Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,866cataloged exploits
35,812CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,573GitHub PoC 14,316VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
Microsoft Windows - Compressed Zipped Folders (MS04-034)
Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows S
35RISK
open ↗Exploit-DB✓ VexDay Proof
Seattle Lab Mail (SLmail) 5.5 - POP3 'PASS' Remote Buffer Overflow (1)
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RISK
open ↗Exploit-DB✓ VexDay Proof
Cscope 13.0/15.x - Insecure Temporary File Creation (1)
main.c in cscope 15-4 and 15-5 creates temporary files with predictable filenames, which allows local users to overwrite
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cscope 13.0/15.x - Insecure Temporary File Creation (2)
main.c in cscope 15-4 and 15-5 creates temporary files with predictable filenames, which allows local users to overwrite
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpBB 2.0.x - 'admin_cash.php' PHP Remote File Inclusion
PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to e
23RISK
open ↗Exploit-DB✓ VexDay Proof
TABS MailCarrier 2.51 - Remote Buffer Overflow
Buffer overflow in MailCarrier 2.51 allows remote attackers to execute arbitrary code via a long (1) EHLO and possibly (
50RISK
open ↗Exploit-DB✓ VexDay Proof
MiniBB 1.7f - 'user' SQL Injection
SQL injection vulnerability in index.php in miniBB 1.7f and earlier allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Exploit-DB✓ VexDay Proof
MiniShare 1.4.1 - Remote Buffer Overflow (2)
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET req
60RISK
open ↗Exploit-DB✓ VexDay Proof
vBulletin - 'LAST.php' SQL Injection
SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Multiple AntiVirus - '.zip' Detection Bypass
Multiple interpretation error in various F-Secure Anti-Virus products, including Workstation 5.43 and earlier, Windows S
28RISK
open ↗Exploit-DB✓ VexDay Proof
Multiple AntiVirus - '.zip' Detection Bypass
Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to by
28RISK
open ↗Exploit-DB✓ VexDay Proof
Multiple AntiVirus - '.zip' Detection Bypass
Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and
28RISK
open ↗Exploit-DB✓ VexDay Proof
Multiple AntiVirus - '.zip' Detection Bypass
Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compress
28RISK
open ↗Exploit-DB✓ VexDay Proof
Multiple AntiVirus - '.zip' Detection Bypass
Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and gl
28RISK
open ↗Exploit-DB✓ VexDay Proof
Multiple AntiVirus - '.zip' Detection Bypass
McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004
35RISK
open ↗Exploit-DB✓ VexDay Proof
Multiple AntiVirus - '.zip' Detection Bypass
RAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global he
28RISK
open ↗Exploit-DB✓ VexDay Proof
Multiple AntiVirus - '.zip' Detection Bypass
Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers
28RISK
open ↗Exploit-DB✓ VexDay Proof
IPSwitch IMail 8.13 - 'DELETE' Remote Stack Overflow
Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a lon
60RISK
open ↗Exploit-DB✓ VexDay Proof
Aztek Forum 4.0 - Multiple Input Validation Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Aztek Forum 4.0 allow remote attackers to inject arbitrary web sc
23RISK
open ↗Exploit-DB✓ VexDay Proof
Kerio Personal Firewall 4.1.1 - Multiple IP Options Denial of Service Vulnerabilities
The FWDRV.SYS driver in Kerio Personal Firewall 4.1.1 and earlier allows remote attackers to cause a denial of service (
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.4.27/2.6.8 - 'binfmt_elf' Executable File Read
The open_exec function in the execve functionality (exec.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, a
23RISK
open ↗Exploit-DB✓ VexDay Proof
XFree86 4.3 - Font Information File Buffer Overflow
Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers t
28RISK
open ↗Exploit-DB✓ VexDay Proof
SlimFTPd 3.15 - Remote Buffer Overflow
Buffer overflow in SlimFTPd 3.15 and earlier allows local users to execute arbitrary code via a long command, such as (1
23RISK
open ↗Exploit-DB✓ VexDay Proof
CCProxy Log - Remote Stack Overflow
Buffer overflow in the logging component of CCProxy allows remote attackers to execute arbitrary code via a long HTTP GE
50RISK
open ↗Exploit-DB✓ VexDay Proof
Qwik SMTP 0.3 - Format String
Format string vulnerability in qwik-smtpd.c in QwikMail SMTP (qwik-smtpd) 0.3 and earlier allows remote attackers to exe
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ability Server 2.34 (Unix) - FTP 'STOR' Remote Buffer Overflow
Buffer overflow in Ability Server 2.34, and possibly other versions, allows remote attackers to execute arbitrary code v
50RISK
open ↗Exploit-DB✓ VexDay Proof
MiniShare 1.4.1 - Remote Buffer Overflow (1)
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET req
60RISK
open ↗Exploit-DB✓ VexDay Proof
Trend Micro ScanMail for Domino 2.51/2.6 - Remote File Disclosure
Trend ScanMail allows remote attackers to obtain potentially sensitive information or disable the anti-virus capability
23RISK
open ↗Exploit-DB✓ VexDay Proof
Monolith Lithtech Game Engine - Multiple Remote Format String Vulnerabilities
Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to caus
23RISK
open ↗Exploit-DB✓ VexDay Proof
TIPS MailPost 5.1.1 - Error Message Cross-Site Scripting
mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, allows remote attackers to cause a denial of service (s
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.