Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,459Referência 22,721GitHub PoC 14,946VulnCheck XDB 8,829Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB
Jedox 2020.2.5 - Remote Code Execution via Executable Groovy-Scripts
The integrator in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to create Jobs to execute arbitrary code v
48RISK
open ↗Exploit-DB
Jedox 2020.2.5 - Remote Code Execution via Configurable Storage Path
Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authentica
60RISK
open ↗Exploit-DB
Jedox 2022.4.2 - Remote Code Execution via Directory Traversal
A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to ex
46RISK
open ↗Exploit-DB
Jedox 2020.2.5 - Disclosure of Database Credentials via Improper Access Controls
Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of dat
38RISK
open ↗Exploit-DB
Jedox 2022.4.2 - Disclosure of Database Credentials via Connection Checks
An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users wi
33RISK
open ↗Exploit-DB
Jedox 2022.4.2 - Code Execution via RPC Interfaces
A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load a
41RISK
open ↗Exploit-DB
Jedox 2020.2.5 - Stored Cross-Site Scripting in Log-Module
A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web
48RISK
open ↗Exploit-DB
FS-S3900-24T4S - Privilege Escalation
FS S3900-24T4S devices allow authenticated attackers with guest access to escalate their privileges and reset the admin
41RISK
open ↗Exploit-DB
MilleGPG5 5.9.2 (Gennaio 2023) - Local Privilege Escalation / Incorrect Access Control
An issue was discovered in Genomedics MilleGP5 5.9.2, allows remote attackers to execute arbitrary code and gain escalat
41RISK
open ↗Exploit-DB
Sophos Web Appliance 4.3.10.4 - Pre-auth command injection
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISK
open ↗Exploit-DB
KodExplorer 4.49 - CSRF to Arbitrary File Upload
kalcaddle KodExplorer cross-site request forgery
33RISK
open ↗Exploit-DB
PaperCut NG/MG 22.0.4 - Authentication Bypass
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open ↗Exploit-DB✓ VexDay Proof
Bang Resto v1.0 - Stored Cross-Site Scripting (XSS)
Bang Resto 1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the itemName parameter in
33RISK
open ↗Exploit-DB✓ VexDay Proof
Bang Resto v1.0 - 'Multiple' SQL Injection
Bang Resto 1.0 was discovered to contain multiple SQL injection vulnerabilities via the btnMenuItemID, itemID, itemPrice
41RISK
open ↗Exploit-DB
Microsoft Word 16.72.23040900 - Remote Code Execution (RCE)
Microsoft Word Remote Code Execution Vulnerability
41RISK
open ↗Exploit-DB
File Replication Pro 7.5.0 - Privilege Escalation/Password reset due Incorrect Access Control
Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan
48RISK
open ↗Exploit-DB
GDidees CMS 3.9.1 - Local File Disclosure
GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename paramet
68RISK
open ↗Exploit-DB
Linux Kernel 6.2 - Userspace Processes To Enable Mitigation
Spectre v2 SMT mitigations problem in Linux kernel
33RISK
open ↗Exploit-DB
Paradox Security Systems IPR512 - Denial Of Service
An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and l
53RISK
open ↗Exploit-DB
Online Computer and Laptop Store 1.0 - Remote Code Execution (RCE)
SourceCodester Online Computer and Laptop Store index.php unrestricted upload
33RISK
open ↗Exploit-DB
Microsoft Edge (Chromium-based) Webview2 1.0.1661.34 - Spoofing
Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability
41RISK
open ↗Exploit-DB
X2CRM v6.6/6.9 - Reflected Cross-Site Scripting (XSS) (Authenticated)
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability v
33RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! v4.2.8 - Unauthenticated information disclosure
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗Exploit-DB
Adobe Connect 11.4.5 - Local File Disclosure
Adobe Connect Improper Access Control Security feature bypass
70RISK
open ↗Exploit-DB
Pentaho BA Server EE 9.3.0.0-428 - Remote Code Execution (RCE) (Unauthenticated)
Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions
100RISK
open ↗Exploit-DB
Symantec Messaging Gateway 10.7.4 - Stored Cross-Site Scripting (XSS)
An authenticated user can embed malicious content with XSS into the admin group policy page.
33RISK
open ↗Exploit-DB
Goanywhere Encryption helper 7.1.1 - Remote Code Execution (RCE)
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RISK
open ↗Exploit-DB
RSA NetWitness Platform 12.2 - Incorrect Access Control / Code Execution
Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Wi
23RISK
open ↗Exploit-DB
Pentaho BA Server EE 9.3.0.0-428 - Remote Code Execution (RCE) (Unauthenticated)
Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.