Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,760cataloged exploits
32,083CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,934GitHub PoC 13,235VulnCheck XDB 8,150Nuclei 4,193Metasploit 3,462✓ verified onlyrecentpopularrisk
3,462 exploits
Metasploit400
ScriptFTP LIST Remote Buffer Overflow
Stack-based buffer overflow in AmmSoft ScriptFTP 3.3 allows remote FTP servers to execute arbitrary code via a long file
50RISK
open ↗Metasploit300
Apple Safari file:// Arbitrary Code Execution
Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers
50RISK
open ↗Metasploit600
myBB 1.6.4 Backdoor Arbitrary Command Execution
myBB 1.6.4 Backdoor Arbitrary Command Execution
63RISK
open ↗Metasploit200
PcVue 10.0 SV.UIGrdCtrl.1 'LoadObject()/SaveObject()' Trusted DWORD Vulnerability
An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows
43RISK
open ↗Metasploit600
Spreecommerce 0.60.1 Arbitrary Command Execution
Spreecommerce < 0.60.2 Search Parameter RCE
63RISK
open ↗Metasploit600
Plone and Zope XMLTools Remote Command Execution
Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, a
60RISK
open ↗Metasploit400
Cytel Studio 9.0 (CY3 File) Stack Buffer Overflow
Cytel Studio <= 9.0 .CY3 File Stack Buffer Overflow
43RISK
open ↗Metasploit600
Apache Struts ParametersInterceptor Remote Code Execution
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class an
60RISK
open ↗Metasploit500
Sunway Forcecontrol SNMP NetDBServer.exe Opcode 0x57
Sunway Forcecontrol SNMP NetDBServer.exe Opcode 0x57
63RISK
open ↗Metasploit600
Snortreport nmap.php/nbtscan.php Remote Command Execution
Snort Report nmap.php/nbtscan.php RCE
63RISK
open ↗Metasploit600
Measuresoft ScadaPro Remote Command Execution
service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the
50RISK
open ↗Metasploit400
DaqFactory HMI NETB Request Overflow
Stack-based buffer overflow in Azeotech DAQFactory 5.85 build 1853 and earlier allows remote attackers to cause a denial
60RISK
open ↗Metasploit300
Beckhoff TwinCAT SCADA PLC 2.11.0.2004 DoS
Beckhoff TwinCAT 2.11.0.2004 and earlier allows remote attackers to cause a denial of service via a crafted request to U
50RISK
open ↗Metasploit500
CyberLink Power2Go name Attribute (p2g) Stack Buffer Overflow Exploit
Multiple stack-based buffer overflows in CyberLink Power2Go 7 (build 196) and 8 (build 1031) allow remote attackers to e
50RISK
open ↗Metasploit400
ACDSee FotoSlate PLP File id Parameter Overflow
Multiple stack-based buffer overflows in ACDSee FotoSlate 4.0 Build 146 allow remote attackers to execute arbitrary code
50RISK
open ↗Metasploit400
ScadaTEC ScadaPhone Stack Buffer Overflow
Buffer overflow in TurboPower Abbrevia before 4.0, as used in ScadaTEC ScadaPhone 5.3.11.1230 and earlier, ScadaTEC Modb
43RISK
open ↗Metasploit200
CTEK SkyRouter 4200 and 4300 Command Execution
apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via sh
50RISK
open ↗Metasploit300
Procyon Core Server HMI Coreservice.exe Stack Buffer Overflow
Core Server HMI Service (Coreservice.exe) in Scadatec Limited Procyon SCADA 1.06, and other versions before 1.14, allows
50RISK
open ↗Metasploit300
eSignal and eSignal Pro File Parsing Buffer Overflow in QUO
WinSig.exe in eSignal 10.6.2425 and earlier allows remote attackers to cause a denial of service (crash) and possibly ex
50RISK
open ↗Metasploit300
rsyslog Long Tag Off-By-Two DoS
Stack-based buffer overflow in the parseLegacySyslogMsg function in tools/syslogd.c in rsyslogd in rsyslog 4.6.x before
23RISK
open ↗Metasploit500
Free MP3 CD Ripper 1.1 WAV File Stack Buffer Overflow
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RISK
open ↗Metasploit300
Apache Range Header DoS (Apache Killer)
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RISK
open ↗Metasploit500
HP Easy Printer Care XMLSimpleAccessor Class ActiveX Control Remote Code Execution
A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to
60RISK
open ↗Metasploit200
RealNetworks Realplayer QCP Parsing Heap Overflow
Heap-based buffer overflow in qcpfformat.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and
43RISK
open ↗Metasploit600
ktsuss suid Privilege Escalation
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified com
60RISK
open ↗Metasploit300
TeeChart Professional ActiveX Control Trusted Integer Dereference
Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier,
23RISK
open ↗Metasploit300
MS11-021 Microsoft Office 2007 Excel .xlb Buffer Overflow
Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain leng
60RISK
open ↗Metasploit300
Adobe Flash Player MP4 SequenceParameterSetNALUnit Buffer Overflow
Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adob
60RISK
open ↗Metasploit400
Apple QuickTime PICT PnSize Buffer Overflow
Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a deni
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.