Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,294cataloged exploits
36,048CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,721GitHub PoC 14,463VulnCheck XDB 8,813Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
Novell Groupwise 5.5/6.0 Servlet Gateway - Default Authentication
Novell Groupwise 5.5 and 6.0 Servlet Gateway is installed with a default username and password for the servlet manager,
23RISK
open ↗Exploit-DB✓ VexDay Proof
System V Derived /bin/login - Extraneous Arguments Buffer Overflow (modem based) (Metasploit)
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary comman
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - Internet Key Exchange Denial of Service (1)
Windows 2000 allows remote attackers to cause a denial of service (CPU consumption) by flooding Internet Key Exchange (I
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 6.0 / Mozilla 0.9.6 / Opera 5.1 - Image Count Denial of Service
Opera 5.11 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 6.0 / Mozilla 0.9.6 / Opera 5.1 - Image Count Denial of Service
Mozilla 0.9.6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 6.0 / Mozilla 0.9.6 / Opera 5.1 - Image Count Denial of Service
Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via
28RISK
open ↗Exploit-DB✓ VexDay Proof
Brian Dorricott MAILTO 1.0.7-9 - Unauthorized Mail Server Use
mailto.exe in Brian Dorricott MAILTO 1.0.9 and earlier allows remote attackers to send SPAM e-mail through remote server
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - RunAs Service Named Pipe Hijacking
RunAs (runas.exe) in Windows 2000 allows local users to create a spoofed named pipe when the service is stopped, then ca
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - RunAs Service Denial of Service
RunAs (runas.exe) in Windows 2000 only creates one session instance at a time, which allows local users to cause a denia
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 5.0 - False Content-Length Field Denial of Service
Microsoft IIS 5.0 allows remote attackers to cause a denial of service via an HTTP request with a content-length value t
35RISK
open ↗Exploit-DB✓ VexDay Proof
FreeBSD 4.4 - AIO Library Cross Process Memory Write
Some AIO operations in FreeBSD 4.4 may be delayed until after a call to execve, which could allow a local user to overwr
23RISK
open ↗Exploit-DB✓ VexDay Proof
Denicomp Winsock RSHD/NT Standard Error 2.21.00 - Denial of Service
wrshdsp.exe in Denicomp Winsock RSHD/NT 2.21.00 and earlier allows remote attackers to cause a denial of service (CPU co
23RISK
open ↗Exploit-DB✓ VexDay Proof
Denicomp Winsock RSHD/NT Standard Error 2.20.00 - Denial of Service
wrshdsp.exe in Denicomp Winsock RSHD/NT 2.21.00 and earlier allows remote attackers to cause a denial of service (CPU co
23RISK
open ↗Exploit-DB✓ VexDay Proof
McKesson Pathways Homecare 6.5 - Weak 'Username' and Password Encryption
Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users to gain privileges by
41RISK
open ↗Exploit-DB✓ VexDay Proof
Volition Red Faction 1.0/1.1 - Game Server/Client Denial of Service
THQ Volition Red Faction Game allows remote attackers to cause a denial of service (hang) of a client or server via pack
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - Internet Key Exchange Denial of Service (2)
Windows 2000 allows remote attackers to cause a denial of service (CPU consumption) by flooding Internet Key Exchange (I
28RISK
open ↗Exploit-DB✓ VexDay Proof
ZoneAlarm Pro 1.0/2.x - Outbound Packet Bypass
Tiny Personal Firewall 1.0 and 2.0 allows local users to bypass filtering via non-standard TCP packets created with non-
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 1.0/2.5/3.0/4.x/5.x/6.x/7.x - 'user.php?uname' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier allows remote attackers to inject arbitrary web s
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 1.0/2.5/3.0/4.x/5.x/6.x/7.x - 'modules.php' Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier allows remote attackers to inject arbitrary web s
23RISK
open ↗Exploit-DB✓ VexDay Proof
OpenBSD 2.x/3.0 - User Mode Return Value Denial of Service
The uipc system calls (uipc_syscalls.c) in OpenBSD 2.9 and 3.0 provide user mode return instead of versus rval kernel mo
23RISK
open ↗Exploit-DB✓ VexDay Proof
EasyNews 1.5 - NewsDatabase/Template Modification
Directory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify n
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cooolsoft PowerFTP Server 2.0 3/2.10 - Multiple Denial of Service Vulnerabilities (1)
Buffer overflow in Cooolsoft PowerFTP Server 2.03 allows remote attackers to cause a denial of service and possibly exec
28RISK
open ↗Exploit-DB✓ VexDay Proof
Cooolsoft PowerFTP Server 2.0 3/2.10 - Multiple Denial of Service Vulnerabilities (2)
Buffer overflow in Cooolsoft PowerFTP Server 2.03 allows remote attackers to cause a denial of service and possibly exec
28RISK
open ↗Exploit-DB✓ VexDay Proof
WU-FTPD 2.6 - File Globbing Heap Corruption
wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which i
45RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.5/6.0 - Spoofable File Extensions
Internet Explorer 5.5 and 6.0 allows remote attackers to cause the File Download dialogue box to misrepresent the name o
28RISK
open ↗Exploit-DB✓ VexDay Proof
ibm informix Web Datablade 3.x/4.1 - Directory Traversal
Directory traversal vulnerability in ifx CGI program in Informix Web DataBlade allows remote attackers to read arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
SuSE Linux 6.4/7.0/7.1/7.2 Berkeley Parallel Make - Local Buffer Overflow
Buffer overflow in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privileges via a l
23RISK
open ↗Exploit-DB✓ VexDay Proof
SuSE Linux 6.4/7.0/7.1/7.2 Berkeley Parallel Make - Shell Definition Format String
Format string vulnerability in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privil
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP - HCP URI Buffer Overflow
Buffer overflow in helpctr.exe program in Microsoft Help Center for Windows XP allows remote attackers to execute arbitr
28RISK
open ↗Exploit-DB✓ VexDay Proof
bharat Mediratta Gallery 1.1/1.2 - Directory Traversal
Directory traversal vulnerability in modules.php in Gallery before 1.2.3 allows remote attackers to read arbitrary files
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.