Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,324cataloged exploits
36,054CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,721GitHub PoC 14,477VulnCheck XDB 8,829Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - SSI Buffer Overrun Privilege Escalation
Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes
35RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris 8 - x86 xlock Heap Overflow
Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPAT
23RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris 2.6/7/8 (SPARC) - xlock Heap Overflow
Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPAT
23RISK
open ↗Exploit-DB✓ VexDay Proof
Fetchmail 5.x - IMAP Reply Signed Integer Index
Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrit
23RISK
open ↗Exploit-DB✓ VexDay Proof
Fetchmail 5.x - POP3 Reply Signed Integer Index
Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrit
23RISK
open ↗Exploit-DB✓ VexDay Proof
Avaya Argent Office - DNS Packet Denial of Service
Avaya Argent Office allows remote attackers to cause a denial of service by sending UDP packets to port 53 with no paylo
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpBB 1.4 - SQL Query Manipulation
SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT 4.0 - NT4ALL Denial of Service
Windows NT 4.0 SP 6a allows a local user with write access to winnt/system32 to cause a denial of service (crash in lsas
23RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle 8/9i - DBSNMP Oracle Home Environment Variable Buffer Overflow
Buffer overflow in dbsnmp in Oracle 8.0.6 through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_H
23RISK
open ↗Exploit-DB✓ VexDay Proof
SuSE 6.3/6.4/7.0 sdb - Arbitrary Command Execution
Sdbsearch.cgi in SuSE Linux 6.0-7.2 could allow remote attackers to execute arbitrary commands by uploading a keylist.tx
28RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle OTRCREP Oracle 8/9 - Home Environment Variable Buffer Overflow
Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_
23RISK
open ↗Exploit-DB✓ VexDay Proof
Omnicron OmniHTTPd 2.0.7 - File Corruption / Command Execution
statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to overwrite arbitrary files via the cgidir parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
GNU findutils 4.0/4.1 - Locate Arbitrary Command Execution
GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename
23RISK
open ↗Exploit-DB✓ VexDay Proof
Omnicron OmniHTTPd 2.0.7 - File Corruption / Command Execution
statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to execute arbitrary commands via the mostbrowsers parameter, w
28RISK
open ↗Exploit-DB✓ VexDay Proof
phpBB 1.x - Page Header Arbitrary Command Execution
prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid lang
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 98 - ARP Denial of Service
The Microsoft Windows network stack allows remote attackers to cause a denial of service (CPU consumption) via a flood o
28RISK
open ↗Exploit-DB✓ VexDay Proof
id Software Quake 3 Arena Server 1.29 - Buffer Overflow
Quake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection pa
23RISK
open ↗Exploit-DB✓ VexDay Proof
SnapStream PVS 1.2 - Plaintext Password
SnapStream PVS 1.2a stores its passwords in plaintext in the file SSD.ini, which could allow a remote attacker to gain p
23RISK
open ↗Exploit-DB✓ VexDay Proof
SnapStream Personal Video Station 1.2 a - PVS Directory Traversal
Directory traversal vulnerability in SnapStream PVS 1.2a allows remote attackers to read arbitrary files via a .. (dot d
23RISK
open ↗Exploit-DB✓ VexDay Proof
SimpleServer:WWW 1.0.7/1.0.8/1.13 - Hex Encoded URL Directory Traversal
Directory traversal vulnerability in SimpleServer:WWW 1.13 and earlier allows remote attackers to execute arbitrary prog
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ipswitch WS_FTP Server 2.0 - Anonymous Multiple FTP Command Buffer Overflows
Buffer overflows in WS_FTP 2.02 allow remote attackers to execute arbitrary code via long arguments to (1) DELE, (2) MDT
35RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco IOS 12 - UDP Denial of Service
Cisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denial of service via a f
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sambar Server 4.x/5.0 - Insecure Default Password Protection
The default configuration of Sambar Server 5 and earlier uses a symmetric key that is compiled into the binary program f
23RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris 2.6/7.0 - DTMail Mail Environment Variable Buffer Overflow
Buffer overflow in dtmail in Solaris 2.6 and 7 allows local users to gain privileges via the MAIL environment variable.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Proxomitron Naoko-4 - Cross-Site Scripting
Cross-site scripting vulnerability in Proxomitron Naoko-4 BetaFour and earlier allows remote attackers to execute arbitr
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sambar Server 4.4/5.0 - 'pagecount' File Overwrite
Directory traversal vulnerability in pagecount CGI script in Sambar Server before 5.0 beta 5 allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
CGIWrap 2.x/3.x - Cross-Site Scripting
Cross-site scripting vulnerability in CGIWrap before 3.7 allows remote attackers to execute arbitrary Javascript on othe
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHPLib Team PHPLIB 7.2 - Remote Script Execution
prepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to execute arbitra
28RISK
open ↗Exploit-DB✓ VexDay Proof
SSH2 3.0 - Short Password Login
SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle 8i - TNS Listener Buffer Overflow
Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers t
60RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.