Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,324cataloged exploits
36,054CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,721GitHub PoC 14,477VulnCheck XDB 8,829Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
Active Classifieds 1.0 - Arbitrary Code Execution
admin.cgi in Active Classifieds Free Edition 1.0, and possibly commercial versions, allows remote attackers to modify th
23RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris 8 libsldap - Local Buffer Overflow (2)
Buffer overflow in the LDAP naming services library (libsldap) in Sun Solaris 8 allows local users to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco IOS 11.x/12.x - HTTP Configuration Arbitrary Administrative Access (4)
HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when lo
50RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco IOS 11.x/12.x - HTTP Configuration Arbitrary Administrative Access (2)
HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when lo
50RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco IOS 11.x/12.x - HTTP Configuration Arbitrary Administrative Access (1)
HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when lo
50RISK
open ↗Exploit-DB✓ VexDay Proof
Icecast 1.1.x/1.3.x - Slash File Name Denial of Service
Icecast 1.3.7, and other versions before 1.3.11 with HTTP server file streaming support enabled allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
Icecast 1.1.x/1.3.x - Directory Traversal
Directory traversal vulnerability in Icecast 1.3.10 and earlier allows remote attackers to read arbitrary files via a mo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10 - nidump Password File Disclosure
nidump on MacOS X before 10.3 allows local users to read the encrypted passwords from the password file by specifying pa
23RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris 8 libsldap - Local Buffer Overflow (1)
Buffer overflow in the LDAP naming services library (libsldap) in Sun Solaris 8 allows local users to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
XFree86 X11R6 3.3 XDM - Session Cookie Guessing
XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth
23RISK
open ↗Exploit-DB✓ VexDay Proof
GNU groff 1.1x - xploitation Via LPD
Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote att
28RISK
open ↗Exploit-DB✓ VexDay Proof
Samba 2.0.x/2.2 - Arbitrary File Creation
Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remot
28RISK
open ↗Exploit-DB✓ VexDay Proof
teTeX 1.0.7 - Filters Temporary File Race Condition
teTeX filter before 1.0.7 allows local users to gain privileges via a symlink attack on temporary files that are produce
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Index Server 2.0 / Indexing Service (Windows 2000) - ISAPI Extension Buffer Overflow (2)
Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier a
60RISK
open ↗Exploit-DB✓ VexDay Proof
Cerberus FTP Server 1.x - Buffer Overflow (Denial of Service) (PoC)
Cerberus FTP 1.5 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code,
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Visual Studio RAD Support - Remote Buffer Overflow (MS03-051) (Metasploit)
Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attack
28RISK
open ↗Exploit-DB✓ VexDay Proof
eXtremail 1.x/2.1 - Remote Format String (2)
Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privile
23RISK
open ↗Exploit-DB✓ VexDay Proof
1C: Arcadia Internet Store 1.0 - Denial of Service
tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to cause a denial of service via a URL request with
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sun SunVTS 4.x - PTExec Buffer Overflow
Buffer overflow in ptexec in the Sun Validation Test Suite 4.3 and earlier allows a local user to gain privileges via a
23RISK
open ↗Exploit-DB✓ VexDay Proof
KDE KTVision 0.1 - File Overwrite
KDE ktvision 0.1.1-271 and earlier allows local attackers to gain root privileges via a symlink attack on a user configu
23RISK
open ↗Exploit-DB✓ VexDay Proof
1C: Arcadia Internet Store 1.0 - Arbitrary File Disclosure
Directory traversal vulnerability in tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to read arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
1C: Arcadia Internet Store 1.0 - Path Disclosure
tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to discover the full path to the working directory v
23RISK
open ↗Exploit-DB✓ VexDay Proof
cfingerd 1.4.1/1.4.2/1.4.3 Utilities - Local Buffer Overflow (1)
Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Visual Studio RAD Support - Remote Buffer Overflow
Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attack
28RISK
open ↗Exploit-DB✓ VexDay Proof
eXtremail 1.x/2.1 - Remote Format String (1)
Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privile
23RISK
open ↗Exploit-DB✓ VexDay Proof
W3M 0.1/0.2 - Malformed MIME Header Buffer Overflow
Buffer overflow in w3m 0.2.1 and earlier allows a remote attacker to execute arbitrary code via a long base64 encoded MI
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Index Server 2.0 / Indexing Service (Windows 2000) - ISAPI Extension Buffer Overflow (PoC)
Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier a
60RISK
open ↗Exploit-DB✓ VexDay Proof
SGI Performance Co-Pilot 2.1.x/2.2 - pmpost Symbolic Link
The pmpost program in Performance Co-Pilot (PCP) before 2.2.1-3 allows a local user to gain privileges via a symlink att
23RISK
open ↗Exploit-DB✓ VexDay Proof
Tarantella Enterprise 3 3.x - 'TTAWebTop.cgi' Arbitrary File Viewing
Directory traversal vulnerability in ttawebtop.cgi in Tarantella Enterprise 3.00 and 3.01 allows remote attackers to rea
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microburst uDirectory 2.0 - Remote Command Execution
udirectory.pl in Microburst Technologies uDirectory 2.0 and earlier allows remote attackers to execute arbitrary command
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.