Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,859cataloged exploits
32,149CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,978GitHub PoC 13,275VulnCheck XDB 8,156Nuclei 4,202Metasploit 3,462✓ verified onlyrecentpopularrisk
3,462 exploits
Metasploit300
3Com SuperStack Switch Denial of Service
Unspecified vulnerability in 3Com SuperStack 3 4400 switches with firmware version before 3.31 allows remote attackers t
30RISK
open ↗Metasploit400
Unreal Tournament 2004 "secure" Overflow (Linux)
The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier,
60RISK
open ↗Metasploit400
Unreal Tournament 2004 "secure" Overflow (Win32)
The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier,
60RISK
open ↗Metasploit500
Squid NTLM Authenticate Overflow
Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when comp
60RISK
open ↗Metasploit200
Subversion Date Svnserve
Stack-based buffer overflow during the apr_time_t data conversion in Subversion 1.0.2 and earlier allows remote attacker
60RISK
open ↗Metasploit200
AppleFileServer LoginExt PathName Overflow
Stack-based buffer overflow in AppleFileServer for Mac OS X 10.3.3 and earlier allows remote attackers to execute arbitr
50RISK
open ↗Metasploit200
MS04-011 Microsoft Private Communications Transport Overflow
Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as u
60RISK
open ↗Metasploit400
MS04-011 Microsoft LSASS Service DsRolerUpgradeDownlevelServer Overflow
Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority
60RISK
open ↗Metasploit300
Norton AntiSpam 2004 SymSpamHelper ActiveX Control Buffer Overflow
Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Nor
50RISK
open ↗Metasploit500
ISS PAM.dll ICQ Parser Buffer Overflow
Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, a
60RISK
open ↗Metasploit300
IBM DB2 db2rcmd.exe Command Execution Vulnerability
DB2 8.1 remote command server (DB2RCMD.EXE) executes the db2rcmdc.exe program as the db2admin administrator, which allow
18RISK
open ↗Metasploit400
BolinTech Dream FTP Server 1.02 Format String
Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string
50RISK
open ↗Metasploit300
Dell OpenManage POST Request Heap Overflow (win32)
Heap-based buffer overflow in Dell OpenManage Web Server 3.4.0 allows remote attackers to cause a denial of service (cra
23RISK
open ↗Metasploit400
Serv-U FTPD MDTM Overflow
Buffer overflow in Serv-U ftp before 5.0.0.4 allows remote authenticated users to execute arbitrary code via a long time
60RISK
open ↗Metasploit500
Proxy-Pro Professional GateKeeper 4.7 GET Request Overflow
Buffer overflow in the web proxy for GateKeeper Pro 4.7 allows remote attackers to execute arbitrary code via a long GET
50RISK
open ↗Metasploit200
PSO Proxy v0.91 Stack Buffer Overflow
Buffer overflow in PSOProxy 0.91 allows remote attackers to cause a denial of service and possibly execute arbitrary cod
50RISK
open ↗Metasploit200
IMail LDAP Service Buffer Overflow
Buffer overflow in the Lightweight Directory Access Protocol (LDAP) daemon (iLDAP.exe 3.9.15.10) in Ipswitch IMail Serve
50RISK
open ↗Metasploit100
MS04-007 Microsoft ASN.1 Library Bitstring Heap Overflow
Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microso
60RISK
open ↗Metasploit500
MDaemon WorldClient form2raw.cgi Stack Buffer Overflow
Stack-based buffer overflow in FORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 allows remote attackers to execute arbi
50RISK
open ↗Metasploit400
MS03-049 Microsoft Workstation Service NetAddAlternateComputerName Overflow
Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers t
60RISK
open ↗Metasploit400
MS03-051 Microsoft IIS ISAPI FrontPage fp30reg.dll Chunked Overflow
Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002
60RISK
open ↗Metasploit400
NIPrint LPD Request Overflow
Buffer overflow in NIPrint 4.10 allows remote attackers to execute arbitrary code via a long string to TCP port 515.
50RISK
open ↗Metasploit200
IA WebMail 3.x Buffer Overflow
Stack-based buffer overflow in IA WebMail Server 3.1.0 allows remote attackers to execute arbitrary code via a long GET
50RISK
open ↗Metasploit400
MS03-046 Exchange 2000 XEXCH50 Heap Overflow
The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service
60RISK
open ↗Metasploit300
mIRC IRC URL Buffer Overflow
Buffer overflow in mIRC before 6.11 allows remote attackers to execute arbitrary code via a long irc:// URL.
50RISK
open ↗Metasploit300
Sendmail SMTP Address prescan Memory Corruption
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, a
30RISK
open ↗Metasploit600
Solaris sadmind Command Execution
The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attack
60RISK
open ↗Metasploit500
Oracle 9i XDB HTTP PASS Overflow (win32)
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to
50RISK
open ↗Metasploit500
Oracle 9i XDB FTP PASS Overflow (win32)
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to
50RISK
open ↗Metasploit500
Oracle 9i XDB FTP UNLOCK Overflow (win32)
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.