Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,652cataloged exploits
34,545CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,581GitHub PoC 13,708VulnCheck XDB 8,225Nuclei 4,228Metasploit 3,467✓ verified onlyrecentpopularrisk
24,443 exploits
Exploit-DB
Shopizer 1.1.5 - Multiple Vulnerabilities
Shopizer 1.1.5 and earlier allows remote attackers to reduce the total cost of their shopping cart via a negative number
23RISK
open ↗Exploit-DB
Shopizer 1.1.5 - Multiple Vulnerabilities
Shopizer 1.1.5 and earlier allows remote attackers to modify the account settings of arbitrary users via the customer.cu
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin DZS-VideoGallery - Cross-Site Scripting / Command Injection
Multiple cross-site scripting (XSS) vulnerabilities in deploy/designer/preview.php in the Digital Zoom Studio (DZS) Vide
38RISK
open ↗Exploit-DB
OpenVPN Private Tunnel Core Service - Unquoted Service Path Privilege Escalation
Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and Ope
33RISK
open ↗Exploit-DB✓ VexDay Proof
WeBid - Multiple Cross-Site Scripting / LDAP Injection Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script
23RISK
open ↗Exploit-DB
OpenVAS Manager 4.0 - Authentication Bypass
OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restricti
23RISK
open ↗Exploit-DB
Infoblox 6.8.2.11 - OS Command Injection
config/userAdmin/login.tdf in Infoblox NetMRI before 6.8.5 allows remote attackers to execute arbitrary commands via she
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin BSK PDF Manager - '/wp-admin/admin.php' Multiple SQL Injections
Multiple SQL injection vulnerabilities in inc/bsk-pdf-dashboard.php in the BSK PDF Manager plugin 1.3.2 for WordPress al
23RISK
open ↗Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
SChannel in Microsoft Internet Explorer 6 through 11 does not ensure that a server's X.509 certificate is the same durin
23RISK
open ↗Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
28RISK
open ↗Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
28RISK
open ↗Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
35RISK
open ↗Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary web script with increased privileg
28RISK
open ↗Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory cor
28RISK
open ↗Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
28RISK
open ↗Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory cor
28RISK
open ↗Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory cor
28RISK
open ↗Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (me
28RISK
open ↗Exploit-DB✓ VexDay Proof
Dolibarr ERP/CRM 3.5.3 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote authenticated users to execute arbitrary S
23RISK
open ↗Exploit-DB✓ VexDay Proof
Dolibarr ERP/CRM 3.5.3 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote attackers to inject arbitrary
23RISK
open ↗Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
35RISK
open ↗Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
28RISK
open ↗Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
Microsoft Internet Explorer 10 and 11 allows remote attackers to read local files on the client via a crafted web site,
28RISK
open ↗Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code and bypass a sandbox protecti
35RISK
open ↗Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (me
28RISK
open ↗Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (me
28RISK
open ↗Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (me
28RISK
open ↗Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
28RISK
open ↗Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
28RISK
open ↗Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
35RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.