Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,967GitHub PoC 13,264VulnCheck XDB 8,156Nuclei 4,201Metasploit 3,462✓ verified onlyrecentpopularrisk
3,462 exploits
Metasploit300
Novell iPrint Client ActiveX Control ExecuteRequest Buffer Overflow
Stack-based buffer overflow in the Novell iPrint Control ActiveX control in ienipp.ocx in Novell iPrint Client before 4.
50RISK
open ↗Metasploit400
Now SMS/MMS Gateway Buffer Overflow
Multiple stack-based buffer overflows in Now SMS/MMS Gateway 2007.06.27 and earlier allow remote attackers to execute ar
50RISK
open ↗Metasploit400
Adobe Collab.collectEmailInfo() Buffer Overflow
Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code
100RISK
open ↗Metasploit400
Adobe util.printf() Buffer Overflow
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary c
100RISK
open ↗Metasploit400
Adobe util.printf() Buffer Overflow
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary c
100RISK
open ↗Metasploit300
UltraVNC 1.0.2 Client (vncviewer.exe) Buffer Overflow
Stack-based buffer overflow in the ClientConnection::NegotiateProtocolVersion function in vncviewer/ClientConnection.cpp
50RISK
open ↗Metasploit400
WinComLPD Buffer Overflow
Integer overflow in the remote administration protocol processing in Client Software WinCom LPD Total 3.0.2.623 and earl
50RISK
open ↗Metasploit400
SAP SAPLPD 6.28 Buffer Overflow
Buffer overflow in SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to
60RISK
open ↗Metasploit300
Facebook Photo Uploader 4 ActiveX Control Buffer Overflow
Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to
50RISK
open ↗Metasploit600
Coppermine Photo Gallery picEditor.php Command Execution
include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing
50RISK
open ↗Metasploit300
Persits XUpload ActiveX AddFile Buffer Overflow
Stack-based buffer overflow in the Persits.XUpload.2 ActiveX control in XUpload.ocx 3.0.0.4 and earlier in Persits XUplo
43RISK
open ↗Metasploit200
Streamcast HTTP User-Agent Buffer Overflow
Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or
50RISK
open ↗Metasploit300
Winamp Ultravox Streaming Metadata (in_mp3.dll) Buffer Overflow
Multiple stack-based buffer overflows in in_mp3.dll in Winamp 5.21, 5.5, and 5.51 allow remote attackers to execute arbi
50RISK
open ↗Metasploit300
SAP MaxDB cons.exe Remote Command Injection
SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell me
60RISK
open ↗Metasploit200
XTACACSD report() Buffer Overflow
Buffer overflow in the report function in xtacacsd 4.1.2 and earlier allows remote attackers to execute arbitrary code v
43RISK
open ↗Metasploit400
MySQL yaSSL SSL Hello Message Buffer Overflow
Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attacke
60RISK
open ↗Metasploit200
MySQL yaSSL SSL Hello Message Buffer Overflow
Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attacke
60RISK
open ↗Metasploit400
HP LoadRunner 9.0 ActiveX AddFolder Buffer Overflow
Buffer overflow in the XUpload.ocx ActiveX control in Persits Software XUpload 2.1.0.1, and probably other versions befo
50RISK
open ↗Metasploit300
IBM Lotus Domino Web Access Upload Module Buffer Overflow
Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, in
50RISK
open ↗Metasploit300
Appian Enterprise Business Suite 5.6 SP1 DoS
Unspecified vulnerability in Appian Enterprise Business Process Management (BPM) Suite 5.6 SP1 allows remote attackers t
50RISK
open ↗Metasploit600
Apple OS X Software Update Command Execution
Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a man-in-the-middle (
43RISK
open ↗Metasploit300
MS07-064 Microsoft DirectX DirectShow SAMI Buffer Overflow
Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for
50RISK
open ↗Metasploit400
MS07-065 Microsoft Message Queueing Service DNS Name Path Overflow
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Window
50RISK
open ↗Metasploit500
BadBlue 2.72b PassThru Buffer Overflow
Stack-based buffer overflow in the PassThru functionality in ext.dll in BadBlue 2.72b and earlier allows remote attacker
50RISK
open ↗Metasploit500
HP OpenView Network Node Manager OpenView5.exe CGI Buffer Overflow
Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allow remote att
50RISK
open ↗Metasploit400
ACDSee XPM File Section Buffer Overflow
Stack-based buffer overflow in the ID_X.apl plugin in ACDSee 9.0 Build 108, Pro 8.1 Build 99, and Photo Editor 4.0 Build
50RISK
open ↗Metasploit200
MacOS X QuickTime RTSP Content-Type Overflow
Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac
50RISK
open ↗Metasploit300
Apple QuickTime 7.3 RTSP Response Header Buffer Overflow
Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac
50RISK
open ↗Metasploit300
WinZip FileView (WZFILEVIEW.FileViewCtrl.61) ActiveX Buffer Overflow
The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before buil
50RISK
open ↗Metasploit300
SonicWall SSL-VPN NetExtender ActiveX Control Buffer Overflow
Stack-based buffer overflow in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.