Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,640GitHub PoC 14,392VulnCheck XDB 8,755Nuclei 4,333Metasploit 3,478✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
Alt-N WebAdmin 2.0.x - Remote File Disclosure
Absolute path traversal vulnerability in Alt-N Technologies WebAdmin 2.0.0 through 2.0.2 allows remote attackers with ad
23RISK
open ↗Exploit-DB✓ VexDay Proof
Alt-N WebAdmin 2.0.x - Remote File Viewing
Absolute path traversal vulnerability in Alt-N Technologies WebAdmin 2.0.0 through 2.0.2 allows remote attackers with ad
23RISK
open ↗Exploit-DB✓ VexDay Proof
Libopt.a 3.1x - Error Logging Buffer Overflow (1)
Multiple buffer overflows in Options Parsing Tool (OPT) shared library 3.18 and earlier, when used in setuid programs, m
23RISK
open ↗Exploit-DB✓ VexDay Proof
Libopt.a 3.1x - Error Logging Buffer Overflow (2)
Multiple buffer overflows in Options Parsing Tool (OPT) shared library 3.18 and earlier, when used in setuid programs, m
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM AIX 4.x - 'enq' Local Buffer Overflow
Buffer overflow in enq command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a lo
23RISK
open ↗Exploit-DB✓ VexDay Proof
SAP Database 7.3/7.4 - SDBINST Race Condition
Race condition in SDBINST for SAP database 7.3.0.29 creates critical files with world-writable permissions before initia
23RISK
open ↗Exploit-DB✓ VexDay Proof
Battleaxe Software BTTLXE Forum - 'login.asp' SQL Injection
SQL injection vulnerability in bttlxeForum 2.0 beta 3 and earlier allows remote attackers to bypass authentication via t
23RISK
open ↗Exploit-DB✓ VexDay Proof
Snort 1.9.1 - 'p7snort191.sh' Remote Command Execution
Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to exec
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5 - Remote 'URLMON.dll' Remote Buffer Overflow
Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitr
35RISK
open ↗Exploit-DB✓ VexDay Proof
PoPToP PPTP 1.1.4-b3 - Remote Command Execution
ctrlpacket.c in PoPToP PPTP server before 1.1.4-b3 allows remote attackers to cause a denial of service via a length fie
60RISK
open ↗Exploit-DB✓ VexDay Proof
Xinetd 2.1.x/2.3.x - Rejected Connection Memory Leakage Denial of Service
Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large numbe
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.2.4 - DirectoryService 'PATH' Local Privilege Escalation
DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache Mod_Access_Referer 1.0.2 - Null Pointer Dereference Denial of Service
mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header tha
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM AIX 4.3.x/5.1 - 'ERRPT' Local Buffer Overflow
Buffer overflow in errpt in AIX 4.3.3 allows local users to execute arbitrary code as root.
23RISK
open ↗Exploit-DB✓ VexDay Proof
IkonBoard 3.1 - Lang Cookie Arbitrary Command Execution (1)
FUNC.pm in IkonBoard 3.1.2a and earlier, including 3.1.1, does not properly cleanse the "lang" cookie when it contains i
28RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel < 2.4.20 - Module Loader Privilege Escalation
The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root p
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache 2.0.44 (Linux) - Remote Denial of Service
A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via
45RISK
open ↗Exploit-DB✓ VexDay Proof
Samba 2.2.x - 'call_trans2open' Remote Buffer Overflow (1)
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RISK
open ↗Exploit-DB✓ VexDay Proof
Samba < 2.2.8 (Linux/BSD) - Remote Code Execution
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.2.x/2.4.x - Privileged Process Hijacking Privilege Escalation (2)
The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root p
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache 2.x - Memory Leak
A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via
45RISK
open ↗Exploit-DB✓ VexDay Proof
PoPToP < 1.1.3-b3/1.1.3-20030409 - Negative Read Overflow (Metasploit)
ctrlpacket.c in PoPToP PPTP server before 1.1.4-b3 allows remote attackers to cause a denial of service via a length fie
60RISK
open ↗Exploit-DB✓ VexDay Proof
PoPToP PPTP 1.0/1.1.x - Negative 'read()' Argument Remote Buffer Overflow
ctrlpacket.c in PoPToP PPTP server before 1.1.4-b3 allows remote attackers to cause a denial of service via a length fie
60RISK
open ↗Exploit-DB✓ VexDay Proof
SETI@home Clients - Remote Buffer Overflow
Buffer overflow in the SETI@home client 3.03 and other versions allows remote attackers to cause a denial of service (cl
28RISK
open ↗Exploit-DB✓ VexDay Proof
Samba 2.2.x - 'call_trans2open' Remote Buffer Overflow (2)
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RISK
open ↗Exploit-DB✓ VexDay Proof
Samba 2.2.x - 'call_trans2open' Remote Buffer Overflow (4)
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RISK
open ↗Exploit-DB✓ VexDay Proof
Samba 2.2.x - Remote Buffer Overflow
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RISK
open ↗Exploit-DB✓ VexDay Proof
Samba 2.2.x - 'nttrans' Remote Overflow (Metasploit)
Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-
45RISK
open ↗Exploit-DB✓ VexDay Proof
Vignette StoryServer 4.1 - Sensitive Stack Memory Information Disclosure
Vignette StoryServer and Vignette V/5 does not properly calculate the size of text variables, which causes Vignette to r
23RISK
open ↗Exploit-DB✓ VexDay Proof
Samba 2.2.0 < 2.2.8 (OSX) - trans2open Overflow (Metasploit)
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.