Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,534GitHub PoC 13,654VulnCheck XDB 8,213Nuclei 4,218Metasploit 3,464✓ verified onlyrecentpopularrisk
24,443 exploits
Exploit-DB
PHPLib < 7.4 - SQL Injection
SQL injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a allows remote attackers to execute
23RISK
open ↗Exploit-DB
PHPLib < 7.4 - SQL Injection
Eval injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a, when index.php3 from the PHPLib d
23RISK
open ↗Exploit-DB
DropBearSSHD 2015.71 - Command Injection
CRLF injection vulnerability in Dropbear SSH before 2016.72 allows remote authenticated users to bypass intended shell-c
28RISK
open ↗Exploit-DB
Schneider Electric SBO / AS - Multiple Vulnerabilities
Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows
28RISK
open ↗Exploit-DB
Gallery 2 < 2.0.2 - Multiple Vulnerabilities
Directory traversal vulnerability in the session handling class (GallerySession.class) in Gallery 2 up to 2.0.2 allows r
23RISK
open ↗Exploit-DB
Gallery 2 < 2.0.2 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in Gallery 2 up to 2.0.2 allows remote attackers to inject arbitrary web script
23RISK
open ↗Exploit-DB✓ VexDay Proof
ATutor 2.2.1 - SQL Injection / Remote Code Execution (Metasploit)
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RISK
open ↗Exploit-DB✓ VexDay Proof
Netgear NMS300 ProSafe Network Management System - Arbitrary File Upload (Metasploit)
Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allow
60RISK
open ↗Exploit-DB
Microsoft Windows - 'srv2.sys' SMB Code Execution (Python) (MS09-050)
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISK
open ↗Exploit-DB
Zimbra 8.0.9 GA - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) be
23RISK
open ↗Exploit-DB
phpRPC < 0.7 - Remote Code Execution
Eval injection vulnerability in the decode function in rpc_decoder.php for phpRPC 0.7 and earlier, as used by runcms, ex
23RISK
open ↗Exploit-DB
Microsoft Windows - 'srv2.sys' SMB Code Execution (Python) (MS09-050)
Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets
45RISK
open ↗Exploit-DB
Microsoft Windows - 'srv2.sys' SMB Code Execution (Python) (MS09-050)
Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process t
35RISK
open ↗Exploit-DB
Microsoft Windows - 'NetAPI32.dll' Code Execution (Python) (MS08-067)
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISK
open ↗Exploit-DB
IBM Lotus Domino R8 - Password Hash Extraction
Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hid
60RISK
open ↗Exploit-DB
Mambo < 4.5.3h - Multiple Vulnerabilities
Directory traversal vulnerability in the _setTemplate function in Mambo 4.5.3, 4.5.3h, and possibly earlier versions all
23RISK
open ↗Exploit-DB✓ VexDay Proof
libxml2 - xmlDictAddString Heap Buffer Overread
The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS befo
23RISK
open ↗Exploit-DB
Mambo < 4.5.3h - Multiple Vulnerabilities
SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arb
23RISK
open ↗Exploit-DB✓ VexDay Proof
libxml2 - xmlParserPrintFileContextInternal Heap Buffer Overread
The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 1
23RISK
open ↗Exploit-DB✓ VexDay Proof
Dell OpenManage Server Administrator 8.2 - (Authenticated) Directory Traversal
Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated adminis
23RISK
open ↗Exploit-DB
libquicktime 1.2.4 - Integer Overflow
Integer overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to caus
23RISK
open ↗Exploit-DB
Ubuntu < 15.10 - PT Chown Arbitrary PTs Access Via User Namespace Privilege Escalation
pt_chown in the glibc package before 2.19-18+deb8u4 on Debian jessie; the elibc package before 2.15-0ubuntu10.14 on Ubun
23RISK
open ↗Exploit-DB
BlackBerry Enterprise Service < 12.4 (BES12) Self-Service - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server
23RISK
open ↗Exploit-DB
Linux Kernel 3.x (Ubuntu 14.04 / Mint 17.3 / Fedora 22) - Double-free usb-midi SMEP Privilege Escalation
Double free vulnerability in the snd_usbmidi_create function in sound/usb/midi.c in the Linux kernel before 4.5 allows p
23RISK
open ↗Exploit-DB
BlackBerry Enterprise Service < 12.4 (BES12) Self-Service - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4
23RISK
open ↗Exploit-DB
PEAR LiveUser < 0.16.8 - Arbitrary File Access
Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Reposito
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash - SimpleButton Creation Type Confusion
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on
28RISK
open ↗Exploit-DB
QuickHeal 16.00 - 'webssx.sys' Driver Denial of Service
The webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service.
23RISK
open ↗Exploit-DB
AUFS (Ubuntu 15.10) - 'allow_userns' Fuse/Xattr User Namespaces Privilege Escalation
The aufs module for the Linux kernel 3.x and 4.x does not properly restrict the mount namespace, which allows local user
23RISK
open ↗Exploit-DB
AUFS (Ubuntu 15.10) - 'allow_userns' Fuse/Xattr User Namespaces Privilege Escalation
The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, which allows local use
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.