Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,967GitHub PoC 13,264VulnCheck XDB 8,156Nuclei 4,201Metasploit 3,462✓ verified onlyrecentpopularrisk
3,462 exploits
Metasploit400
Adobe Flash Player ActionScript Launch Command Execution Vulnerability
Unspecified vulnerability in Adobe Flash Player for Linux 10.0.12.36, and 9.0.151.0 and earlier, allows remote attackers
60RISK
open ↗Metasploit500
Realtek Media Player Playlist Buffer Overflow
Stack-based buffer overflow in Realtek Media Player (aka Realtek Sound Manager, RtlRack, or rtlrack.exe) 1.15.0.0 allows
50RISK
open ↗Metasploit600
MS09-004 Microsoft SQL Server sp_replwritetovarbin Memory Corruption via SQL Injection
Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop
60RISK
open ↗Metasploit400
MS09-004 Microsoft SQL Server sp_replwritetovarbin Memory Corruption
Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop
60RISK
open ↗Metasploit300
MS08-078 Microsoft Internet Explorer Data Binding Memory Corruption
Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet
50RISK
open ↗Metasploit600
Sun Java Calendar Deserialization Privilege Escalation
The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; a
60RISK
open ↗Metasploit400
Cain and Abel RDP Buffer Overflow
Stack-based buffer overflow in the RDP protocol password decoder in Cain & Abel 4.9.23 and 4.9.24, and possibly earlier,
50RISK
open ↗Metasploit100
Microsoft Works 7 WkImgSrv.dll WKsPictureInterface() ActiveX Code Execution
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and
50RISK
open ↗Metasploit300
Avahi Source Port 0 DoS
The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 al
50RISK
open ↗Metasploit300
Pi3Web ISAPI DoS
Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi
43RISK
open ↗Metasploit600
Openfire Admin Console Authentication Bypass
Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows rem
60RISK
open ↗Metasploit400
VLC Media Player RealText Subtitle Overflow
Stack-based buffer overflow in VideoLAN VLC media player 0.9.x before 0.9.6 might allow user-assisted attackers to execu
50RISK
open ↗Metasploit600
Chilkat Crypt ActiveX WriteFile Unsafe Method
Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilka
50RISK
open ↗Metasploit100
DjVu DjVu_ActiveX_MSOffice.dll ActiveX ComponentBuffer Overflow
Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers
50RISK
open ↗Metasploit300
PacketTrap TFTP Server 2.2.5459.0 DoS
The TFTP server in PacketTrap pt360 Tool Suite PRO 2.0.3901.0 and earlier allows remote attackers to cause a denial of s
50RISK
open ↗Metasploit500
MS08-067 Microsoft Server Service Relative Path Stack Corruption
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISK
open ↗Metasploit400
TugZip 3.5 Zip File Parsing Buffer Overflow Vulnerability
Stack-based buffer overflow in TUGzip 3.5.0.0 allows remote attackers to denial of service (crash) or execute arbitrary
50RISK
open ↗Metasploit300
Victory FTP Server 5.0 LIST DoS
VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a crafted LIST command, which triggers a NU
50RISK
open ↗Metasploit300
Victory FTP Server 5.0 LIST DoS
VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a LIST command that starts with a "/\/" (fo
50RISK
open ↗Metasploit600
Opera historysearch XSS
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary w
50RISK
open ↗Metasploit300
Oracle DB SQL Injection via SYS.DBMS_CDC_PUBLISH.ALTER_AUTOLOG_CHANGE_SOURCE
Unspecified vulnerability in the Change Data Capture component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6 allow
18RISK
open ↗Metasploit300
Oracle DB SQL Injection via SYS.LT.MERGEWORKSPACE
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3,
50RISK
open ↗Metasploit300
Oracle DB SQL Injection via SYS.DBMS_CDC_IPUBLISH.ALTER_HOTLOG_INTERNAL_CSOURCE
Unspecified vulnerability in the Change Data Capture component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6 allow
18RISK
open ↗Metasploit400
VideoLAN VLC TiVo Buffer Overflow
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RISK
open ↗Metasploit600
Mantis manage_proj_page PHP Code Execution
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RISK
open ↗Metasploit600
Husdawg, LLC. System Requirements Lab ActiveX Unsafe Method
Husdawg, LLC Systems Requirements Lab 3, as used by Instant Expert Analysis, allows remote attackers to force the downlo
50RISK
open ↗Metasploit300
Microsoft Host Integration Server 2006 Command Execution Vulnerability
Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, whic
40RISK
open ↗Metasploit300
Titan FTP Server 6.26.630 SITE WHO DoS
Titan FTP Server 6.26 build 630 allows remote attackers to cause a denial of service (CPU consumption) via the SITE WHO
50RISK
open ↗Metasploit500
Sun Solaris sadmind adm_build_path() Buffer Overflow
Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allo
50RISK
open ↗Metasploit300
Oracle DB SQL Injection via SYS.LT.COMPRESSWORKSPACE
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3,
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.