Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,978GitHub PoC 13,282VulnCheck XDB 8,176Nuclei 4,202Metasploit 3,462✓ verified onlyrecentpopularrisk
3,462 exploits
Metasploit500
MS03-026 Microsoft RPC DCOM Interface Overflow
Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote
60RISK
open ↗Metasploit400
MS03-022 Microsoft IIS ISAPI nsiislog.dll ISAPI POST Overflow
Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability
60RISK
open ↗Metasploit200
Alt-N WebAdmin USER Buffer Overflow
Buffer overflow in WebAdmin.exe for WebAdmin allows remote attackers to execute arbitrary code via an HTTP request to We
50RISK
open ↗Metasploit300
Sambar 6 Search Results Buffer Overflow
Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers t
60RISK
open ↗Metasploit300
LeapWare LeapFTP v2.7.3.600 PASV Reply Client Overflow
Buffer overflow in LeapFTP 2.7.3.600 allows remote FTP servers to execute arbitrary code via a long IP address response
50RISK
open ↗Metasploit300
MS03-020 Microsoft Internet Explorer Object Type
Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via
60RISK
open ↗Metasploit500
MS03-007 Microsoft IIS 5.0 WebDAV ntdll.dll Path Overflow
Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Wind
60RISK
open ↗Metasploit500
Seattle Lab Mail 5.5 POP3 Buffer Overflow
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RISK
open ↗Metasploit200
Kerio Firewall 2.1.4 Authentication Packet Overflow
Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows r
50RISK
open ↗Metasploit500
BadBlue 2.5 EXT.dll Buffer Overflow
Buffer overflow in ext.dll in BadBlue 2.55 allows remote attackers to execute arbitrary code via a long mfcisapicommand
50RISK
open ↗Metasploit500
Poptop Negative Read Overflow
ctrlpacket.c in PoPToP PPTP server before 1.1.4-b3 allows remote attackers to cause a denial of service via a length fie
60RISK
open ↗Metasploit500
Samba trans2open Overflow (*BSD x86)
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RISK
open ↗Metasploit200
Samba 2.2.2 - 2.2.6 nttrans Buffer Overflow
Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute a
30RISK
open ↗Metasploit500
Samba trans2open Overflow (Mac OS X PPC)
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RISK
open ↗Metasploit500
Samba trans2open Overflow (Solaris SPARC)
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RISK
open ↗Metasploit500
Samba trans2open Overflow (Linux x86)
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RISK
open ↗Metasploit600
QuickTime Streaming Server parse_xml.cgi Remote Execution
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote a
50RISK
open ↗Metasploit300
Solaris KCMS + TTDB Arbitrary File Read
Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allow
23RISK
open ↗Metasploit500
RealServer Describe Buffer Overflow
Multiple buffer overflows in RealNetworks Helix Universal Server 9.0 (9.0.2.768) allow remote attackers to execute arbit
60RISK
open ↗Metasploit300
PuTTY Buffer Overflow
Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers
60RISK
open ↗Metasploit200
Webster HTTP Server GET Buffer Overflow
Buffer overflow in Webster HTTP Server allows remote attackers to execute arbitrary code via a long URL.
50RISK
open ↗Metasploit200
TFTPD32 Long Filename Buffer Overflow
Buffer overflow in tftpd of TFTP32 2.21 and earlier allows remote attackers to execute arbitrary code via a long filenam
50RISK
open ↗Metasploit300
MS02-065 Microsoft IIS MDAC msadcs.dll RDS DataStub Content-Type Overflow
Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 th
60RISK
open ↗Metasploit300
MS02-063 PPTP Malformed Control Data Kernel Denial of Service
Buffer overflow in Microsoft PPTP Service on Windows XP and Windows 2000 allows remote attackers to cause a denial of se
30RISK
open ↗Metasploit500
Savant 3.1 Web Server Overflow
Buffer overflow in Savant Web Server 3.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP G
50RISK
open ↗Metasploit600
HP-UX LPD Command Execution
Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of ser
38RISK
open ↗Metasploit400
MS02-056 Microsoft SQL Server Hello Overflow
Buffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 al
60RISK
open ↗Metasploit400
MS02-039 Microsoft SQL Server Resolution Overflow
Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSD
60RISK
open ↗Metasploit200
SecureCRT SSH1 Buffer Overflow
Buffer overflow in Van Dyke SecureCRT SSH client before 3.4.6, and 4.x before 4.0 beta 3, allows an SSH server to execut
50RISK
open ↗Metasploit500
Solaris dtspcd Heap Overflow
Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remo
60RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.