Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,559cataloged exploits
34,978CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 13,960VulnCheck XDB 8,542Nuclei 4,243Metasploit 3,472✓ verified onlyrecentpopularrisk
24,443 exploits
Exploit-DB✓ VexDay Proof
IncrediMail - 'ImShExtU.dll' ActiveX Memory Corruption
Stack-based buffer overflow in the DoWebMenuAction function in the IncrediMail IMMenuShellExt ActiveX control (ImShExt.d
35RISK
open ↗Exploit-DB✓ VexDay Proof
TYPSoft FTP Server 1.10 - 'RETR' Denial of Service (1)
Typsoft FTP Server 1.11, with "Sub Directory Include" enabled, allows remote attackers to cause a denial of service (cra
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Komento 1.0.0 - 'sid' SQL Injection
SQL injection vulnerability in the Konsultasi (com_konsultasi) component 1.0.0 for Joomla! allows remote attackers to ex
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component FDione Form Wizard 1.0.2 - Local File Inclusion
Directory traversal vulnerability in the Dione Form Wizard (aka FDione or com_dioneformwizard) component 1.0.2 for Jooml
38RISK
open ↗Exploit-DB✓ VexDay Proof
Symantec Alert Management System Intel Alert Originator Service - Remote Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in IAO.EXE in the Intel Alert Originator Service in Symantec Alert Management Syst
50RISK
open ↗Exploit-DB✓ VexDay Proof
TomatoCMS 2.0.x - SQL Injection
SQL injection vulnerability in index.php in TomatoCMS before 2.0.5 allows remote attackers to execute arbitrary SQL comm
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Shockwave Player 11.5.6.606 - 'DIR' Multiple Memory Vulnerabilities
Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service
28RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Safari 4.0.5 - 'parent.close()' Memory Corruption Code Execution
Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using
28RISK
open ↗Exploit-DB✓ VexDay Proof
Saurus CMS 4.7 - 'edit.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admin/edit.php in Saurus CMS 4.7.0 allows remote authenticated users, with "
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Outlook Express and Windows Mail - Integer Overflow
Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2
28RISK
open ↗Exploit-DB✓ VexDay Proof
AgentX++ Master - AgentX::receive_agentx Stack Buffer Overflow (Metasploit)
Stack-based buffer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Ser
50RISK
open ↗Exploit-DB
29o3 CMS - 'LibDir' Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in 29o3 CMS 0.1 allow remote attackers to execute arbitrary PHP code
23RISK
open ↗Exploit-DB✓ VexDay Proof
724CMS Enterprise 4.59 - SQL Injection
SQL injection vulnerability in index.php in 724Networks 724CMS 4.01 and earlier allows remote attackers to execute arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
tekno.Portal 0.1b - 'makale.php?id' SQL Injection
SQL injection vulnerability in makale.php in tekno.Portal 0.1b allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB
PHPKB Knowledge Base Software 2.0 - Multilanguage Support Multiple SQL Injections
SQL injection vulnerability in comment.php in PHP Knowledge Base (PHPKB) 1.5 and 2.0 allows remote attackers to execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
Advanced Poll 2.0 - 'mysql_host' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in misc/get_admin.php in Advanced Poll 2.08 allows remote attackers to inject a
23RISK
open ↗Exploit-DB
PHPKB Knowledge Base Software 2.0 - Multilanguage Support Multiple SQL Injections
Multiple SQL injection vulnerabilities in PHPKB Knowledge Base Software 1.5 Professional allow remote attackers to execu
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Workstation Service - NetAddAlternateComputerName Overflow (MS03-049) (Metasploit)
Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers t
60RISK
open ↗Exploit-DB✓ VexDay Proof
Novell eDirectory NDS Server - Host Header Overflow (Metasploit)
Multiple stack-based buffer overflows in Novell eDirectory 8.8.x before 8.8.1 FTF1, and 8.x up to 8.7.3.8, and Novell Ne
60RISK
open ↗Exploit-DB✓ VexDay Proof
Easy File Sharing FTP Server 2.0 - PASS Overflow (Metasploit)
Stack-based buffer overflow in EFS Software Easy File Sharing FTP Server 2.0 allows remote attackers to execute arbitrar
50RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Document Capture 10g - ActiveX Control Buffer Overflow (Metasploit)
Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used
50RISK
open ↗Exploit-DB✓ VexDay Proof
Alibaba Clone 3.0 (Special) - SQL Injection
SQL injection vulnerability in offers_buy.php in Alibaba Clone 3.0 allows remote attackers to execute arbitrary SQL comm
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple QuickTime 7.3 - RTSP Response Header Buffer Overflow (Metasploit)
Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac
50RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Tivoli Storage Manager Express CAD Service - Remote Buffer Overflow (Metasploit) (2)
Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1
60RISK
open ↗Exploit-DB✓ VexDay Proof
Now SMS/Mms Gateway - Remote Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in Now SMS/MMS Gateway 2007.06.27 and earlier allow remote attackers to execute ar
50RISK
open ↗Exploit-DB✓ VexDay Proof
MySQL yaSSL (Windows) - SSL Hello Message Buffer Overflow (Metasploit)
Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attacke
60RISK
open ↗Exploit-DB✓ VexDay Proof
3Com TFTP Service (3CTftpSvc) - 'Mode' Remote Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in 3Com 3CTftpSvc 2.0.1, and possibly earlier, allow remote attackers to cause a d
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Whale Intelligent Application Gateway - ActiveX Control Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in the Whale Client Components ActiveX control (WhlMgr.dll), as used in Microsoft
50RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft RRAS Service - Remote Overflow (MS06-025) (Metasploit)
Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Serve
60RISK
open ↗Exploit-DB✓ VexDay Proof
freeSSHd 1.0.9 - Key Exchange Algorithm String Buffer Overflow (Metasploit)
Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other produc
60RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.