Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,967GitHub PoC 13,264VulnCheck XDB 8,156Nuclei 4,201Metasploit 3,462✓ verified onlyrecentpopularrisk
3,462 exploits
Metasploit600
Samba "username map script" Command Execution
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open ↗Metasploit400
Trend Micro ServerProtect 5.58 EarthAgent.EXE Buffer Overflow
Multiple stack-based buffer overflows in Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 allow remote
60RISK
open ↗Metasploit400
Trend Micro ServerProtect 5.58 CreateBinding() Buffer Overflow
Multiple stack-based buffer overflows in Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 allow remote
60RISK
open ↗Metasploit300
Solaris srsexec Arbitrary File Reader
srsexec in Sun Remote Services (SRS) Net Connect Software Proxy Core package in Sun Solaris 10 does not enforce file per
38RISK
open ↗Metasploit400
IBM TPM for OS Deployment 5.1.0.x rembo.exe Buffer Overflow
The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly hand
50RISK
open ↗Metasploit200
CA BrightStor ArcServe Media Service Stack Buffer Overflow
Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Me
60RISK
open ↗Metasploit600
Apple QTJava toQTPointer() Arbitrary Memory Access
Apple QuickTime Java extensions (QTJava.dll), as used in Safari and other browsers, and when Java is enabled, allows rem
60RISK
open ↗Metasploit200
LANDesk Management Suite 8.7 Alert Service Buffer Overflow
Stack-based buffer overflow in the Alert Service (aolnsrvr.exe) in LANDesk Management Suite 8.7 allows remote attackers
60RISK
open ↗Metasploit500
MS07-029 Microsoft DNS RPC Service extractQuotedChar() Overflow (TCP)
Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 200
60RISK
open ↗Metasploit0
MS07-029 Microsoft DNS RPC Service extractQuotedChar() Overflow (SMB)
Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 200
60RISK
open ↗Metasploit300
Roxio CinePlayer ActiveX Control Buffer Overflow
Multiple stack-based buffer overflows in SonicDVDDashVRNav.dll in Roxio CinePlayer 3.2 allow remote attackers to execute
50RISK
open ↗Metasploit300
HP Mercury Quality Center ActiveX Control ProgColor Buffer Overflow
Stack-based buffer overflow in the SPIDERLib.Loader ActiveX control (Spider90.ocx) 9.1.0.4353 in TestDirector (TD) for M
50RISK
open ↗Metasploit500
Windows ANI LoadAniIcon() Chunk Size Stack Buffer Overflow (SMTP)
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RISK
open ↗Metasploit500
Windows ANI LoadAniIcon() Chunk Size Stack Buffer Overflow (SMTP)
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code
50RISK
open ↗Metasploit500
Windows ANI LoadAniIcon() Chunk Size Stack Buffer Overflow (HTTP)
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RISK
open ↗Metasploit300
WinDVD7 IASystemInfo.DLL ActiveX Control Buffer Overflow
Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio Ci
50RISK
open ↗Metasploit400
D-Link TFTP 1.0 Long Filename Buffer Overflow
Buffer overflow in D-Link TFTP Server 1.0 allows remote attackers to cause a denial of service (crash) via a long (1) GE
50RISK
open ↗Metasploit300
Mercury/32 4.01 IMAP LOGIN SEH Buffer Overflow
Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers
50RISK
open ↗Metasploit200
PHP 4 unserialize() ZVAL Reference Counter Overflow (Cookie)
Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long
50RISK
open ↗Metasploit500
Apache mod_jk 1.2.20 Buffer Overflow
Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apach
60RISK
open ↗Metasploit300
Wireshark chunked_encoding_dissector Function DOS
Wireshark before 0.99.6 allows remote attackers to cause a denial of service (crash) via a crafted chunked encoding in a
23RISK
open ↗Metasploit600
JBoss JMX Console Deployer Upload and Execute
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which
60RISK
open ↗Metasploit600
JBoss DeploymentFileRepository WAR Deployment (via JMXInvokerServlet)
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which
60RISK
open ↗Metasploit600
JBoss JMX Console Deployer Upload and Execute
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RISK
open ↗Metasploit400
Trend Micro ServerProtect 5.58 Buffer Overflow
Multiple stack-based buffer overflows in Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance F
60RISK
open ↗Metasploit400
Snort 2 DCE/RPC Preprocessor Buffer Overflow
Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire I
60RISK
open ↗Metasploit600
Sun Solaris Telnet Remote Authentication Bypass Vulnerability
Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterpr
60RISK
open ↗Metasploit300
Trend Micro OfficeScan Client ActiveX Control Buffer Overflow
Multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control in OfficeScanSetupIN
50RISK
open ↗Metasploit200
CA BrightStor ARCserve for Laptops and Desktops LGServer Buffer Overflow
Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1
60RISK
open ↗Metasploit300
NCTAudioFile2 v2.x ActiveX Control SetFormatLikeSample() Buffer Overflow
Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple prod
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.