Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,429GitHub PoC 14,270VulnCheck XDB 8,693Nuclei 4,299Metasploit 3,474✓ verified onlyrecentpopularrisk
77,449 exploits
Exploit-DB
NVFLARE < 2.1.4 - Unsafe Deserialization due to Pickle
NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage ma
48RISK
open ↗Exploit-DB
ImpressCMS v1.4.3 - Authenticated SQL Injection
SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this al
23RISK
open ↗Exploit-DB✓ VexDay Proof
Abantecart v1.3.2 - Authenticated Remote Code Execution
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable
23RISK
open ↗Exploit-DB✓ VexDay Proof
Composr-CMS Version <=10.0.39 - Authenticated Remote Code Execution
Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrar
23RISK
open ↗GitHub PoC★ 1
a simple tool to detect the exploitation of BlueKeep vulnerability (CVE-2019-0708)
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗Exploit-DB
DLink DIR 819 A1 - Denial of Service
On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via t
41RISK
open ↗VulnCheck XDB
initial-access
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗Exploit-DB
System Mechanic v15.5.0.61 - Arbitrary Read/Write
In Iolo System Shield AntiVirus and AntiSpyware 5.0.0.136, the amp.sys driver file contains an Arbitrary Write vulnerabi
28RISK
open ↗GitHub PoC
Authenticated Remote Code Execution in Icinga Web 2 <2.8.6, <2.9.6, <2.10
Arbitrary code execution for authenticated users in Icinga Web 2
46RISK
open ↗Exploit-DB✓ VexDay Proof
SimpleMachinesForum v2.1.1 - Authenticated Remote Code Execution
SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting
23RISK
open ↗GitHub PoC
Brandaoo/CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗Exploit-DB
Password Manager for IIS v2.0 - XSS
Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL
33RISK
open ↗Exploit-DB✓ VexDay Proof
MODX Revolution v2.8.3-pl - Authenticated Remote Code Execution
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an ex
23RISK
open ↗Exploit-DB✓ VexDay Proof
NEX-Forms WordPress plugin < 7.9.7 - Authenticated SQLi
NEX-Forms < 7.9.7 - Authenticated SQLi
43RISK
open ↗Exploit-DB
_camp_ Raspberry Pi camera server 1.0 - Authentication Bypass
patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access
60RISK
open ↗GitHub PoC★ 1
RSA NetWitness Platform EDR Agent / Incorrect Access Control - Code Execution
Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Wi
23RISK
open ↗VulnCheck XDB
initial-access
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗GitHub PoC★ 37
MinIO敏感信息泄露漏洞批量扫描poc&exp
Minio Information Disclosure in Cluster Deployment
100RISK
open ↗GitHub PoC★ 7
CVE-2023-28432,minio未授权访问检测工具
Minio Information Disclosure in Cluster Deployment
100RISK
open ↗GitHub PoC
CVE-2023-23397 powershell patch script for Windows 10 and 11
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open ↗GitHub PoC★ 1
An exploitation demo of Outlook Elevation of Privilege Vulnerability
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open ↗GitHub PoC★ 94
Joomla! < 4.2.8 - Unauthenticated information disclosure
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗GitHub PoC★ 6
test of exploit for CVE-2023-21716
Microsoft Word Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC★ 8
CVE-2023-28343 POC exploit
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.