Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,967GitHub PoC 13,264VulnCheck XDB 8,156Nuclei 4,201Metasploit 3,462✓ verified onlyrecentpopularrisk
3,462 exploits
Metasploit600
Oracle BeeHive 2 voice-servlet processEvaluation() Vulnerability
Unspecified vulnerability in the Services for Beehive component in Oracle Fusion Middleware 2.0.1.0, 2.0.1.1, 2.0.1.2, 2
60RISK
open ↗Metasploit300
MS11-038 Microsoft Office Excel Malformed OBJ Record Handling Overflow
Stack-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML F
60RISK
open ↗Metasploit500
HP OpenView Network Node Manager ovwebsnmpsrv.exe Unrecognized Option Buffer Overflow
Buffer overflow in the error handling functionality in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.5
50RISK
open ↗Metasploit300
Easy CD-DA Recorder PLS Buffer Overflow
Stack-based buffer overflow in D.R. Software Audio Converter 8.1, 2007, and 8.05 allows remote attackers to execute arbi
50RISK
open ↗Metasploit300
Adobe Flash Player "newfunction" Invalid Pointer Use
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrob
100RISK
open ↗Metasploit300
Adobe Flash Player "newfunction" Invalid Pointer Use
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrob
100RISK
open ↗Metasploit200
MacOS X EvoCam HTTP GET Buffer Overflow
Buffer overflow in the web server for EvoLogical EvoCam 3.6.6 and 3.6.7 allows remote attackers to execute arbitrary cod
50RISK
open ↗Metasploit600
Outlook ATTACH_BY_REF_ONLY File Execution
Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_
50RISK
open ↗Metasploit600
Outlook ATTACH_BY_REF_RESOLVE File Execution
Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_
50RISK
open ↗Metasploit300
SolarWinds TFTP Server 10.4.0.10 Denial of Service
SolarWinds TFTP Server 10.4.0.10 allows remote attackers to cause a denial of service (no new connections) via a crafted
50RISK
open ↗Metasploit500
CommuniCrypt Mail 1.16 SMTP ActiveX Stack Buffer Overflow
CommuniCrypt Mail <= 1.16 ANSMTP/AOSMTP ActiveX Control Buffer Overflow
36RISK
open ↗Metasploit500
HP OpenView Network Node Manager getnnmdata.exe (Hostname) CGI Buffer Overflow
Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows r
50RISK
open ↗Metasploit500
HP OpenView Network Node Manager getnnmdata.exe (ICount) CGI Buffer Overflow
Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows r
50RISK
open ↗Metasploit500
HP OpenView Network Node Manager getnnmdata.exe (MaxAge) CGI Buffer Overflow
Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows r
60RISK
open ↗Metasploit500
HP OpenView Network Node Manager snmpviewer.exe Buffer Overflow
Stack-based buffer overflow in the doLoad function in snmpviewer.exe in HP OpenView Network Node Manager (OV NNM) 7.01,
50RISK
open ↗Metasploit600
HP Mercury LoadRunner Agent magentproc.exe Remote Command Execution
Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before 9.50 allows remote
60RISK
open ↗Metasploit400
Microsoft Office Visio VISIODWG.DLL DXF File Handling Vulnerability
Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to ex
50RISK
open ↗Metasploit600
Maple Maplet File Creation and Command Execution
Maple <= v13 Maplet File Creation and Command Execution
36RISK
open ↗Metasploit600
JBoss Java Class DeploymentFileRepository WAR Deployment
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RISK
open ↗Metasploit600
JBoss JMX Console Beanshell Deployer WAR Upload and Deployment
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RISK
open ↗Metasploit300
Oracle DB SQL Injection via SYS.DBMS_CDC_PUBLISH.DROP_CHANGE_SOURCE
Unspecified vulnerability in the Change Data Capture component in Oracle Database 9.2.0.8 and 9.2.0.8DV allows remote au
23RISK
open ↗Metasploit300
Xftp FTP Client 3.0 PWD Remote Buffer Overflow
Xftp FTP Client <= 3.0 PWD Response Buffer Overflow
43RISK
open ↗Metasploit400
AgentX++ Master AgentX::receive_agentx Stack Buffer Overflow
Stack-based buffer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Ser
50RISK
open ↗Metasploit300
MS10-026 Microsoft MPEG Layer-3 Audio Stack Based Overflow
Multiple stack-based buffer overflows in the MPEG Layer-3 audio codecs in Microsoft Windows 2000 SP4, XP SP2 and SP3, Se
50RISK
open ↗Metasploit500
Windows Media Services ConnectFunnel Stack Buffer Overflow
Stack-based buffer overflow in nsum.exe in the Windows Media Unicast Service in Media Services for Microsoft Windows 200
50RISK
open ↗Metasploit300
Trellian FTP Client 3.01 PASV Remote Buffer Overflow
Stack-based buffer overflow in Trellian FTP client 3.01, including 3.1.3.1789, allows remote attackers to execute arbitr
50RISK
open ↗Metasploit600
Sun Java Web Start Plugin Command Line Argument Injection
Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Toolkit in Java 6 U
50RISK
open ↗Metasploit600
Sun Java Web Start Plugin Command Line Argument Injection
Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6
50RISK
open ↗Metasploit500
EasyFTP Server MKD Command Stack Buffer Overflow
EasyFTP MKD Command buffer overflow
28RISK
open ↗Metasploit600
AjaXplorer checkInstall.php Remote Command Execution
AjaXplorer < 2.6 checkInstall.php Unauthenticated RCE
63RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.