Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,324cataloged exploits
36,054CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,721GitHub PoC 14,477VulnCheck XDB 8,829Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
Microsoft IIS 3.0/4.0/5.0 - PWS Escaped Characters Decoding Command Execution (7)
Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encodi
60RISK
open ↗Exploit-DB✓ VexDay Proof
Maxum Rumpus FTP Server 1.3.2/1.3.4/2.0.3 dev - Remote Denial of Service
Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 allows a remote attacker to perform a denial of service (hang) by creating
23RISK
open ↗Exploit-DB✓ VexDay Proof
Pacific Software Carello 1.2.1 Shopping Cart - Command Execution
Carello E-Commerce 1.2.1 and earlier allows a remote attacker to gain additional privileges and execute arbitrary comman
23RISK
open ↗Exploit-DB✓ VexDay Proof
Immunix OS 6.2/7.0 / RedHat 5.2/6.2/7.0 / SuSE Linux 6.x/7.0/7.1 - 'Man -S' Heap Overflow
Buffer overflow in man program in various distributions of Linux allows local user to execute arbitrary code as group ma
23RISK
open ↗Exploit-DB✓ VexDay Proof
OpenServer 5.0.5/5.0.6 / HP-UX 10/11 / Solaris 2.6/7.0/8 - rpc.yppasswdd Buffer Overrun
Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access v
35RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Personal Web Sharing 1.1/1.5/1.5.5 - Remote Denial of Service
Personal Web Sharing 1.5.5 allows a remote attacker to cause a denial of service via a long HTTP request.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 SP1/SP2 - isapi .printer Extension Overflow (2)
Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via
60RISK
open ↗Exploit-DB✓ VexDay Proof
DCForum 6.0 - Remote Admin Privilege Arbitrary Commands
DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symb
23RISK
open ↗Exploit-DB✓ VexDay Proof
BeroFTPD 1.3.4(1) (Linux x86) - Remote Code Execution
The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remo
60RISK
open ↗Exploit-DB✓ VexDay Proof
IRIX 5.3/6.2/6.3/6.4/6.5/6.5.11 - '/usr/lib/print/netprint' Local Privilege Escalation
Unknown vulnerability in netprint in IRIX 6.2, and possibly other versions, allows local users with lp privileges attack
23RISK
open ↗Exploit-DB✓ VexDay Proof
SCO OpenServer 5.0.x - StartX Weak XHost Permissions
SCO OpenServer 5.0.5 through 5.0.7 only supports Xauthority style access control when users log in using scologin, which
23RISK
open ↗Exploit-DB✓ VexDay Proof
SpyNet 6.5 Chat Server - Multiple Connection Denial of Service Vulnerabilities
Spytech Spynet Chat Server 6.5 allows a remote attacker to create a denial of service (crash) via a large number of conn
23RISK
open ↗Exploit-DB✓ VexDay Proof
IRIX 5.3/6.2/6.3/6.4/6.5/6.5.11 - '/usr/bin/lpstat' Local Overflow / Local Privilege Escalation
Buffer overflow in lpstat in IRIX 6.2 and 6.3 allows local users to gain root privileges via a long -n option.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Jason Rahaim MP3Mystic 1.0.x - Server Directory Traversal
Directory traversal vulnerability in MP3Mystic prior to 1.04b3 allows a remote attacker to download arbitrary files via
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 SP1/SP2 - isapi .printer Extension Overflow (1)
Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via
60RISK
open ↗Exploit-DB✓ VexDay Proof
T. Hauck Jana Server 1.45/1.46/2.0 - MS-DOS Device Name Denial of Service
T. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of service via a URL request
23RISK
open ↗Exploit-DB✓ VexDay Proof
T. Hauck Jana Server 1.45/1.46 - Hex Encoded Directory Traversal
T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..' (dot dot) attack wh
28RISK
open ↗Exploit-DB✓ VexDay Proof
Vixie Cron crontab 3.0 - Privilege Lowering Failure (1)
crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification ope
23RISK
open ↗Exploit-DB✓ VexDay Proof
Drummond Miles A1Stats 1.0 - 'a1disp2.cgi' Traversal Arbitrary File Read
Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary file
28RISK
open ↗Exploit-DB✓ VexDay Proof
Novell BorderManager Enterprise Edition 3.5 - Denial of Service
Remote attackers can cause a denial of service in Novell BorderManager 3.6 and earlier by sending TCP SYN flood to port
23RISK
open ↗Exploit-DB✓ VexDay Proof
Drummond Miles A1Stats 1.0 - 'a1disp3.cgi' Traversal Arbitrary File Read
Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary file
28RISK
open ↗Exploit-DB✓ VexDay Proof
Drummond Miles A1Stats 1.0 - 'a1disp4.cgi' Traversal Arbitrary File Read
Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary file
28RISK
open ↗Exploit-DB✓ VexDay Proof
ElectroSoft ElectroComm 1.0/2.0 - Denial of Service
ElectroSystems Engineering Inc. ElectroComm 2.0 and earlier allows a remote attacker to create a denial of service via l
23RISK
open ↗Exploit-DB✓ VexDay Proof
Hughes Technologies DSL_Vdns 1.0 - Denial of Service
Hughes Technologies Virtual DNS (VDNS) Server 1.0 allows a remote attacker to create a denial of service by connecting t
23RISK
open ↗Exploit-DB✓ VexDay Proof
cgiCentral WebStore 400 - Administrator Authentication Bypass
WSSecurity.pl in WebStore allows remote attackers to bypass authentication by providing the program with a filename that
23RISK
open ↗Exploit-DB✓ VexDay Proof
cgiCentral WebStore 400 - Arbitrary Command Execution
ws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via
23RISK
open ↗Exploit-DB✓ VexDay Proof
WU-FTPD 2.4.2/2.5 .0/2.6.0 - Remote Format String Stack Overwrite (3)
The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remo
60RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco Catalyst 2900 12.0 - '5.2'XU SNMP Empty UDP Packet Denial of Service
Cisco Catalyst 2900XL switch allows a remote attacker to create a denial of service via an empty UDP packet sent to port
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco HSRP - Denial of Service
Cisco Hot Standby Routing Protocol (HSRP) allows local attackers to cause a denial of service by spoofing HSRP packets.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 5.0 - '.printer' ISAPI Extension Buffer Overflow (2)
Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via
60RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.