Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,559cataloged exploits
34,978CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 13,960VulnCheck XDB 8,542Nuclei 4,243Metasploit 3,472✓ verified onlyrecentpopularrisk
24,443 exploits
Exploit-DB✓ VexDay Proof
Alt-N MDaemon 9.6.4 - IMAPD FETCH Buffer Overflow (Metasploit)
Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to
50RISK
open ↗Exploit-DB✓ VexDay Proof
Borland Interbase - 'Create-Request' Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in the database service (ibserver.exe) in Borland InterBase 2007 before SP2 allows remote at
50RISK
open ↗Exploit-DB✓ VexDay Proof
Borland CaliberRM - StarTeam Multicast Service Buffer Overflow (Metasploit)
Stack-based buffer overflow in the PGMWebHandler::parse_request function in the StarTeam Multicast Service component (ST
50RISK
open ↗Exploit-DB✓ VexDay Proof
Mercury/32 < 4.01b - PH Server Module Buffer Overflow (Metasploit)
Buffer overflow in Mercury Mail Transport System 4.01b allows remote attackers to execute arbitrary code via a long requ
50RISK
open ↗Exploit-DB✓ VexDay Proof
EnjoySAP SAP GUI - ActiveX Control Buffer Overflow (Metasploit)
Stack-based buffer overflow in the kweditcontrol.kwedit.1 ActiveX control in FrontEnd\SapGui\kwedit.dll in the EnjoySAP
50RISK
open ↗Exploit-DB✓ VexDay Proof
FlipViewer FViewerLoading - ActiveX Control Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in the FViewerLoading ActiveX control (FlipViewerX.dll) in E-Book Systems FlipView
50RISK
open ↗Exploit-DB✓ VexDay Proof
MailEnable - IMAPD W3C Logging Buffer Overflow (Metasploit)
Buffer overflow in the W3C logging for MailEnable Enterprise 1.1 and Professional 1.6 allows remote attackers to execute
50RISK
open ↗Exploit-DB✓ VexDay Proof
PuTTy.exe 0.53 - Remote Buffer Overflow (Metasploit)
Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers
60RISK
open ↗Exploit-DB✓ VexDay Proof
CA BrightStor ARCserve Backup - 'AddColumn()' ActiveX Buffer Overflow (Metasploit)
Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including Br
50RISK
open ↗Exploit-DB✓ VexDay Proof
File Sharing Wizard 1.5.0 - Buffer Overflow (PoC)
Stack-based buffer overflow in iSharer File Sharing Wizard 1.5.0 allows remote attackers to cause a denial of service (c
28RISK
open ↗Exploit-DB✓ VexDay Proof
ShixxNOTE 6.net - Font Field Overflow (Metasploit)
Buffer overflow in ShixxNote 6.net build 117 allows remote attackers to execute arbitrary code via a long font field.
50RISK
open ↗Exploit-DB✓ VexDay Proof
Kerio Personal Firewall 2.1.4 - Authentication Packet Overflow (Metasploit)
Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows r
50RISK
open ↗Exploit-DB
iOS Impact PDF Reader 2.0 - POST Method Remote Denial of Service
Impact Financials, Inc. Impact PDF Reader 2.0, 1.2, and other versions for iPhone and iPod touch allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
VideoWhisper PHP 2 Way Video Chat - 'r' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in VideoWhisper PHP 2 Way Video Chat component for Joomla! allows remote attack
23RISK
open ↗Exploit-DB✓ VexDay Proof
Python 3.2 - 'audioop' Module Memory Corruption
The audioop module in Python 2.7 and 3.2 does not verify the relationships between size arguments and byte string length
28RISK
open ↗Exploit-DB✓ VexDay Proof
LibTIFF 3.9.4 - Unknown Tag Second Pass Processing Remote Denial of Service
LibTIFF 3.9.0 ignores tags in certain situations during the first stage of TIFF file processing and does not properly ha
23RISK
open ↗Exploit-DB✓ VexDay Proof
XnView 1.97.4 - '.MBM' File Remote Heap Buffer Overflow
Heap-based buffer overflow in XnView 1.97.4 and possibly earlier allows remote attackers to execute arbitrary code via a
28RISK
open ↗Exploit-DB✓ VexDay Proof
Yamamah Photo Gallery 1.00 - 'download.php' Local File Disclosure
Directory traversal vulnerability in themes/default/download.php in Yamamah Photo Gallery 1.00, as distributed before 20
23RISK
open ↗Exploit-DB✓ VexDay Proof
UnrealIRCd 3.2.8.1 - Remote Downloader/Execute
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RISK
open ↗Exploit-DB✓ VexDay Proof
Digital Interchange Document Library - SQL Injection
SQL injection vulnerability in view_group.asp in Digital Interchange Document Library 5.8.5 allows remote attackers to e
23RISK
open ↗Exploit-DB✓ VexDay Proof
UTStats - Cross-Site Scripting / SQL Injection / Full Path Disclosure
Cross-site scripting (XSS) vulnerability in pages/match_report.php in UTStats Beta 4 and earlier allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
Digital Interchange Calendar - SQL Injection
SQL injection vulnerability in index.asp in Digital Interchange Calendar 5.8.5 allows remote attackers to execute arbitr
23RISK
open ↗Exploit-DB✓ VexDay Proof
Yamamah Photo Gallery 1.00 - 'calbums' SQL Injection
SQL injection vulnerability in index.php in Yamamah (aka Dove Photo Album) 1.00 allows remote attackers to execute arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
Litespeed Technologies - Web Server Remote Poison Null Byte
LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scrip
50RISK
open ↗Exploit-DB✓ VexDay Proof
UTStats - Cross-Site Scripting / SQL Injection / Full Path Disclosure
SQL injection vulnerability in index.php in UTStats Beta 4 and earlier allows remote attackers to execute arbitrary SQL
23RISK
open ↗Exploit-DB
Yamamah - 'news' SQL Injection / Source Code Disclosure
SQL injection vulnerability in index.php in Yamamah (aka Dove Photo Album) 1.00 allows remote attackers to execute arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
Yamamah 1.0 - SQL Injection
SQL injection vulnerability in index.php in Yamamah (aka Dove Photo Album) 1.00 allows remote attackers to execute arbit
23RISK
open ↗Exploit-DB
Yamamah - 'news' SQL Injection / Source Code Disclosure
Directory traversal vulnerability in themes/default/download.php in Yamamah Photo Gallery 1.00, as distributed before 20
23RISK
open ↗Exploit-DB✓ VexDay Proof
BrightSuite Groupware - SQL Injection
SQL injection vulnerability in pages/contact_list_mail_form.asp in BrightSuite Groupware 5.4 allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
VU Web Visitor Analyst - Authentication Bypass
Multiple SQL injection vulnerabilities in redir.asp in VU Web Visitor Analyst allow remote attackers to execute arbitrar
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.