Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,640GitHub PoC 14,392VulnCheck XDB 8,755Nuclei 4,333Metasploit 3,478✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
Ximian Evolution 1.x - MIME image/* Content-Type Data Inclusion
The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly esca
28RISK
open ↗Exploit-DB✓ VexDay Proof
WFChat 1.0 - Information Disclosure
WF-Chat 1.0 Beta stores sensitive information under the web root with insufficient access control, which allows remote a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mambo Site Server 4.0.10 - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php for Mambo Site Server 4.0.10 allows remote attackers to execute sc
23RISK
open ↗Exploit-DB✓ VexDay Proof
SIPS 0.2.2 - User Information Disclosure
Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insuff
23RISK
open ↗Exploit-DB✓ VexDay Proof
MyABraCaDaWeb 1.0 - Full Path Disclosure
MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to obtain sensitive information via an invalid IDAdmin or other
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 5.0 (Windows XP/2000/NT 4.0) - WebDAV 'ntdll.dll' Remote Buffer Overflow (4)
Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Wind
60RISK
open ↗Exploit-DB✓ VexDay Proof
Ximian Evolution 1.x - UUEncoding Denial of Service
The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attack
28RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.2.x/2.4.x - Privileged Process Hijacking Privilege Escalation (1)
The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root p
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ximian Evolution 1.x - UUEncoding Parsing Memory Corruption
Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumpt
28RISK
open ↗Exploit-DB✓ VexDay Proof
Samba 2.2.x - CIFS/9000 Server A.01.x Packet Assembling Buffer Overflow
Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-
45RISK
open ↗Exploit-DB✓ VexDay Proof
Man Program 1.5 - Unsafe Return Value Command Execution
man before 1.5l allows attackers to execute arbitrary code via a malformed man file with improper quotes, which causes t
23RISK
open ↗Exploit-DB✓ VexDay Proof
Multitech RouteFinder 550 - Remote Memory Corruption
Buffer overflow in the web interface for SOHO Routefinder 550 before firmware 4.63 allows remote attackers to cause a de
28RISK
open ↗Exploit-DB✓ VexDay Proof
Qpopper 4.0.x - Remote Memory Corruption
The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprint
23RISK
open ↗Exploit-DB✓ VexDay Proof
MySQL 3.23.x - 'mysqld' Local Privilege Escalation
MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SEL
35RISK
open ↗Exploit-DB✓ VexDay Proof
Clearswift MAILsweeper 4.x - MIME Attachment Filter Bypass
Clearswift MAILsweeper 4.x allows remote attackers to bypass attachment detection via an attachment that does not specif
23RISK
open ↗Exploit-DB✓ VexDay Proof
File 3.x - Utility Local Memory Allocation
Unknown vulnerability in the "Automatic File Content Type Recognition (AFCTR) Tool version of the file package before 3.
23RISK
open ↗Exploit-DB✓ VexDay Proof
File 3.x - Local Stack Overflow Code Execution (1)
Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user runn
23RISK
open ↗Exploit-DB✓ VexDay Proof
File 3.x - Local Stack Overflow Code Execution (2)
Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user runn
23RISK
open ↗Exploit-DB✓ VexDay Proof
HP JetDirect Printer - SNMP JetAdmin Device Password Disclosure
HP JetDirect printers allow remote attackers to obtain the administrative password for the (1) web and (2) telnet servic
28RISK
open ↗Exploit-DB✓ VexDay Proof
Sendmail 8.12.x - Header Processing Buffer Overflow (1)
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted addre
45RISK
open ↗Exploit-DB✓ VexDay Proof
Sendmail 8.12.x - Header Processing Buffer Overflow (2)
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted addre
45RISK
open ↗Exploit-DB✓ VexDay Proof
TCPDump 3.x - Malformed ISAKMP Packet Denial of Service
isakmp_sub_print in tcpdump 3.6 through 3.7.1 allows remote attackers to cause a denial of service (CPU consumption) via
28RISK
open ↗Exploit-DB✓ VexDay Proof
Axis Communications HTTP Server 2.x - Messages Information Disclosure
AXIS 2400 Video Server 2.00 through 2.33 allows remote attackers to obtain sensitive information via an HTTP request to
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple QuickTime/Darwin Streaming Server 4.1.x - 'parse_xml.cgi' File Disclosure
Directory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Serv
23RISK
open ↗Exploit-DB✓ VexDay Proof
Invision Board 1.1.1 - 'ipchat.php' Remote File Inclusion
ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is e
23RISK
open ↗Exploit-DB✓ VexDay Proof
Electronic Arts Battlefield 1942 1.2/1.3 - Remote Administration Authentication Buffer Overflow
Buffer overflow in the remote console (rcon) in Battlefield 1942 1.2 and 1.3 allows remote attackers to cause a denial o
23RISK
open ↗Exploit-DB✓ VexDay Proof
AMX Mod 0.9.2 - Remote 'amx_say' Format String
Format string vulnerability in AMX 0.9.2 and earlier, a plugin for Valve Software's Half-Life Server, allows remote atta
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/ME - Help and Support Center Buffer Overflow
Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to
28RISK
open ↗Exploit-DB✓ VexDay Proof
CuteNews 0.88 - 'comments.php' Remote File Inclusion
PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL
23RISK
open ↗Exploit-DB✓ VexDay Proof
CuteNews 0.88 - 'search.php' Remote File Inclusion
PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.