Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,640GitHub PoC 14,392VulnCheck XDB 8,755Nuclei 4,333Metasploit 3,478✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
Microsoft Windows - ListBox/ComboBox Control Local (MS03-045)
Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary co
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft FrontPage Server Extensions - 'fp30reg.dll' (MS03-051)
Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000 - Workstation Service Overflow (MS03-049)
Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers t
60RISK
open ↗Exploit-DB✓ VexDay Proof
GNU Zebra 0.9x / Quagga 0.96 - Remote Denial of Service
The vty layer in Quagga before 0.96.4, and Zebra 0.93b and earlier, does not verify that sub-negotiation is taking place
23RISK
open ↗Exploit-DB✓ VexDay Proof
Qualcomm Eudora 5.x/6.0 - Spoofed Attachment Line Denial of Service
Buffer overflow in Eudora 5.2.1 allows remote attackers to cause a denial of service (crash and failed restart) and poss
23RISK
open ↗Exploit-DB✓ VexDay Proof
Wireless Tools 26 (IWConfig) - ARGV Local Command Line Buffer Overflow (2)
Buffer overflow in iwconfig, when installed setuid, allows local users to execute arbitrary code via a long OUT environm
23RISK
open ↗Exploit-DB✓ VexDay Proof
Epic 1.0.1/1.0.x - CTCP Nickname Server Message Buffer Overrun
EPIC IRC Client (EPIC4) pre2.002, pre2.003, and possibly later versions, allows remote malicious IRC servers to cause a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Hylafax 4.1.x - HFaxD Format String
Format string vulnerability in hfaxd for Hylafax 4.1.7 and earlier allows remote attackers to execute arbitrary code.
28RISK
open ↗Exploit-DB✓ VexDay Proof
IBM DB2 - 'db2stop' Command Line Argument Local Overflow
Multiple buffer overflows in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via long com
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM DB2 - 'db2govd' Command Line Argument Local Overflow
Multiple buffer overflows in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via long com
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000 - RPC Remote Non Exec Memory
The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and loc
35RISK
open ↗Exploit-DB✓ VexDay Proof
OpenBSD - 'ibcs2_exec' Kernel Code Execution
OpenBSD kernel 3.3 and 3.4 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM DB2 - 'db2start' Command Line Argument Local Overflow
Multiple buffer overflows in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via long com
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM DB2 - 'db2stop' Format String Arbitrary Code Execution
Multiple format string vulnerabilities in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM DB2 - 'db2start' Format String Arbitrary Code Execution
Multiple format string vulnerabilities in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM DB2 - 'db2govd' Format String Arbitrary Code Execution
Multiple format string vulnerabilities in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code
23RISK
open ↗Exploit-DB✓ VexDay Proof
OpenAutoClassifieds 1.0 - 'Listing' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in friendmail.php in OpenAutoClassifieds 1.0 allows remote attackers to inject
23RISK
open ↗Exploit-DB✓ VexDay Proof
NIPrint LPD-LPR Print Server 4.10 - Remote Overflow
Help in NIPrint LPD-LPR Print Server 4.10 and earlier executes Windows Explorer with SYSTEM privileges, which allows loc
23RISK
open ↗Exploit-DB✓ VexDay Proof
John Beatty Easy PHP Photo Album 1.0 - 'dir' HTML Injection
Cross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo Album 1.0 allows remote attackers to inject arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
GNU CFEngine 2.0.x - CFServD Transaction Packet Buffer Overrun (2)
Buffer overflow in net.c for cfengine 2.x before 2.0.8 allows remote attackers to execute arbitrary code via certain pac
28RISK
open ↗Exploit-DB✓ VexDay Proof
Nullsoft SHOUTcast 1.9.2 - 'icy-name/icy-url' Memory Corruption (1)
Buffer overflow in NullSoft Shoutcast Server 1.9.2 allows local users to cause a denial of service via (1) icy-name foll
23RISK
open ↗Exploit-DB✓ VexDay Proof
VieNuke VieBoard 2.6 - SQL Injection
SQL injection vulnerability in viewtopic.asp in VieBoard 2.6 allows remote attackers to execute arbitrary SQL commands v
23RISK
open ↗Exploit-DB✓ VexDay Proof
Web Wiz Forum 6.34/7.0/7.5 - Unauthorized Private Forum Access
post_message_form.asp in Web Wiz Forums 6.34 through 7.5, when quote mode is used, allows remote attackers to read or wr
23RISK
open ↗Exploit-DB✓ VexDay Proof
IA WebMail Server 3.0/3.1 - GET Buffer Overrun
Stack-based buffer overflow in IA WebMail Server 3.1.0 allows remote attackers to execute arbitrary code via a long GET
50RISK
open ↗Exploit-DB✓ VexDay Proof
MPM Guestbook 1.2 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in MPM Guestbook 1.2 allows remote attackers to inject arbitrary web script or
23RISK
open ↗Exploit-DB✓ VexDay Proof
Nullsoft SHOUTcast 1.9.2 - 'icy-name/icy-url' Memory Corruption (2)
Buffer overflow in NullSoft Shoutcast Server 1.9.2 allows local users to cause a denial of service via (1) icy-name foll
23RISK
open ↗Exploit-DB✓ VexDay Proof
Synthetic Reality SymPoll 1.5 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Sympoll 1.5 allows remote attackers to inject arbitrary web scr
23RISK
open ↗Exploit-DB✓ VexDay Proof
MathoPD 1.x - Remote Buffer Overflow
Buffer overflow in the prepare_reply function in request.c for Mathopd 1.2 through 1.5b13, and possibly earlier versions
28RISK
open ↗Exploit-DB✓ VexDay Proof
PHPKit 1.6 - 'Include.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
BRS Webweaver 1.06 - HTTPd 'User-Agent' Remote Denial of Service
Buffer overflow in BRS WebWeaver 1.06 and earlier allows remote attackers to cause a denial of service (crash) and possi
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.