Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,367GitHub PoC 14,225VulnCheck XDB 8,649Nuclei 4,283Metasploit 3,474✓ verified onlyrecentpopularrisk
77,302 exploits
GitHub PoC★ 1
isacaya/CVE-2019-11358
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RISK
open ↗VulnCheck XDB
client-side
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RISK
open ↗GitHub PoC★ 2
Exim < 4.90.1 RCE Vulnerability remake for Python3 with arguments passed from CLI
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISK
open ↗GitHub PoC★ 2
Perform With Massive Authentication Bypass (Wordpress Mstore-API)
MStore API <= 3.9.2 - Authentication Bypass
75RISK
open ↗GitHub PoC★ 1
Quick PoC checker for common configurations that might be available via directory traversal due to CVE-2013-3827
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2;
50RISK
open ↗Exploit-DB
Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Event Access
EventON < 2.1.2 - Unauthenticated Event Access
50RISK
open ↗Metasploit600
LG Simple Editor Command Injection (CVE-2023-40504)
LG Simple Editor readVideoInfo Command Injection Remote Code Execution Vulnerability
65RISK
open ↗GitHub PoC★ 2
CVE-2023-37979 PoC and Checker
WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
56RISK
open ↗GitHub PoC
# Exploit Title: Pluck CMS 4.7.16 - Remote Code Execution (RCE) (Authenticated) # Date: 13.03.2022 # Exploit Author: Ashish Koli (Shikari) # Vendor Homepage: https://github.com/pluck-cms/pluck # Version: 4.7.16 # Tested on Ubuntu 20.04.3 LTS # CVE: CVE-2022-26965
In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remot
35RISK
open ↗Exploit-DB
WordPress Plugin Ninja Forms 3.6.25 - Reflected XSS
WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
56RISK
open ↗Exploit-DB
PHPJabbers Cleaning Business 1.0 - Reflected XSS
PHP Jabbers Cleaning Business index.php cross site scripting
48RISK
open ↗Exploit-DB
PHPJabbers Service Booking Script 1.0 - Reflected XSS
PHP Jabbers Service Booking Script index.php cross site scripting
48RISK
open ↗GitHub PoC
Vulnerable environment of CVE-2013-2251 (S2-016) for testing
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a
100RISK
open ↗Exploit-DB
PHPJabbers Rental Property Booking 2.0 - Reflected XSS
PHP Jabbers Rental Property Booking index.php cross site scripting
33RISK
open ↗Exploit-DB
PHPJabbers Taxi Booking 2.0 - Reflected XSS
PHP Jabbers Taxi Booking index.php cross site scripting
48RISK
open ↗GitHub PoC
Vulnerable environment of CVE-2020-17530 (S2-061) for testing
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open ↗Exploit-DB
Shelly PRO 4PM v0.11.0 - Authentication Bypass
Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition t
23RISK
open ↗GitHub PoC★ 4
Remote Unauthenticated API Access Vulnerability in MobileIron Core 11.2 and older
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted fu
100RISK
open ↗Exploit-DB
PHPJabbers Shuttle Booking Software 1.0 - Reflected XSS
PHP Jabbers Shuttle Booking Software index.php cross site scripting
48RISK
open ↗VulnCheck XDB
initial-access
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted fu
100RISK
open ↗Exploit-DB
PHPJabbers Night Club Booking 1.0 - Reflected XSS
PHP Jabbers Night Club Booking Software index.php cross site scripting
48RISK
open ↗Exploit-DB
Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Post Access via IDOR
EventON < 2.1.2 - Unauthenticated Post Access via IDOR
38RISK
open ↗VulnCheck XDB
initial-access
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open ↗VulnCheck XDB
initial-access
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open ↗GitHub PoC★ 4
Exploit CVE-2021-41773 and CVE-2021-42013
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗VulnCheck XDB
remote-with-credentials
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open ↗VulnCheck XDB
initial-access
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open ↗VulnCheck XDB
initial-access
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.