Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,367GitHub PoC 14,225VulnCheck XDB 8,649Nuclei 4,283Metasploit 3,474✓ verified onlyrecentpopularrisk
77,302 exploits
GitHub PoC★ 52
PoC for the recent critical vuln affecting OpenSSH versions < 9.3p2
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISK
open ↗VulnCheck XDB
infoleak
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISK
open ↗VulnCheck XDB
initial-access
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RISK
open ↗GitHub PoC
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RISK
open ↗VulnCheck XDB
initial-access
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISK
open ↗Exploit-DB
Adlisting Classified Ads 2.14.0 - WebPage Content Information Disclosure
Templatecookie Adlisting Redirect ad-list information disclosure
60RISK
open ↗Metasploit600
CrushFTP Unauthenticated RCE
CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes
60RISK
open ↗Exploit-DB✓ VexDay Proof
Social-Commerce 3.1.6 - Reflected XSS
mooSocial mooStore cross site scripting
43RISK
open ↗Exploit-DB
Pyro CMS 3.9 - Server-Side Template Injection (SSTI) (Authenticated)
PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template in
35RISK
open ↗Exploit-DB✓ VexDay Proof
mooSocial 3.1.8 - Reflected XSS
mooSocial mooStore index cross site scripting
43RISK
open ↗Exploit-DB
Emagic Data Center Management Suite v6.0 - OS Command Injection
OS Command Injection Vulnerability in Emagic Data Center Management Suite
53RISK
open ↗VulnCheck XDB
initial-access
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
68RISK
open ↗GitHub PoC
Original Exploit Source: https://www.exploit-db.com/exploits/46635
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open ↗GitHub PoC
Campcodes Online Matrimonial Website System 3.3 Cross Site Scripting
install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG docum
23RISK
open ↗GitHub PoC★ 9
CVE exploitation for WebKit jsc CVE-2018-4416
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
35RISK
open ↗VulnCheck XDB
client-side
Sitemap by click5 < 1.0.36 - Unauthenticated Arbitrary Options Update
43RISK
open ↗GitHub PoC★ 2
Running this exploit on a vulnerable system allows a local attacker to gain a root shell on the machine.
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open ↗GitHub PoC
MrE-Fog/jboss-_CVE-2017-12149
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISK
open ↗VulnCheck XDB
initial-access
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISK
open ↗VulnCheck XDB
local
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open ↗GitHub PoC★ 3
This repo hosts TUKRU's Linux Privilege Escalation exploit (CVE-2021-22555). It demonstrates gaining root privileges via a vulnerability. Tested on Ubuntu 5.8.0-48-generic and COS 5.4.89+. Use responsibly and ethically.
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISK
open ↗GitHub PoC★ 1
Quick PoC checker for common configurations that might be available via directory traversal due to CVE-2013-3827
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2;
50RISK
open ↗GitHub PoC★ 2
Perform With Massive Authentication Bypass (Wordpress Mstore-API)
MStore API <= 3.9.2 - Authentication Bypass
75RISK
open ↗VulnCheck XDB
infoleak
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2;
50RISK
open ↗GitHub PoC★ 2
Exim < 4.90.1 RCE Vulnerability remake for Python3 with arguments passed from CLI
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.