Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,534GitHub PoC 13,654VulnCheck XDB 8,213Nuclei 4,218Metasploit 3,464✓ verified onlyrecentpopularrisk
24,443 exploits
Exploit-DB✓ VexDay Proof
Advantech Webaccess Dashboard Viewer - Arbitrary File Upload (Metasploit)
Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 7 < 10 / 2008 < 2012 (x86/x64) - Local Privilege Escalation (MS16-032)
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 7 < 10 / 2008 < 2012 R2 (x86/x64) - Local Privilege Escalation (MS16-032) (PowerShell)
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RISK
open ↗Exploit-DB
Sony Playstation 4 (PS4) < 2.50 - WebKit Code Execution (PoC)
Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox
35RISK
open ↗Exploit-DB
Symantec Brightmail 10.6.0-7 - LDAP Credentials Disclosure (Metasploit)
The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discove
38RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - DrawMenuBarTemp Wild-Write (MS16-039)
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, W
23RISK
open ↗Exploit-DB
modified eCommerce Shopsoftware 2.0.0.0 rev 9678 - Blind SQL Injection
Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, when the easybill-modul
23RISK
open ↗Exploit-DB
Novell ServiceDesk - (Authenticated) Arbitrary File Upload (Metasploit)
Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remot
50RISK
open ↗Exploit-DB✓ VexDay Proof
Exim - 'perl_startup' Local Privilege Escalation (Metasploit)
Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.
38RISK
open ↗Exploit-DB✓ VexDay Proof
AirOS 6.x - Arbitrary File Upload
Ubiquiti airOS HTTP(S) unauthenticated arbitrary file upload
85RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Excel - Out-of-Bounds Read Code Execution (MS16-042)
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Word 2016 for Mac, Office Compa
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 9/10/11 - 'CDOMStringDataList::InitFromString' Out-of-Bounds Read (MS15-112)
Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via
28RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Application Testing Suite (ATS) 12.4.0.2.0 - Authentication Bypass / Arbitrary File Upload
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Application Testing Suite (ATS) 12.4.0.2.0 - Authentication Bypass / Arbitrary File Upload
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RISK
open ↗Exploit-DB
Axis Network Cameras - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.
35RISK
open ↗Exploit-DB✓ VexDay Proof
Google Android - IMemory Native Interface is Insecure for IPC Use
libs/binder/IMemory.cpp in the IMemory Native Interface in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.
23RISK
open ↗Exploit-DB
Novell ServiceDesk 6.5/7.0.3/7.1.0 - Multiple Vulnerabilities
Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request
23RISK
open ↗Exploit-DB
Novell ServiceDesk 6.5/7.0.3/7.1.0 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus Novell Service Desk before 7.2 allow remote authentic
23RISK
open ↗Exploit-DB✓ VexDay Proof
Google Android - IOMX 'getConfig'/'getParameter' Information Disclosure
media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x befo
23RISK
open ↗Exploit-DB
Novell ServiceDesk 6.5/7.0.3/7.1.0 - Multiple Vulnerabilities
LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows rem
23RISK
open ↗Exploit-DB
Novell ServiceDesk 6.5/7.0.3/7.1.0 - Multiple Vulnerabilities
Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remot
50RISK
open ↗Exploit-DB
Apple Intel HD 3000 Graphics Driver 10.0.0 - Local Privilege Escalation
The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary co
23RISK
open ↗Exploit-DB✓ VexDay Proof
ExaGrid - Known SSH Key and Default Password (Metasploit)
ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, whic
60RISK
open ↗Exploit-DB✓ VexDay Proof
ExaGrid - Known SSH Key and Default Password (Metasploit)
ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and
60RISK
open ↗Exploit-DB
Panda Endpoint Administration Agent < 7.50.00 - Local Privilege Escalation
Panda Endpoint Administration Agent before 7.50.00, as used in Panda Security for Business products for Windows, uses a
23RISK
open ↗Exploit-DB
Linux Kernel (x86) - Disable ASLR by Setting the RLIMIT_STACK Resource to Unlimited
The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize t
23RISK
open ↗Exploit-DB
Panda Security URL Filtering < 4.3.1.9 - Local Privilege Escalation
Panda Security URL Filtering before 4.3.1.9 uses a weak ACL for the "Panda Security URL Filtering" directory and install
23RISK
open ↗Exploit-DB
Microsoft Windows Kernel - 'win32k.sys' Local Privilege Escalation (MS14-058)
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - MSHTML!CSVGHelpers::SetAttributeStringAndPointer Use-After-Free (MS16-023)
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a
35RISK
open ↗Exploit-DB
Hexchat IRC Client 2.11.0 - Directory Traversal
Directory traversal vulnerability in the client in HexChat 2.11.0 allows remote IRC servers to read or modify arbitrary
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.