Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,542cataloged exploits
34,971CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 13,947VulnCheck XDB 8,542Nuclei 4,243Metasploit 3,468✓ verified onlyrecentpopularrisk
24,443 exploits
Exploit-DB✓ VexDay Proof
IPSwitch IMail IMAP4D - Delete Overflow (Metasploit)
Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a lon
60RISK
open ↗Exploit-DB✓ VexDay Proof
HP OpenView OmniBack II - Command Execution (Metasploit)
Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack c
43RISK
open ↗Exploit-DB✓ VexDay Proof
Macrovision Installshield Update Service - ActiveX Unsafe Method (Metasploit)
Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXn
50RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - ANI LoadAniIcon() Chunk Size Stack Buffer Overflow (SMTP) (MS07-017) (Metasploit)
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code
50RISK
open ↗Exploit-DB✓ VexDay Proof
Computer Associates License Client - GETCONFIG Overflow (Metasploit)
Multiple buffer overflows in Computer Associates (CA) License Client and Server 0.1.0.15 allow remote attackers to execu
50RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - COM CreateObject Code Execution (MS06-014/MS06-073) (Metasploit)
Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and dis
60RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Safari - Archive Metadata Command Execution (Metasploit)
The "Open 'safe' files after downloading" option in Safari on Apple Mac OS X allows remote user-assisted attackers to ex
50RISK
open ↗Exploit-DB✓ VexDay Proof
AwingSoft Winds3D Player 3.5 - SceneURL Download and Execute (Metasploit)
The Awingsoft Awakening Winds3D Viewer plugin 3.5.0.9 allows remote attackers to execute arbitrary programs via a SceneU
43RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - 'createTextRange()' Code Execution (MS06-013) (Metasploit)
Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arb
50RISK
open ↗Exploit-DB✓ VexDay Proof
LightNEasy CMS 3.2.1 - Blind SQL Injection
SQL injection vulnerability in LightNEasy.php in LightNEasy 3.2.1, when magic_quotes_gpc is disabled, allows remote auth
23RISK
open ↗Exploit-DB✓ VexDay Proof
LightNEasy CMS 3.2.1 - Blind SQL Injection
SQL injection vulnerability in LightNEasy.php in LightNEasy 3.2.1, when magic_quotes_gpc is disabled, allows remote atta
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ultra Shareware Office Control - ActiveX HttpUpload Buffer Overflow (Metasploit)
Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware
50RISK
open ↗Exploit-DB✓ VexDay Proof
McAfee ePolicy Orchestrator / ProtectionPilot - Remote Overflow (Metasploit)
Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attac
60RISK
open ↗Exploit-DB✓ VexDay Proof
HP - 'OmniInet.exe' MSG_PROTOCOL Buffer Overflow (Metasploit) (2)
Stack-based buffer overflow in OmniInet.exe (aka the backup client service daemon) in the Application Recovery Manager c
50RISK
open ↗Exploit-DB✓ VexDay Proof
RhinoSoft Serv-U FTPd Server - MDTM Overflow (Metasploit)
Buffer overflow in Serv-U ftp before 5.0.0.4 allows remote authenticated users to execute arbitrary code via a long time
60RISK
open ↗Exploit-DB✓ VexDay Proof
VideoLAN VLC Client (Windows x86) - 'smb://' URI Buffer Overflow (Metasploit)
Stack-based buffer overflow in the Win32AddConnection function in modules/access/smb.c in VideoLAN VLC media player 0.9.
50RISK
open ↗Exploit-DB✓ VexDay Proof
IBM TPM for OS Deployment 5.1.0.x - 'rembo.exe' Remote Buffer Overflow (Metasploit)
The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly hand
50RISK
open ↗Exploit-DB✓ VexDay Proof
Sun Java - Calendar Deserialization (Metasploit)
The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; a
60RISK
open ↗Exploit-DB✓ VexDay Proof
PeerCast 0.1216 (Windows x86) - URL Handling Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in the procConnectArgs function in servmgr.cpp in PeerCast before 0.1217 allow rem
60RISK
open ↗Exploit-DB✓ VexDay Proof
PeerCast 0.1216 (Linux) - URL Handling Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in the procConnectArgs function in servmgr.cpp in PeerCast before 0.1217 allow rem
60RISK
open ↗Exploit-DB✓ VexDay Proof
Arugizer Trojan Horse (Energizer DUO) - Code Execution (Metasploit)
UsbCharger.dll in the Energizer DUO USB battery charger software contains a backdoor that is implemented through the Aru
43RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe - U3D CLODProgressiveMeshDeclaration Array Overrun (Metasploit) (1)
Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might all
50RISK
open ↗Exploit-DB✓ VexDay Proof
TikiWiki tiki-graph_formula - PHP Remote Code Execution (Metasploit)
tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f ar
60RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Lotus Domino Web Access Upload Module - Remote Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, in
50RISK
open ↗Exploit-DB✓ VexDay Proof
Mercantec SoftCart - CGI Overflow (Metasploit)
Buffer overflow in SoftCart.exe in Mercantec SoftCart 4.00b allows remote attackers to execute arbitrary code via a long
50RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox 3.5 - 'escape()' Return Value Memory Corruption (Metasploit)
js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1
50RISK
open ↗Exploit-DB✓ VexDay Proof
Apple QTJava - 'toQTPointer()' Arbitrary Memory Access (Metasploit)
Apple QuickTime Java extensions (QTJava.dll), as used in Safari and other browsers, and when Java is enabled, allows rem
60RISK
open ↗Exploit-DB
primitive CMS 1.0.9 - Multiple Vulnerabilities
cms_write.php in Primitive CMS 1.0.9 does not properly restrict access, which allows remote attackers to gain administra
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco WebEx Meeting Manager UCF - 'atucfobj.dll' ActiveX NewObject Method Buffer Overflow (Metasploit)
Stack-based buffer overflow in the WebexUCFObject ActiveX control in atucfobj.dll in Cisco WebEx Meeting Manager before
50RISK
open ↗Exploit-DB✓ VexDay Proof
McAfee Visual Trace - ActiveX Control Buffer Overflow (Metasploit)
Stack-based buffer overflow in the NeoTraceExplorer.NeoTraceLoader ActiveX control (NeoTraceExplorer.dll) in NeoTrace Ex
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.