Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,438cataloged exploits
36,583CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,152GitHub PoC 15,079VulnCheck XDB 8,883Nuclei 4,365Metasploit 3,493✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
Nginx 0.6.38 - Heap Corruption
Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, a
45RISK
open ↗Exploit-DB✓ VexDay Proof
GaleriaSHQIP 1.0 - SQL Injection
SQL injection vulnerability in index.php in GaleriaSHQIP 1.0, when magic_quotes_gpc is disabled, allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
XOOPS 2.0.14 - 'article.php' SQL Injection
SQL injection vulnerability in article.php in the Article module for XOOPS allows remote attackers to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel < 2.6.36-rc1 (Ubuntu 10.04 / 2.6.32) - 'CAN BCM' Local Privilege Escalation
Integer overflow in net/can/bcm.c in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.27.
23RISK
open ↗Exploit-DB✓ VexDay Proof
iGaming CMS - Multiple SQL Injections
Multiple SQL injection vulnerabilities in iGaming 1.5 and earlier allow remote attackers to execute arbitrary SQL comman
23RISK
open ↗Exploit-DB✓ VexDay Proof
kontakt formular 1.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in formmailer.php in Kontakt Formular 1.1 allows remote attackers to execute arb
23RISK
open ↗Exploit-DB✓ VexDay Proof
EncFS 1.6.0 - Flawed CBC/CFB Cryptography Implementation
SSL_Cipher.cpp in EncFS before 1.7.0 does not properly handle integer data sizes when constructing headers intended for
23RISK
open ↗Exploit-DB✓ VexDay Proof
Gaestebuch 1.2 - Remote File Inclusion
PHP remote file inclusion vulnerability in guestbook/gbook.php in Gaestebuch 1.2 allows remote attackers to execute arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
NTP daemon readvar - Remote Buffer Overflow (Metasploit)
Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial o
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - Object Type (MS03-020) (Metasploit)
Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via
60RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Extension Manager CS5 5.0.298 - 'dwmapi.dll' DLL Hijacking
Untrusted search path vulnerability in Adobe Extension Manager CS5 5.0.298 allows local users, and possibly remote attac
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Contacts 'wab32res.dll' DLL Hijacking
Untrusted search path vulnerability in Microsoft Windows Contacts allows local users, and possibly remote attackers, to
28RISK
open ↗Exploit-DB✓ VexDay Proof
Google Earth 5.1.3535.3218 - 'quserex.dll' DLL Hijacking
Untrusted search path vulnerability in Google Earth 5.1.3535.3218 allows local users, and possibly remote attackers, to
23RISK
open ↗Exploit-DB✓ VexDay Proof
Xitami Web Server 2.5c2 - If-Modified-Since Overflow (Metasploit)
Multiple buffer overflows in iMatix Xitami Web Server 2.5c2 allow remote attackers to execute arbitrary code via a long
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Address Book 6.00.2900.5512 - 'wab32res.dll' DLL Hijacking
Untrusted search path vulnerability in Microsoft Windows Contacts allows local users, and possibly remote attackers, to
28RISK
open ↗Exploit-DB✓ VexDay Proof
Autodesk AutoCAD 2007 - 'color.dll' DLL Hijacking
Multiple untrusted search path vulnerabilities in Autodesk AutoCAD 2010 allow local users to gain privileges via a Troja
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Services - 'nwapi32.dll' (MS06-066) (Metasploit)
Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 al
60RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Thunderbird - 'dwmapi.dll' DLL Hijacking
Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 an
28RISK
open ↗Exploit-DB✓ VexDay Proof
Corel PHOTO-PAINT X3 13.0.0.576 - 'crlrib.dll' DLL Hijacking
Multiple untrusted search path vulnerabilities in Corel PHOTO-PAINT and CorelDRAW X5 15.1.0.588 allow local users to gai
23RISK
open ↗Exploit-DB✓ VexDay Proof
Corel PHOTO-PAINT X3 13.0.0.576 - 'crlrib.dll' DLL Hijacking
DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel
23RISK
open ↗Exploit-DB✓ VexDay Proof
CorelDRAW X3 13.0.0.576 - 'crlrib.dll' DLL Hijacking
DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mercur Messaging 2005 - IMAP Login Buffer Overflow (Metasploit)
Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause
50RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Group Convertor - 'imm.dll' DLL Hijacking
Untrusted search path vulnerability in Microsoft Windows Progman Group Converter (grpconv.exe) allows local users, and p
28RISK
open ↗Exploit-DB✓ VexDay Proof
Eureka Email Client 2.2q - ERR Remote Buffer Overflow (Metasploit) (2)
Stack-based buffer overflow in Eureka Email 2.2q allows remote POP3 servers to execute arbitrary code via a long error m
50RISK
open ↗Exploit-DB✓ VexDay Proof
Skype 4.2.0.169 - 'wab32.dll' DLL Hijacking
Untrusted search path vulnerability in Skype 4.2.0.169 and earlier allows local users, and possibly remote attackers, to
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Internet Communication Settings - 'schannel.dll' DLL Hijacking
Untrusted search path vulnerability in Microsoft Windows Internet Communication Settings on Windows XP SP3 allows local
28RISK
open ↗Exploit-DB✓ VexDay Proof
Media Player Classic 6.4.9.1 - 'iacenc.dll' DLL Hijacking
Untrusted search path vulnerability in the Indeo Codec in iac25_32.ax in Microsoft Windows XP SP3 allows local users to
28RISK
open ↗Exploit-DB✓ VexDay Proof
TechSmith Snagit 10 (Build 788) - 'dwmapi.dll' DLL Hijacking
Untrusted search path vulnerability in TechSmith Snagit all versions 10.x and 11.x allows local users, and possibly remo
23RISK
open ↗Exploit-DB✓ VexDay Proof
SquirrelMail PGP Plugin - Command Execution (SMTP) (Metasploit)
The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via s
43RISK
open ↗Exploit-DB✓ VexDay Proof
NullSoft Winamp 5.581 - 'wnaspi32.dll' DLL Hijacking
Untrusted search path vulnerability in Nullsoft Winamp 5.581, and probably other versions, allows local users, and possi
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.