Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,832GitHub PoC 14,991VulnCheck XDB 8,829Nuclei 4,357Metasploit 3,489✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB✓ VexDay Proof
Apache 1.2.5/1.3.1 / UnityMail 2.0 - MIME Header Denial of Service
Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache 1.2.5/1.3.1 / UnityMail 2.0 - MIME Header Denial of Service
UnityMail allows remote attackers to conduct a denial of service via a large number of MIME headers.
23RISK
open ↗Exploit-DB✓ VexDay Proof
SGI IRIX 6.4 - 'ioconfig' Local Privilege Escalation
ioconfig on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Netscape Messaging Server 3.55 & University of Washington imapd 10.234 - Remote Buffer Overflow
Arbitrary command execution via IMAP buffer overflow in authenticate command.
28RISK
open ↗Exploit-DB✓ VexDay Proof
Sun Solaris 2.6 - power management
Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until after the sys-suspe
23RISK
open ↗Exploit-DB✓ VexDay Proof
HP JetAdmin 1.0.9 Rev. D - symlink
HP JetAdmin D.01.09 on Solaris allows local users to change the permissions of arbitrary files via a symlink attack on t
23RISK
open ↗Exploit-DB✓ VexDay Proof
Slackware Linux 3.5 - '/etc/group' Local Privilege Escalation
login in Slackware Linux 3.2 through 3.5 does not properly check for an error when the /etc/group file is missing, which
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ray Chan WWW Authorization Gateway 0.1 - Command Execution
Ray Chan WWW Authorization Gateway 0.1 CGI program allows remote attackers to execute arbitrary commands via shell metac
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ralf S. Engelschall ePerl 2.2.12 - Handling of ISINDEX Query
ePerl 2.2.12 allows remote attackers to read arbitrary files and possibly execute certain commands by specifying a full
23RISK
open ↗Exploit-DB✓ VexDay Proof
Metainfo Sendmail 2.0/2.5 / MetaIP 3.1 - Upload / Execute Read Scripts
MetaInfo MetaWeb web server allows users to upload, execute, and read scripts.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.0/2.1 - Send a SIGIO Signal To Any Process
Linux 2.0.34 does not properly prevent users from sending SIGIO signals to arbitrary processes, which allows local users
23RISK
open ↗Exploit-DB✓ VexDay Proof
NetBSD 1.3.2 / SGI IRIX 6.5.1 - 'at(1)' Read File
The at program in IRIX 6.2 and NetBSD 1.3.2 and earlier allows local users to read portions of arbitrary files by submit
23RISK
open ↗Exploit-DB✓ VexDay Proof
Qualcomm qpopper 2.4 - POP Server Buffer Overflow (2)
Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long
53RISK
open ↗Exploit-DB✓ VexDay Proof
Qualcomm qpopper 2.4 - POP Server Buffer Overflow (1)
Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long
53RISK
open ↗Exploit-DB✓ VexDay Proof
RedHat Linux 4.2 / SGI IRIX 6.3 / Solaris 2.6 - 'mailx' (2)
Buffer overflow in SGI IRIX mailx program.
23RISK
open ↗Exploit-DB✓ VexDay Proof
textcounter.pl 1.2 - Arbitrary Command Execution
The textcounter.pl by Matt Wright allows remote attackers to execute arbitrary commands via shell metacharacters.
28RISK
open ↗Exploit-DB✓ VexDay Proof
RedHat Linux 4.2 / SGI IRIX 6.3 / Solaris 2.6 - 'mailx' (1)
Buffer overflow in SGI IRIX mailx program.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cheyenne Inoculan for Windows NT 4.0 - Share
Cheyenne InocuLAN Anti-Virus Server in Inoculan 4.0 before Service Pack 2 creates an update directory with "EVERYONE FUL
23RISK
open ↗Exploit-DB✓ VexDay Proof
AMD K6 Processor - Denial of Service
Bug in AMD K6 processor on Linux 2.0.x and 2.1.x kernels allows local users to cause a denial of service (crash) via a p
23RISK
open ↗Exploit-DB✓ VexDay Proof
Allaire ColdFusion Server 4.0.1 - 'CFCRYPT.EXE' Decrypt Pages
The ColdFusion CFCRYPT program for encrypting CFML templates has weak encryption, allowing attackers to decrypt the temp
23RISK
open ↗Exploit-DB✓ VexDay Proof
Fred N. van Kempen dip 3.3.7 - Local Buffer Overflow (1)
The dip program on many Linux systems allows local users to gain root access via a buffer overflow.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Fred N. van Kempen dip 3.3.7 - Local Buffer Overflow (2)
The dip program on many Linux systems allows local users to gain root access via a buffer overflow.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Debian suidmanager 0.18 - Command Execution
suidexec in suidmanager 0.18 on Debian 2.0 allows local users to gain root privileges by specifying a malicious program
23RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris 7.0 - 'ufsdump' Local Buffer Overflow (1)
Solaris ufsrestore buffer overflow.
41RISK
open ↗Exploit-DB✓ VexDay Proof
BSD 'lpr' 2000.05.07/0.48/0.72 / lpr-ppd 0.72 - Local Buffer Overflow (2)
Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and poss
23RISK
open ↗Exploit-DB✓ VexDay Proof
BSD 'lpr' 2000.05.07/0.48/0.72 / lpr-ppd 0.72 - Local Buffer Overflow (1)
Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and poss
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.0.33 - IP Fragment Overlap
IPChains in Linux kernels 2.2.10 and earlier does not reassemble IP fragments before checking the header information, wh
23RISK
open ↗Exploit-DB✓ VexDay Proof
Qualcomm Eudora Internet Mail Server 1.2 - Remote Buffer Overflow
Buffer overflow in Eudora Internet Mail Server (EIMS) 2.01 and earlier on MacOS systems allows remote attackers to cause
23RISK
open ↗Exploit-DB✓ VexDay Proof
ISC BIND 4.9.7 -T1B - named SIGINT / SIGIOT Symlink
named in ISC BIND 4.9 and 8.1 allows local users to destroy files via a symlink attack on (1) named_dump.db when root ki
23RISK
open ↗Exploit-DB✓ VexDay Proof
ISC BIND (Linux/BSD) - Remote Buffer Overflow (1)
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.