Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,559cataloged exploits
34,978CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 13,960VulnCheck XDB 8,542Nuclei 4,243Metasploit 3,472✓ verified onlyrecentpopularrisk
21,899 exploits
Referência✓ VexDay Proof
Microsoft Windows Message Queuing Service - RPC Buffer Overflow (MS07-065) (1)
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Window
50RISK
open ↗Referência✓ VexDay Proof
Microsoft Windows Message Queuing Service - RPC Buffer Overflow (MS07-065) (2)
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Window
50RISK
open ↗Referência✓ VexDay Proof
Microsoft Windows Server 2000 SP4 (Advanced Server) - Message Queue (MS07-065)
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Window
50RISK
open ↗Referência✓ VexDay Proof
PNPHPBB2 < 1.2 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in the PNphpBB2 1.2i and earlier module for PostNuke allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
Particle Gallery 1.0.1 - SQL Injection
SQL injection vulnerability in viewimage.php in Particle Soft Particle Gallery 1.0.1 and earlier allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
DVD X Player 4.1 Professional - '.PLF' File Buffer Overflow
Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF
50RISK
open ↗Referência✓ VexDay Proof
SNMPc 7.0.18 - Remote Denial of Service (Metasploit)
The SNMPc Server (crserv.exe) process in Castle Rock Computing SNMPc before 7.0.19 allows remote attackers to cause a de
23RISK
open ↗Referência✓ VexDay Proof
X.Org xorg-x11-xfs 1.0.2-3.1 - Local Race Condition
The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the
23RISK
open ↗Referência✓ VexDay Proof
Quick.Cart 2.2 - Local/Remote File Inclusion / Remote Code Execution
config/general.php in Quick.Cart 2.2 and earlier uses a default username and password, which allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
Yahoo! Messenger Webcam 8.1 - ActiveX Remote Buffer Overflow
Buffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows
50RISK
open ↗Referência✓ VexDay Proof
Yahoo! Messenger Webcam 8.1 - ActiveX Remote Buffer Overflow (2)
Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows
28RISK
open ↗Referência✓ VexDay Proof
Ace-FTP Client 1.24a - Remote Buffer Overflow (PoC)
Buffer overflow in Ace-FTP Client 1.24a allows user-assisted, remote FTP servers to execute arbitrary code via a long re
23RISK
open ↗Referência✓ VexDay Proof
Vivotek Motion Jpeg Control - 'MjpegDecoder.dll 2.0.0.13' Remote Overflow
Stack-based buffer overflow in the Vivotek Motion Jpeg ActiveX control (aka MjpegControl) in MjpegDecoder.dll 2.0.0.13 a
23RISK
open ↗Referência✓ VexDay Proof
EDraw Office Viewer Component - Unsafe Method
A certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions befo
23RISK
open ↗Referência✓ VexDay Proof
PHP 'FFI' Extension 5.0.5 - 'Safe_mode' Local Bypass
The Foreign Function Interface (ffi) extension in PHP 5.0.5 does not follow safe_mode restrictions, which allows context
23RISK
open ↗Referência✓ VexDay Proof
NVR SP2 2.0 'nvUtility.dll 1.0.14.0' - 'SaveXMLFile()' Insecure Method
Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1.0.14.0 in
23RISK
open ↗Referência✓ VexDay Proof
phpBB Links MOD 1.2.2 - SQL Injection
SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote a
23RISK
open ↗Referência✓ VexDay Proof
OtsTurntables 1.00 - '.m3u' Local Buffer Overflow
Buffer overflow in Ots Labs OTSTurntables 1.00 allows user-assisted remote attackers to execute arbitrary code via a lon
23RISK
open ↗Referência✓ VexDay Proof
CKGold Shopping Cart 2.0 - 'category.php' Blind SQL Injection
SQL injection vulnerability in category.php in CartKeeper CKGold Shopping Cart 2.0 allows remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
PHPMytourney - 'menu.php' Remote File Inclusion
PHP remote file inclusion vulnerability in menu.php in phpMytourney allows remote attackers to execute arbitrary PHP cod
35RISK
open ↗Referência
CVE-2010-0317
Novell Netware 6.5 SP8 allows remote attackers to cause a denial of service (NULL pointer dereference, memory consumptio
28RISK
open ↗Referência✓ VexDay Proof
Microsoft Visual Basic Enterprise 6.0 SP6 - Code Execution
Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to ex
50RISK
open ↗Referência✓ VexDay Proof
Microsoft Visual FoxPro 6.0 - FPOLE.OCX 6.0.8450.0 Remote (PoC)
Stack-based buffer overflow in certain ActiveX controls in (1) FPOLE.OCX 6.0.8450.0 and (2) Foxtlib.ocx, as used in the
35RISK
open ↗Referência✓ VexDay Proof
GlobalLink 2.7.0.8 - 'glItemCom.dll SetInfo()' Heap Overflow
Multiple heap-based buffer overflows in GlobalLink 2.7.0.8 allow remote attackers to execute arbitrary code via (1) a lo
23RISK
open ↗Referência✓ VexDay Proof
GlobalLink 2.7.0.8 - 'glitemflat.dll SetClientInfo()' Heap Overflow
Multiple heap-based buffer overflows in GlobalLink 2.7.0.8 allow remote attackers to execute arbitrary code via (1) a lo
23RISK
open ↗Referência✓ VexDay Proof
AtomixMP3 2.3 - '.pls' Local Buffer Overflow
Buffer overflow in AtomixMP3 2.3 allows user-assisted remote attackers to execute arbitrary code via long strings in fil
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Visual Studio 6.0 - 'VBTOVSI.dll 1.0.0.0' File Overwrite
Absolute directory traversal vulnerability in a certain ActiveX control in the VB To VSI Support Library (VBTOVSI.DLL) 1
28RISK
open ↗Referência✓ VexDay Proof
X-Cart - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote attackers to execute arbitrary PHP code via a
23RISK
open ↗Referência✓ VexDay Proof
Boa 0.93.15 - HTTP Basic Authentication Bypass
The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent st
50RISK
open ↗Referência✓ VexDay Proof
JBlog 1.0 - 'index.php?id' SQL Injection
Multiple SQL injection vulnerabilities in JBlog 1.0 allow (1) remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.