Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,832GitHub PoC 14,991VulnCheck XDB 8,829Nuclei 4,357Metasploit 3,489✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB
Apache Log4j 2 - Remote Code Execution (RCE)
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open ↗Exploit-DB
Booked Scheduler 2.7.5 - Remote Command Execution (RCE) (Authenticated)
phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitra
28RISK
open ↗Exploit-DB
WebHMI 4.0 - Remote Code Execution (RCE) (Authenticated)
Distributed Data Systems WebHM
60RISK
open ↗Exploit-DB
HD-Network Real-time Monitoring System 2.0 - Local File Inclusion (LFI)
HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_L
50RISK
open ↗Exploit-DB
Raspberry Pi 5.10 - Default Credentials
Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain a
28RISK
open ↗Exploit-DB
Grafana 8.3.0 - Directory Traversal and Arbitrary File Read
Grafana path traversal
100RISK
open ↗Exploit-DB
Student Management System 1.0 - SQLi Authentication Bypass
Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (
28RISK
open ↗Exploit-DB
Auerswald COMpact 8.0B - Multiple Backdoors
Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web
60RISK
open ↗Exploit-DB
Croogo 3.0.2 - Remote Code Execution (Authenticated)
A Remote Code Execution (RCE) vulnerability exists in Croogo 3.0.2via admin/file-manager/attachments, which lets a malic
23RISK
open ↗Exploit-DB
WordPress Plugin DZS Zoomsounds 6.45 - Arbitrary File Read (Unauthenticated)
ZoomSounds <= 6.45 Unauthenticated Directory Traversal and Sensitive Information Dislosure
68RISK
open ↗Exploit-DB
Online Enrollment Management System in PHP and PayPal 1.0 - 'U_NAME' Stored Cross-Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Enrollment Management System in PHP an
23RISK
open ↗Exploit-DB
Linux Kernel 5.1.x - 'PTRACE_TRACEME' pkexec Local Privilege Escalation (2)
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open ↗Exploit-DB✓ VexDay Proof
SuiteCRM 7.11.18 - Remote Code Execution (RCE) (Authenticated) (Metasploit)
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumsta
50RISK
open ↗Exploit-DB
Bludit 3.13.1 - 'username' Cross Site Scripting (XSS)
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.
38RISK
open ↗Exploit-DB
GitLab 13.10.2 - Remote Code Execution (RCE) (Unauthenticated)
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open ↗Exploit-DB
Online Learning System 2.0 - Remote Code Execution (RCE)
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/adm
23RISK
open ↗Exploit-DB
Simple Subscription Website 1.0 - SQLi Authentication Bypass
SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login.
23RISK
open ↗Exploit-DB
WordPress Plugin WPSchoolPress 2.1.16 - 'Multiple' Cross Site Scripting (XSS)
WPSchoolPress < 2.1.17 - Multiple Admin+ Stored Cross-Site Scripting
23RISK
open ↗Exploit-DB
PHP Laravel 8.70.1 - Cross Site Scripting (XSS) to Cross Site Request Forgery (CSRF)
Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Val
28RISK
open ↗Exploit-DB✓ VexDay Proof
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗Exploit-DB✓ VexDay Proof
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open ↗Exploit-DB
FormaLMS 2.4.4 - Authentication Bypass
An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain
28RISK
open ↗Exploit-DB
FusionPBX 4.5.29 - Remote Code Execution (RCE) (Authenticated)
An issue was discovered in FusionPBX before 4.5.30. The fax_extension may have risky characters (it is not constrained t
35RISK
open ↗Exploit-DB
Eclipse Jetty 11.0.5 - Sensitive File Disclosure
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characte
70RISK
open ↗Exploit-DB
OpenAM 13.0 - LDAP Injection
ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacke
60RISK
open ↗Exploit-DB
Fuel CMS 1.4.1 - Remote Code Execution (3)
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open ↗Exploit-DB
WebCTRL OEM 6.5 - 'locale' Reflected Cross-Site Scripting (XSS)
The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for re
43RISK
open ↗Exploit-DB✓ VexDay Proof
Movable Type 7 r.5002 - XMLRPC API OS Command Injection (Metasploit)
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISK
open ↗Exploit-DB
Hikvision Web Server Build 210702 - Command Injection
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.