Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,497GitHub PoC 13,627VulnCheck XDB 8,198Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
24,443 exploits
Exploit-DB
WordPress Plugin Mail Masta 1.0 - SQL Injection
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/list
23RISK
open ↗Exploit-DB
Netgear DGN2200v1/v2/v3/v4 - 'ping.cgi' Remote Command Execution
ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitra
90RISK
open ↗Exploit-DB✓ VexDay Proof
Artifex MuPDF mujstest 1.10a - Null Pointer Dereference
Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, Inc. MuPDF 1.10a allows remote attackers t
23RISK
open ↗Exploit-DB✓ VexDay Proof
dotCMS 3.6.1 - Blind Boolean SQL Injection
An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessib
23RISK
open ↗Exploit-DB✓ VexDay Proof
Geutebruck 5.02024 G-Cam/EFD-2250 - 'testaction.cgi' Remote Command Execution (Metasploit)
An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD
28RISK
open ↗Exploit-DB✓ VexDay Proof
Geutebruck 5.02024 G-Cam/EFD-2250 - 'testaction.cgi' Remote Command Execution (Metasploit)
An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authenticatio
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'gdi32.dll' EMR_SETDIBITSTODEVICE Heap Out-of-Bounds Reads / Memory Disclosure
gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
45RISK
open ↗Exploit-DB✓ VexDay Proof
GOM Player 2.3.10.5266 - '.fpx' Denial of Service
GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspeci
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco ASA - WebVPN CIFS Handling Buffer Overflow
A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software,
28RISK
open ↗Exploit-DB
OpenText Documentum D2 - Remote Code Execution
OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a craf
28RISK
open ↗Exploit-DB✓ VexDay Proof
NVIDIA Driver 375.70 - Buffer Overflow in Command Buffer Submission
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) implem
23RISK
open ↗Exploit-DB✓ VexDay Proof
NVIDIA Driver 375.70 - DxgkDdiEscape 0x100008b Out-of-Bounds Read/Write
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handle
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Edge - TypedArray.sort Use-After-Free (MS16-145)
The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (m
45RISK
open ↗Exploit-DB✓ VexDay Proof
Google Android - Inter-process munmap in android.util.MemoryIntArray
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Google Android - android.util.MemoryIntArray Ashmem Race Conditions
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
23RISK
open ↗Exploit-DB
F5 BIG-IP 11.6 SSL Virtual Server - 'Ticketbleed' Memory Disclosure
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may
45RISK
open ↗Exploit-DB✓ VexDay Proof
ntfs-3g - Unsanitized modprobe Environment Privilege Escalation
ntfs-3g: Modprobe influence vulnerability via environment variables
56RISK
open ↗Exploit-DB
Linux Kernel 3.10.0 (CentOS 7) - Denial of Service
The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fa
28RISK
open ↗Exploit-DB✓ VexDay Proof
HP Smart Storage Administrator 2.30.6.0 - Remote Command Injection (Metasploit)
A Remote Arbitrary Code Execution vulnerability in HPE Smart Storage Administrator version before v2.60.18.0 was found.
28RISK
open ↗Exploit-DB
F5 BIG-IP SSL Virtual Server - 'Ticketbleed' Memory Disclosure
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may
45RISK
open ↗Exploit-DB
Node.JS - 'node-serialize' Remote Code Execution
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISK
open ↗Exploit-DB
OpenBSD HTTPd < 6.0 - Memory Exhaustion Denial of Service
httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for
28RISK
open ↗Exploit-DB
CUPS < 2.0.3 - Remote Command Execution
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-va
28RISK
open ↗Exploit-DB
ntfs-3g (Debian 9) - Local Privilege Escalation
ntfs-3g: Modprobe influence vulnerability via environment variables
56RISK
open ↗Exploit-DB✓ VexDay Proof
Apple WebKit - Type Confusion in RenderBox with Accessibility Enabled
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple WebKit - 'HTMLFormElement::reset()' Use-After Free
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple WebKit - 'HTMLKeygenElement' Type Confusion
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISK
open ↗Exploit-DB
AlienVault OSSIM/USM < 5.3.1 - Remote Code Execution (Metasploit)
PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vuln
23RISK
open ↗Exploit-DB
PHP PEAR 1.10.1 - Arbitrary File Download
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenam
28RISK
open ↗Exploit-DB✓ VexDay Proof
Netgear Routers - Password Disclosure
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.