown vulnerability in CIFS.NLM in Novell Netware 6.5 SP2 and SP3, 5.1, and 6.0 allows remote attackers to cause a den
50RISK
open ↗Metasploit200
CA BrightStor ARCserve Message Engine Buffer Overflow
Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10
50RISK
open ↗Metasploit200
Novell NetMail IMAP AUTHENTICATE Buffer Overflow
Buffer overflow in the IMAP command continuation function in Novell NetMail 3.52 before 3.52C may allow remote attackers
23RISK
open ↗Metasploit300
Apple QuickTime 7.1.3 RTSP URI Buffer Overflow
Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
50RISK
open ↗Metasploit200
Novell NetMail NMAP STOR Buffer Overflow
Multiple buffer overflows in Novell NetMail before 3.52e FTF2 allow remote attackers to execute arbitrary code (1) by ap
50RISK
open ↗Metasploit200
Novell NetMail IMAP APPEND Buffer Overflow
Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated u
50RISK
open ↗Metasploit200
Novell NetMail IMAP SUBSCRIBE Buffer Overflow
Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated u
50RISK
open ↗Metasploit500
AstonSoft DeepBurner (DBR File) Path Buffer Overflow
Buffer overflow in Astonsoft DeepBurner Pro and Free 1.8.0 and earlier allows user-assisted remote attackers to execute
50RISK
open ↗Metasploit500
MailEnable IMAPD (2.34/2.35) Login Request Buffer Overflow
Stack-based buffer overflow in the IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.35, Pro
50RISK
open ↗Metasploit300
FileZilla FTP Server Malformed PORT Denial of Service
FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to t
60RISK
open ↗Metasploit500
3CTftpSvc TFTP Long Mode Buffer Overflow
Multiple stack-based buffer overflows in 3Com 3CTftpSvc 2.0.1, and possibly earlier, allow remote attackers to cause a d
60RISK
open ↗Metasploit200
Allied Telesyn TFTP Server 1.9 Long Filename Overflow
Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote at
50RISK
open ↗Metasploit500
ProFTPD 1.2 - 1.3.0 sreplace Buffer Overflow (Linux)
Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier allows remote attackers, probably auth
60RISK
open ↗Metasploit200
CA BrightStor ARCserve Tape Engine Buffer Overflow
Buffer overflow in the Tape Engine (tapeeng.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 an
60RISK
open ↗Metasploit400
XMPlay 3.3.0.4 (ASX Filename) Buffer Overflow
Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via
50RISK
open ↗Metasploit400
MS06-066 Microsoft Services nwwks.dll Module Exploit
Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 al
60RISK
open ↗Metasploit0
MS06-070 Microsoft Workstation Service NetpManageIPCConnect Overflow
Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Wi
60RISK
open ↗Metasploit400
MS06-066 Microsoft Services nwapi32.dll Module Exploit
Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 al
60RISK
open ↗Metasploit300
MS06-067 Microsoft Internet Explorer Daxctle.OCX KeyFrame Method Heap Buffer Overflow Vulnerability
Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) fo
60RISK
open ↗Metasploit600
America Online ICQ ActiveX Control Arbitrary File Download and Execute
The ICQPhone.SipxPhoneManager ActiveX control in America Online ICQ 5.1 allows remote attackers to download and execute
50RISK
open ↗Metasploit200
Omni-NFS Server Buffer Overflow
Stack-based buffer overflow in nfsd.exe in XLink Omni-NFS Server 5.2 allows remote attackers to execute arbitrary code v
50RISK
open ↗Metasploit300
TikiWiki Information Disclosure
Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_m
50RISK
open ↗Metasploit300
Microsoft Windows NAT Helper Denial of Service
Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, a
60RISK
open ↗Metasploit500
Novell eDirectory NDS Server Host Header Overflow
Multiple stack-based buffer overflows in Novell eDirectory 8.8.x before 8.8.1 FTF1, and 8.x up to 8.7.3.8, and Novell Ne
60RISK
open ↗Metasploit600
Solaris libnspr NSPR_LOG_FILE Privilege Escalation
The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment v
38RISK
open ↗Metasploit300
MS06-071 Microsoft Internet Explorer XML Core Services HTTP Request Handling
Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML
60RISK
open ↗Metasploit200
SHTTPD URI-Encoded POST Request Overflow
Stack-based buffer overflow in Sergey Lyubka Simple HTTPD (shttpd) 1.34 allows remote attackers to execute arbitrary cod
50RISK
open ↗Metasploit200
CA BrightStor ARCserve Message Engine Heap Overflow
Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; BrightStor ARCserve B
60RISK
open ↗Metasploit500
NaviCOPA 2.0.1 URL Handling Buffer Overflow
Buffer overflow in InterVations NaviCOPA Web Server 2.01 allows remote attackers to execute arbitrary code via a long HT
50RISK
open ↗Metasploit500
TFTPDWIN v0.4.2 Long Filename Buffer Overflow
Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.