Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,967GitHub PoC 13,264VulnCheck XDB 8,156Nuclei 4,201Metasploit 3,462✓ verified onlyrecentpopularrisk
3,462 exploits
Metasploit500
HTTPDX tolog() Function Format String Vulnerability
Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remo
50RISK
open ↗Metasploit600
AwingSoft Winds3D Player 3.5 SceneURL Download and Execute
The Awingsoft Awakening Winds3D Viewer plugin 3.5.0.9 allows remote attackers to execute arbitrary programs via a SceneU
43RISK
open ↗Metasploit400
MS09-067 Microsoft Excel Malformed FEATHEADER Record Vulnerability
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Conv
100RISK
open ↗Metasploit300
Microsoft Windows EOT Font Table Directory Integer Overflow
win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse fon
50RISK
open ↗Metasploit600
Apache Tomcat Manager Application Deployer Authenticated Code Execution
HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers t
50RISK
open ↗Metasploit600
Apache Tomcat Manager Application Deployer Authenticated Code Execution
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a
60RISK
open ↗Metasploit600
Apache Tomcat Manager Application Deployer Authenticated Code Execution
HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to exe
60RISK
open ↗Metasploit600
Apache Tomcat Manager Authenticated Upload Code Execution
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which all
60RISK
open ↗Metasploit600
Apache Tomcat Manager Authenticated Upload Code Execution
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a
60RISK
open ↗Metasploit600
Apache Tomcat Manager Authenticated Upload Code Execution
HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers t
50RISK
open ↗Metasploit600
Apache Tomcat Manager Authenticated Upload Code Execution
The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN acc
50RISK
open ↗Metasploit600
Apache Tomcat Manager Application Deployer Authenticated Code Execution
IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial
50RISK
open ↗Metasploit600
Apache Tomcat Manager Authenticated Upload Code Execution
IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial
50RISK
open ↗Metasploit600
Apache Tomcat Manager Authenticated Upload Code Execution
HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to exe
60RISK
open ↗Metasploit600
Apache Tomcat Manager Application Deployer Authenticated Code Execution
The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN acc
50RISK
open ↗Metasploit600
Apache Tomcat Manager Application Deployer Authenticated Code Execution
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which all
60RISK
open ↗Metasploit400
IBM Tivoli Storage Manager Express CAD Service Buffer Overflow
Stack-based buffer overflow in the client acceptor daemon (CAD) scheduler in the client in IBM Tivoli Storage Manager (T
50RISK
open ↗Metasploit500
Sun Java JRE AWT setDiffICM Buffer Overflow
Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment
50RISK
open ↗Metasploit500
IBM Tivoli Storage Manager Express RCA Service Buffer Overflow
Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM
60RISK
open ↗Metasploit500
Sun Java JRE getSoundbank file:// URI Buffer Overflow
Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, J
60RISK
open ↗Metasploit200
Hewlett-Packard Power Manager Administration Buffer Overflow
Stack-based buffer overflow in the login form in the management web server in HP Power Manager allows remote attackers t
60RISK
open ↗Metasploit300
Symantec Altiris Deployment Solution ActiveX Control Buffer Overflow
Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilitie
50RISK
open ↗Metasploit300
Symantec ConsoleUtilities ActiveX Control Buffer Overflow
Stack-based buffer overflow in the BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control 6
50RISK
open ↗Metasploit200
CA eTrust PestPatrol ActiveX Control Buffer Overflow
Stack-based buffer overflow in the PestPatrol ActiveX control (ppctl.dll) 5.6.7.9 in CA eTrust PestPatrol allows remote
50RISK
open ↗Metasploit400
Rhinosoft Serv-U Session Cookie Buffer Overflow
Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other ver
60RISK
open ↗Metasploit400
SafeNet SoftRemote GROUPNAME Buffer Overflow
Stack-based buffer overflow in SafeNet SoftRemote 10.8.5 (Build 2) and 10.3.5 (Build 6), and possibly other versions bef
38RISK
open ↗Metasploit200
UFO: Alien Invasion IRC Client Buffer Overflow
UFO: Alien Invasion <= 2.2.1 IRC Client Buffer Overflow
43RISK
open ↗Metasploit200
UFO: Alien Invasion IRC Client Buffer Overflow
UFO: Alien Invasion <= 2.2.1 IRC Client Buffer Overflow
43RISK
open ↗Metasploit300
Eureka Email 2.2q ERR Remote Buffer Overflow
Stack-based buffer overflow in Eureka Email 2.2q allows remote POP3 servers to execute arbitrary code via a long error m
50RISK
open ↗Metasploit500
Oracle 10gR2 TNS Listener AUTH_SESSKEY Buffer Overflow
Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10.2.0.4 allows remote
60RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.