Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,459Referência 22,721GitHub PoC 14,946VulnCheck XDB 8,829Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB
BuildaGate5library v5 - Reflected Cross-Site Scripting (XSS)
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code
23RISK
open ↗Exploit-DB
Windows 10 v21H1 - HTTP Protocol Stack Remote Code Execution
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open ↗Exploit-DB
Microsoft Outlook Microsoft 365 MSO (Version 2306 Build 16.0.16529.20100) 32-bit - Remote Code Execution
Microsoft Outlook Remote Code Execution Vulnerability
41RISK
open ↗Exploit-DB
Lost and Found Information System v1.0 - SQL Injection
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lf
23RISK
open ↗Exploit-DB
Microsoft Edge 114.0.1823.67 (64-bit) - Information Disclosure
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
33RISK
open ↗Exploit-DB
Sales of Cashier Goods v1.0 - Cross Site Scripting (XSS)
POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parame
38RISK
open ↗Exploit-DB
FuguHub 8.1 - Remote Code Execution
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the c
53RISK
open ↗Exploit-DB
Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 64-bit - Remote Code Execution (RCE)
Microsoft Office Remote Code Execution Vulnerability
41RISK
open ↗Exploit-DB
WP AutoComplete 1.0.4 - Unauthenticated SQLi
WP AutoComplete Search <= 1.0.4 - Unauthenticated SQLi
48RISK
open ↗Exploit-DB
Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 32-bit - Remote Code Execution (RCE)
Microsoft Excel Remote Code Execution Vulnerability
41RISK
open ↗Exploit-DB
TP-Link TL-WR940N V4 - Buffer OverFlow
TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6Cfg
35RISK
open ↗Exploit-DB
POS Codekop v2.0 - Authenticated Remote Code Execution (RCE)
POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename p
23RISK
open ↗Exploit-DB
Windows 11 22h2 - Kernel Privilege Elevation
Windows Kernel Elevation of Privilege Vulnerability
41RISK
open ↗Exploit-DB
Microsoft SharePoint Enterprise Server 2016 - Spoofing
Microsoft SharePoint Server Spoofing Vulnerability
41RISK
open ↗Exploit-DB
PrestaShop Winbiz Payment module - Improper Limitation of a Pathname to a Restricted Directory
Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules/winbizpayment/downloads/download
41RISK
open ↗Exploit-DB
Azure Apache Ambari 2302250400 - Spoofing
Azure Apache Ambari Spoofing Vulnerability
33RISK
open ↗Exploit-DB
NCH Express Invoice - Clear Text Password Storage and Account Takeover
NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.
23RISK
open ↗Exploit-DB
Smart Office Web 20.28 - Remote Information Disclosure (Unauthenticated)
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the
68RISK
open ↗Exploit-DB
Smart Office Web 20.28 - Remote Information Disclosure (Unauthenticated)
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to view sensitive information via Display
41RISK
open ↗Exploit-DB✓ VexDay Proof
Super Socializer 7.13.52 - Reflected XSS
Super Socializer < 7.13.52 - Reflected XSS
48RISK
open ↗Exploit-DB
WP Sticky Social 1.0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting (XSS)
The WP Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,
33RISK
open ↗Exploit-DB✓ VexDay Proof
SPIP v4.2.0 - Remote Code Execution (Unauthenticated)
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open ↗Exploit-DB
Nokia ASIKA 7.13.52 - Hard-coded private key disclosure
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures
33RISK
open ↗Exploit-DB
Symantec SiteMinder WebAgent v12.52 - Cross-site scripting (XSS)
A user can supply malicious HTML and JavaScript code that will be executed in the client browser
33RISK
open ↗Exploit-DB
WordPress Theme Medic v1.0.0 - Weak Password Recovery Mechanism for Forgotten Password
Password reset links invalidation issue in WordPress
38RISK
open ↗Exploit-DB✓ VexDay Proof
PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE)
Code Injection in pyload/pyload
85RISK
open ↗Exploit-DB
Teachers Record Management System 1.0 - File Upload Type Validation
PHPGurukul Teachers Record Management System Profile Picture changeimage.php unrestricted upload
33RISK
open ↗Exploit-DB✓ VexDay Proof
Sales Tracker Management System v1.0 - Multiple Vulnerabilities
SourceCodester Sales Tracker Management System cross site scripting
28RISK
open ↗Exploit-DB
WordPress Theme Workreap 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RISK
open ↗Exploit-DB
Tree Page View Plugin 1.6.7 - Cross Site Scripting (XSS)
WordPress CMS Tree Page View Plugin <= 1.6.7 is vulnerable to Cross Site Scripting (XSS)
56RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.