Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,910GitHub PoC 14,997VulnCheck XDB 8,843Nuclei 4,358Metasploit 3,489✓ verified onlyrecentpopularrisk
24,695 exploits
Exploit-DB✓ VexDay Proof
Adobe Flash TextField.type Setter - Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash TextField.text Setter - Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash TextField.tabIndex Setter - Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash TextField.htmlText Setter - Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RISK
open ↗Exploit-DB✓ VexDay Proof
Google Chrome - Renderer Process to Browser Process Privilege Escalation
Integer overflow in the WebCursor::Deserialize function in content/common/cursors/webcursor.cc in Google Chrome before 4
23RISK
open ↗Exploit-DB✓ VexDay Proof
win32k Clipboard Bitmap - Use-After-Free
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash TextField.gridFitType Setter - Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and
28RISK
open ↗Exploit-DB✓ VexDay Proof
win32k Desktop and Clipboard - Null Pointer Dereference
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'win32k!OffsetChildren' Null Pointer Dereference
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash TextField.antiAliasType Setter - Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and
28RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash MovieClip.lineStyle - Use-After-Frees
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and
35RISK
open ↗Exploit-DB✓ VexDay Proof
Zen Cart 1.5.4 - Local File Inclusion
Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files
28RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash GradientFill - Use-After-Frees
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and
28RISK
open ↗Exploit-DB✓ VexDay Proof
Wireshark - dissect_diameter_base_framed_ipv6_prefix Stack Buffer Overflow
The dissect_tds7_colmetadata_token function in epan/dissectors/packet-tds.c in the TDS dissector in Wireshark 2.0.x befo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Wireshark - dissect_diameter_base_framed_ipv6_prefix Stack Buffer Overflow
The dissect_diameter_base_framed_ipv6_prefix function in epan/dissectors/packet-diameter.c in the DIAMETER dissector in
23RISK
open ↗Exploit-DB✓ VexDay Proof
Wireshark - addresses_equal 'dissect_rsvp_common' Use-After-Free
The dissect_rsvp_common function in epan/dissectors/packet-rsvp.c in the RSVP dissector in Wireshark 1.12.x before 1.12.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Wireshark - dissct_rsl_ipaccess_msg Static Out-of-Bounds Read
The dissct_rsl_ipaccess_msg function in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.1
23RISK
open ↗Exploit-DB✓ VexDay Proof
Wireshark - ascend_seek Static Out-of-Bounds Read
The ascend_seek function in wiretap/ascendtext.c in the Ascend file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x b
23RISK
open ↗Exploit-DB✓ VexDay Proof
Wireshark - dissect_nbap_MACdPDU_Size SIGSEGV
epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not va
23RISK
open ↗Exploit-DB✓ VexDay Proof
Wireshark - memcpy 'get_value / dissect_btatt' SIGSEGV
The get_value function in epan/dissectors/packet-btatt.c in the Bluetooth Attribute (aka BT ATT) dissector in Wireshark
23RISK
open ↗Exploit-DB✓ VexDay Proof
Wireshark - dissect_zcl_pwr_prof_pwrprofstatersp Static Out-of-Bounds Read
The dissect_zcl_pwr_prof_pwrprofstatersp function in epan/dissectors/packet-zbee-zcl-general.c in the ZigBee ZCL dissect
23RISK
open ↗Exploit-DB✓ VexDay Proof
Wireshark - wmem_alloc Assertion Failure
The ipmi_fmt_udpport function in epan/dissectors/packet-ipmi.c in the IPMI dissector in Wireshark 2.0.x before 2.0.1 imp
23RISK
open ↗Exploit-DB✓ VexDay Proof
Wireshark - find_signature Stack Out-of-Bounds Read
wiretap/vwr.c in the VeriWave file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate cer
23RISK
open ↗Exploit-DB✓ VexDay Proof
Wireshark - my_dgt_tbcd_unpack Static Buffer Overflow
The Mobile Identity parser in (1) epan/dissectors/packet-ansi_a.c in the ANSI A dissector and (2) epan/dissectors/packet
23RISK
open ↗Exploit-DB✓ VexDay Proof
Wireshark - file_read 'wtap_read_bytes_or_eof/mp2t_find_next_pcr' Stack Buffer Overflow
The mp2t_find_next_pcr function in wiretap/mp2t.c in the MP2T file parser in Wireshark 2.0.x before 2.0.1 does not reser
23RISK
open ↗Exploit-DB✓ VexDay Proof
Wireshark - AirPDcapPacketProcess Stack Buffer Overflow
The AirPDcapPacketProcess function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before 1.12.9 an
23RISK
open ↗Exploit-DB✓ VexDay Proof
Jenkins CLI - RMI Java Deserialization (Metasploit)
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary co
60RISK
open ↗Exploit-DB✓ VexDay Proof
ManageEngine Desktop Central 9 - FileUploadServlet ConnectionId (Metasploit)
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and e
60RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! 1.5 < 3.4.5 - Object Injection Remote Command Execution
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Type Confusion in IExternalizable.readExternal When Performing Local Serialization
Adobe Flash Player before 18.0.0.255 and 19.x before 19.0.0.226 on Windows and OS X and before 11.2.202.540 on Linux all
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.