Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,459Referência 22,721GitHub PoC 14,946VulnCheck XDB 8,829Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB
Shelly PRO 4PM v0.11.0 - Authentication Bypass
Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition t
23RISK
open ↗Exploit-DB
PHPJabbers Taxi Booking 2.0 - Reflected XSS
PHP Jabbers Taxi Booking index.php cross site scripting
48RISK
open ↗Exploit-DB
PHPJabbers Service Booking Script 1.0 - Reflected XSS
PHP Jabbers Service Booking Script index.php cross site scripting
48RISK
open ↗Exploit-DB
PHPJabbers Night Club Booking 1.0 - Reflected XSS
PHP Jabbers Night Club Booking Software index.php cross site scripting
48RISK
open ↗Exploit-DB✓ VexDay Proof
Uvdesk v1.1.3 - File Upload Remote Code Execution (RCE) (Authenticated)
An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafte
23RISK
open ↗Exploit-DB
Keeper Security desktop 16.10.2 & Browser Extension 16.5.4 - Password Dumping
An issue was discovered in Keeper Password Manager for Desktop version 16.10.2 (fixed in 17.2), and the KeeperFill Brows
23RISK
open ↗Exploit-DB
mooDating 1.2 - Reflected Cross-site scripting (XSS)
mooSocial mooDating URL pages cross site scripting
43RISK
open ↗Exploit-DB
mooDating 1.2 - Reflected Cross-site scripting (XSS)
mooSocial mooDating URL ajax_invite cross site scripting
43RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin AN_Gradebook 5.0.1 - SQLi
AN_GradeBook <= 5.0.1 - Subscriber+ SQLi
23RISK
open ↗Exploit-DB
mooDating 1.2 - Reflected Cross-site scripting (XSS)
mooSocial mooDating URL question cross site scripting
43RISK
open ↗Exploit-DB
mooDating 1.2 - Reflected Cross-site scripting (XSS)
mooSocial mooDating URL users cross site scripting
43RISK
open ↗Exploit-DB✓ VexDay Proof
RosarioSIS 10.8.4 - CSV Injection
RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module.
33RISK
open ↗Exploit-DB✓ VexDay Proof
copyparty v1.8.6 - Reflected Cross Site Scripting (XSS)
copyparty vulnerable to reflected cross-site scripting via k304 parameter
48RISK
open ↗Exploit-DB
mooDating 1.2 - Reflected Cross-site scripting (XSS)
mooSocial mooDating URL view cross site scripting
43RISK
open ↗Exploit-DB
mooDating 1.2 - Reflected Cross-site scripting (XSS)
mooSocial mooDating URL find-a-match cross site scripting
43RISK
open ↗Exploit-DB
mooDating 1.2 - Reflected Cross-site scripting (XSS)
mooSocial mooDating URL friends cross site scripting
43RISK
open ↗Exploit-DB
pfSense v2.7.0 - OS Command Injection
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attac
60RISK
open ↗Exploit-DB
RWS WorldServer 11.7.3 - Session Token Enumeration
Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized a
23RISK
open ↗Exploit-DB
Microsoft Office 365 Version 18.2305.1222.0 - Elevation of Privilege + RCE.
Microsoft Office Elevation of Privilege Vulnerability
41RISK
open ↗Exploit-DB
Hikvision Hybrid SAN Ds-a71024 Firmware - Multiple Remote Code Execution
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to t
53RISK
open ↗Exploit-DB✓ VexDay Proof
Online Piggery Management System v1.0 - unauthenticated file upload vulnerability
Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by send
43RISK
open ↗Exploit-DB
ABB FlowX v4.00 - Exposure of Sensitive Information
Flow-X disclosure of sensitive information to unauthenticated users
33RISK
open ↗Exploit-DB
Cisco UCS-IMC Supervisor 2.2.0.0 - Authentication Bypass
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Authentication Bypass Vulnerability
85RISK
open ↗Exploit-DB
WinterCMS < 1.2.3 - Persistent Cross-Site Scripting
Winter CMS vulnerable to stored XSS through privileged upload of SVG file
28RISK
open ↗Exploit-DB
Icinga Web 2.10 - Authenticated Remote Code Execution
Arbitrary code execution for authenticated users in Icinga Web 2
46RISK
open ↗Exploit-DB
BuildaGate5library v5 - Reflected Cross-Site Scripting (XSS)
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code
23RISK
open ↗Exploit-DB
MiniTool Partition Wizard ShadowMaker v.12.7 - Unquoted Service Path _MTAgentService_
20RISK
open ↗Exploit-DB
MiniTool Partition Wizard ShadowMaker v.12.7 - Unquoted Service Path _MTSchedulerService_
20RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.