Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,640GitHub PoC 14,392VulnCheck XDB 8,755Nuclei 4,333Metasploit 3,478✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader (UNIX) 5.0 6 / Xpdf 0.9x Hyperlinks - Arbitrary Command Execution
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary comma
35RISK
open ↗Exploit-DB✓ VexDay Proof
Winmail Mail Server 2.3 Build 0402 - Remote Format String
Format string vulnerability in Magic WinMail Server 2.3, and possibly other 2.x versions, allows remote attackers to cau
23RISK
open ↗Exploit-DB✓ VexDay Proof
mnoGoSearch 3.1.20 - Remote Command Execution
Buffer overflow in search.cgi for mnoGoSearch 3.2.10 allows remote attackers to execute arbitrary code via a long tmplt
23RISK
open ↗Exploit-DB✓ VexDay Proof
Atftpd 0.6 - 'atftpdx.c' Remote Command Execution
Buffer overflow in atftp daemon (atftpd) 0.6.1 and earlier, and possibly later versions, allows remote attackers to caus
23RISK
open ↗Exploit-DB✓ VexDay Proof
MNOGoSearch 3.1.20 - 'search.cgi?UL' Remote Buffer Overflow (1)
Buffer overflow in search.cgi for mnoGoSearch 3.1.20 allows remote attackers to execute arbitrary code via a long ul par
23RISK
open ↗Exploit-DB✓ VexDay Proof
MNOGoSearch 3.1.20 - 'search.cgi?UL' Remote Buffer Overflow (2)
Buffer overflow in search.cgi for mnoGoSearch 3.1.20 allows remote attackers to execute arbitrary code via a long ul par
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache 2.0.45 - 'APR' Crash
Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - Object Tag (MS03-020)
Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via
60RISK
open ↗Exploit-DB✓ VexDay Proof
Maxwebportal 1.30 - Remote Database Disclosure
The default installation of MaxWebPortal 1.30 stores the portal database under the web document root with insecure acces
23RISK
open ↗Exploit-DB✓ VexDay Proof
Xaos 3.0 - Language Option Local Buffer Overflow
Buffer overflow in xaos 3.0-23 and earlier, when running setuid, allows local users to gain root privileges via a long -
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sun JRE/SDK 1.x - Untrusted Applet Java Security Model Violation
Sun Java Runtime Environment (JRE) and SDK 1.4.0_01 and earlier allows untrusted applets to access certain information w
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5 - OBJECT Tag Buffer Overflow
Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via
60RISK
open ↗Exploit-DB✓ VexDay Proof
kon2 - Local Buffer Overflow (2)
Buffer overflow in KON kon2 0.3.9b and earlier allows local users to execute arbitrary code via a long -Coding command l
23RISK
open ↗Exploit-DB✓ VexDay Proof
kon2 - Local Buffer Overflow (1)
Buffer overflow in KON kon2 0.3.9b and earlier allows local users to execute arbitrary code via a long -Coding command l
23RISK
open ↗Exploit-DB✓ VexDay Proof
Pi3Web 2.0.2 - SortName Buffer Overflow
Pi3Web web server 2.0.2 Beta 1, when the Directory Index is configured to use the "Name" column and sort using the colum
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - WebDAV Remote Code Execution (2)
Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Wind
60RISK
open ↗Exploit-DB✓ VexDay Proof
IBM AIX 4.3.x/5.1 - 'LSMCODE' Environment Variable Local Buffer Overflow
Buffer overflow in lsmcode in AIX 4.3.3.
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebCortex WebStores2000 - SQL Injection
SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthor
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 5.0 < 5.1 - Remote Denial of Service
Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a lon
35RISK
open ↗Exploit-DB✓ VexDay Proof
PHP 4.x - Transparent Session ID Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_tra
23RISK
open ↗Exploit-DB✓ VexDay Proof
GNU Make For IBM AIX 4.3.3 - CC Path Local Buffer Overflow
Buffer overflow in GNU make for IBM AIX 4.3.3, when installed setgid, allows local users to gain privileges via a long C
23RISK
open ↗Exploit-DB✓ VexDay Proof
AIX 4.3.3/5.x - Getlvcb Command Line Argument Buffer Overflow (1)
Multiple buffer overflows in LVM for AIX 5.1 and 5.2 allow local users to gain privileges via the (1) putlvcb or (2) get
23RISK
open ↗Exploit-DB✓ VexDay Proof
AIX 4.3.3/5.1 - Invscoutd Symbolic Link
The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 5.0 - WebDAV PROPFIND / SEARCH Method Denial of Service
Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a lon
35RISK
open ↗Exploit-DB✓ VexDay Proof
Bandmin 1.4 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.cgi for Bandmin 1.4 allows remote attackers to insert arbitrary HTML o
23RISK
open ↗Exploit-DB✓ VexDay Proof
Axis Network Camera 2.x - HTTP Authentication Bypass
The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass acces
28RISK
open ↗Exploit-DB✓ VexDay Proof
Upclient 5.0 b7 - Command Line Argument Buffer Overflow
Buffer overflow in Uptime Client (UpClient) 5.0b7, and possibly other versions, allows local users to gain privileges vi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sun ONE Application Server 7.0 - Source Disclosure
Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that
28RISK
open ↗Exploit-DB✓ VexDay Proof
Sun ONE Application Server 7.0 - Error Message Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the webapps-simple sample application for (1) Sun ONE Application Server 7.0
23RISK
open ↗Exploit-DB✓ VexDay Proof
Batalla Naval 1.0 4 - Remote Buffer Overflow (2)
Buffer overflow in gbnserver for Gnome Batalla Naval 1.0.4 allows remote attackers to execute arbitrary code via a long
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.