Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,295cataloged exploits
36,048CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,721GitHub PoC 14,464VulnCheck XDB 8,813Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
EFTP Server 2.0.7.337 - Directory Existence / File Existence
Directory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a
23RISK
open ↗Exploit-DB✓ VexDay Proof
RedHat Linux 7.0 Apache - Remote Username Enumeration
Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists a
50RISK
open ↗Exploit-DB✓ VexDay Proof
SpeechD 0.1/0.2 - Privileged Command Execution
speechd 0.54 and earlier, with the Festival or rsynth speech synthesis package, allows attackers to execute arbitrary co
23RISK
open ↗Exploit-DB✓ VexDay Proof
CGIEmail 1.6 - Remote Buffer Overflow
Buffer overflow in cgicso.c for cgiemail 1.6 allows remote attackers to cause a denial of service (crash) and possibly e
23RISK
open ↗Exploit-DB✓ VexDay Proof
Digital Unix 4.0 - MSGCHK MH_PROFILE Symbolic Link
msgchk in Digital UNIX 4.0G and earlier allows a local user to read the first line of arbitrary files via a symlink atta
23RISK
open ↗Exploit-DB✓ VexDay Proof
Taylor UUCP 1.0.6 - Argument Handling Privilege Escalation
uuxqt in Taylor UUCP package does not properly remove dangerous long options, which allows local users to gain privilege
23RISK
open ↗Exploit-DB✓ VexDay Proof
Hassan Consulting Shopping Cart 1.23 - Arbitrary Command Execution
shop.pl in Hassan Consulting Shopping Cart 1.23 allows remote attackers to execute arbitrary commands via shell metachar
23RISK
open ↗Exploit-DB✓ VexDay Proof
Merit AAA RADIUS Server 3.8 - rlmadmin Symbolic Link
rlmadmin RADIUS management utility in Merit AAA Server 3.8M, 5.01, and possibly other versions, allows local users to re
23RISK
open ↗Exploit-DB✓ VexDay Proof
Power Up HTML 0.8033 Beta - Directory Traversal Arbitrary File Disclosure
Directory traversal vulnerability in r.pl (aka r.cgi) of Randy Parker Power Up HTML 0.8033beta allows remote attackers t
28RISK
open ↗Exploit-DB✓ VexDay Proof
Digital Unix 4.0 - MSGCHK Buffer Overflow
Buffer overflow in msgchk in Digital UNIX 4.0G and earlier allows local users to execute arbitrary code via a long comma
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco Secure IDS 2.0/3.0 / Snort 1.x / ISS RealSecure 5/6 / NFR 5.0 - Encoded IIS Detection Evasion
Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000
23RISK
open ↗Exploit-DB✓ VexDay Proof
AOLServer 3 - 'Authentication String' Remote Buffer Overflow (2)
Buffer overflow in AOLserver 3.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary co
28RISK
open ↗Exploit-DB✓ VexDay Proof
HP-UX 11.0 - SWVerify Buffer Overflow
Buffer overflow in swverify in HP-UX 11.0, and possibly other programs, allows local users to gain privileges via a long
23RISK
open ↗Exploit-DB✓ VexDay Proof
Irix LPD tagprinter - Command Execution (Metasploit)
lpsched in IRIX 6.5.13f and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.
50RISK
open ↗Exploit-DB✓ VexDay Proof
SIX-webboard 2.01 - File Retrieval
generate.cgi in SIX-webboard 2.01 and before allows remote attackers to read arbitrary files via a dot dot (..) in the c
23RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris 8.0 LPD - Command Execution (Metasploit)
lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request wit
60RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris 2.x/7.0/8 LPD - Remote Command Execution
lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request wit
60RISK
open ↗Exploit-DB✓ VexDay Proof
RedHat 6.2/7.0/7.1 Lpd - Remote Command Execution via DVI Printfilter Configuration Error
The default configuration of the DVI print filter (dvips) in Red Hat Linux 7.0 and earlier does not run dvips in secure
23RISK
open ↗Exploit-DB✓ VexDay Proof
Respondus for WebCT 1.1.2 - Weak Password Encryption
Respondus 1.1.2 for WebCT uses weak encryption to remember usernames and passwords, which allows local users who can rea
23RISK
open ↗Exploit-DB✓ VexDay Proof
UltraEdit 8.2 - FTP Client Weak Password Encryption
UltraEdit uses weak encryption to record FTP passwords in the uedit32.ini file, which allows local users who can read th
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco CBOS 2.x - Multiple TCP Connection Denial of Service Vulnerabilities
Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via mul
23RISK
open ↗Exploit-DB✓ VexDay Proof
AOLServer 3 - 'Authentication String' Remote Buffer Overflow (1)
Buffer overflow in AOLserver 3.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary co
28RISK
open ↗Exploit-DB✓ VexDay Proof
BSDI 3.0/3.1 - Local Kernel Denial of Service
Vulnerability in a system call in BSDI 3.0 and 3.1 allows local users to cause a denial of service (reboot) in the kerne
23RISK
open ↗Exploit-DB✓ VexDay Proof
Intego FileGuard 2.0/4.0 - Weak Password Encryption
Intego FileGuard 4.0 uses weak encryption to store user information and passwords, which allows local users to gain priv
23RISK
open ↗Exploit-DB✓ VexDay Proof
glFTPd 1.x - 'LIST' Denial of Service
glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument t
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sendmail 8.11/8.12 Debugger - Arbitrary Code Execution (1)
Sendmail 8.10.0 through 8.11.5, and 8.12.0 beta, allows local users to modify process memory and possibly gain privilege
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sendmail 8.11/8.12 Debugger - Arbitrary Code Execution (3)
Sendmail 8.10.0 through 8.11.5, and 8.12.0 beta, allows local users to modify process memory and possibly gain privilege
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sendmail 8.11/8.12 Debugger - Arbitrary Code Execution (4)
Sendmail 8.10.0 through 8.11.5, and 8.12.0 beta, allows local users to modify process memory and possibly gain privilege
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sendmail 8.11/8.12 Debugger - Arbitrary Code Execution (2)
Sendmail 8.10.0 through 8.11.5, and 8.12.0 beta, allows local users to modify process memory and possibly gain privilege
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 5.0 - In-Process Table Privilege Escalation
IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges v
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.