Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,967GitHub PoC 13,264VulnCheck XDB 8,156Nuclei 4,201Metasploit 3,462✓ verified onlyrecentpopularrisk
3,462 exploits
Metasploit400
Adobe U3D CLODProgressiveMeshDeclaration Array Overrun
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x befor
100RISK
open ↗Metasploit400
Adobe U3D CLODProgressiveMeshDeclaration Array Overrun
Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might all
50RISK
open ↗Metasploit400
Adobe FlateDecode Stream Predictor 02 Integer Overflow
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows rem
100RISK
open ↗Metasploit500
HTTPDX h_handlepeer() Function Buffer Overflow
Stack-based buffer overflow in the h_handlepeer function in http.cpp in httpdx 1.4, and possibly 1.4.3, allows remote at
50RISK
open ↗Metasploit400
Adobe FlateDecode Stream Predictor 02 Integer Overflow
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows rem
100RISK
open ↗Metasploit500
AIX Calendar Manager Service Daemon (rpc.cmsd) Opcode 21 Buffer Overflow
Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through
50RISK
open ↗Metasploit300
Dopewars Denial of Service
Dopewars 1.5.12 allows remote attackers to cause a denial of service (segmentation fault) via a REQUESTJET message with
50RISK
open ↗Metasploit300
NTP.org ntpd Reserved Mode Denial of Service
ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and ba
30RISK
open ↗Metasploit300
Xlink FTP Client Buffer Overflow
Unspecified vulnerability in XLink Omni-NFS Enterprise allows remote attackers to execute arbitrary code via unspecified
50RISK
open ↗Metasploit400
Xlink FTP Server Buffer Overflow
Unspecified vulnerability in XLink Omni-NFS Enterprise allows remote attackers to execute arbitrary code via unspecified
50RISK
open ↗Metasploit500
InterSystems Cache UtilConfigHome.csp Argument Buffer Overflow
InterSystems Caché UtilConfigHome.csp Stack Buffer Overflow
63RISK
open ↗Metasploit600
Persits XUpload ActiveX MakeHttpRequest Directory Traversal
Directory traversal vulnerability in the Persits.XUpload.2 ActiveX control (XUpload.ocx) in HP LoadRunner 9.5 allows rem
50RISK
open ↗Metasploit200
EMC ApplicationXtender (KeyWorks) ActiveX Control Buffer Overflow
Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHel
23RISK
open ↗Metasploit600
Adobe RoboHelp Server 8 Arbitrary File Upload and Execute
Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows
60RISK
open ↗Metasploit500
Vermillion FTP Daemon PORT Command Memory Corruption
Vermillion FTP <= 1.31 Daemon PORT Command Memory Corruption
43RISK
open ↗Metasploit600
Zabbix Server Arbitrary Command Execution
The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via
50RISK
open ↗Metasploit600
Zabbix Agent net.tcp.listen Command Injection
The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote att
43RISK
open ↗Metasploit600
Symantec Altiris Deployment Solution ActiveX Control Arbitrary File Download and Execute
The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution
50RISK
open ↗Metasploit400
MS09-050 Microsoft SRV2.SYS SMB Negotiate ProcessID Function Table Dereference
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISK
open ↗Metasploit300
Microsoft IIS FTP Server LIST Stack Exhaustion
Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allo
60RISK
open ↗Metasploit500
MS09-053 Microsoft IIS FTP Server NLST Response Overflow
Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authen
60RISK
open ↗Metasploit600
osCommerce 2.2 Arbitrary PHP Code Execution
osCommerce <= 2.2 Admin File Manager Arbitrary PHP Code Execution
63RISK
open ↗Metasploit300
Oracle Document Capture 10g ActiveX Control Buffer Overflow
Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used
50RISK
open ↗Metasploit300
ProFTP 2.9 Banner Remote Buffer Overflow
Buffer overflow in Labtam ProFTP 2.9 allows remote FTP servers to cause a denial of service (application crash) or execu
43RISK
open ↗Metasploit500
ProShow Gold v4.0.2549 (PSH File) Stack Buffer Overflow
Multiple stack-based buffer overflows in Photodex ProShow Gold 4.0.2549 allow remote attackers to execute arbitrary code
50RISK
open ↗Metasploit500
Xenorate 2.50 (.xpl) Universal Local Buffer Overflow (SEH)
Xenorate <= 2.50 .xpl File Stack-Based Buffer Overflow
36RISK
open ↗Metasploit300
Oracle Secure Backup Authentication Bypass/Command Injection Vulnerability
Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers
50RISK
open ↗Metasploit400
VUPlayer CUE Buffer Overflow
Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in
50RISK
open ↗Metasploit400
VUPlayer M3U Buffer Overflow
Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long st
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.