Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,967GitHub PoC 13,264VulnCheck XDB 8,156Nuclei 4,201Metasploit 3,462✓ verified onlyrecentpopularrisk
3,462 exploits
Metasploit300
MS06-055 Microsoft Internet Explorer VML Fill Method Code Execution
Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet
50RISK
open ↗Metasploit200
Ipswitch WS_FTP Server 5.05 XMD5 Overflow
Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arb
60RISK
open ↗Metasploit600
TikiWiki jhot Remote Command Execution
Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execu
50RISK
open ↗Metasploit400
MaxDB WebDBM Database Parameter Overflow
Buffer overflow in SAP DB and MaxDB before 7.6.00.30 allows remote attackers to execute arbitrary code via a long databa
60RISK
open ↗Metasploit300
Cisco VPN Concentrator 3000 FTP Unauthorized Administrative Access
Multiple unspecified vulnerabilities in Cisco VPN 3000 series concentrators before 4.1, 4.1.x up to 4.1(7)L, and 4.7.x u
23RISK
open ↗Metasploit200
Texas Imperial Software WFTPD 3.23 SIZE Overflow
Buffer overflow in WFTPD Server 3.23 allows remote attackers to execute arbitrary code via long SIZE commands.
50RISK
open ↗Metasploit400
MS06-040 Microsoft Server Service NetpwPathCanonicalize Overflow
Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote a
60RISK
open ↗Metasploit400
Apple iOS MobileSafari LibTIFF Buffer Overflow
Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and othe
50RISK
open ↗Metasploit300
McAfee Subscription Manager Stack Buffer Overflow
Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite
50RISK
open ↗Metasploit400
Apple iOS MobileMail LibTIFF Buffer Overflow
Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and othe
50RISK
open ↗Metasploit200
Easy File Sharing FTP Server 2.0 PASS Overflow
Stack-based buffer overflow in EFS Software Easy File Sharing FTP Server 2.0 allows remote attackers to execute arbitrar
50RISK
open ↗Metasploit500
Apache Module mod_rewrite LDAP Protocol Buffer Overflow
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and o
60RISK
open ↗Metasploit200
eIQNetworks ESA Topology DELETEDEVICE Overflow
Multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) before 2.5.0, as used in product
60RISK
open ↗Metasploit300
Mozilla Suite/Firefox Navigator Object Code Execution
Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by chang
60RISK
open ↗Metasploit200
eIQNetworks ESA License Manager LICMGR_ADDLICENSE Overflow
Multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) before 2.5.0, as used in product
60RISK
open ↗Metasploit200
FileCopa FTP Server Pre 18 Jul Version
Buffer overflow in FileCOPA FTP Server before 1.01 released on 18th July 2006, allows remote authenticated attackers to
50RISK
open ↗Metasploit200
McAfee ePolicy Orchestrator / ProtectionPilot Overflow
Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attac
60RISK
open ↗Metasploit300
MS06-057 Microsoft Internet Explorer WebViewFolderIcon setSlice() Overflow
Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service
68RISK
open ↗Metasploit300
Microsoft SRV.SYS Mailslot Write Corruption
The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a de
60RISK
open ↗Metasploit500
SIPfoundry sipXezPhone 0.35a CSeq Field Overflow
Buffer overflow in SIPfoundry sipXtapi released before 20060324 allows remote attackers to execute arbitrary code via a
50RISK
open ↗Metasploit500
SIPfoundry sipXphone 2.6.0.27 CSeq Buffer Overflow
Buffer overflow in SIPfoundry sipXtapi released before 20060324 allows remote attackers to execute arbitrary code via a
50RISK
open ↗Metasploit500
AIM Triton 1.0.4 CSeq Buffer Overflow
Buffer overflow in SIPfoundry sipXtapi released before 20060324 allows remote attackers to execute arbitrary code via a
50RISK
open ↗Metasploit300
Webmin File Disclosure
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RISK
open ↗Metasploit200
Private Wire Gateway Buffer Overflow
Buffer overflow in the Online Registration Facility for Algorithmic Research PrivateWire VPN software up to 3.7 allows r
50RISK
open ↗Metasploit200
MS06-025 Microsoft RRAS Service Overflow
Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Serve
60RISK
open ↗Metasploit400
MS06-025 Microsoft RRAS Service RASMAN Registry Overflow
Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Serve
60RISK
open ↗Metasploit200
Cesar FTP 0.99g MKD Command Buffer Overflow
Stack-based buffer overflow in CesarFTP 0.99g and earlier allows remote attackers to cause a denial of service (applicat
50RISK
open ↗Metasploit400
Qbik WinGate WWW Proxy Server URL Processing Overflow
Stack-based buffer overflow in the WWW Proxy Server of Qbik WinGate 6.1.1.1077 allows remote attackers to cause a denial
60RISK
open ↗Metasploit600
SpamAssassin spamd Remote Command Execution
SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute a
60RISK
open ↗Metasploit400
Symantec Remote Management Buffer Overflow
Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitr
60RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.