Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,290cataloged exploits
36,046CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,721GitHub PoC 14,461VulnCheck XDB 8,811Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
78,258 exploits
Metasploit600
Atlassian Confluence WebWork OGNL Injection
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open ↗Exploit-DB
HP OfficeJet 4630/7110 MYM1FN2025AR/2117A - Stored Cross-Site Scripting (XSS)
A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross
23RISK
open ↗GitHub PoC★ 1
Kibana Prototype Pollution
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open ↗VulnCheck XDB
infoleak
SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated at
60RISK
open ↗VulnCheck XDB
client-side
Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corru
83RISK
open ↗GitHub PoC★ 24
my exp for chrome V8 CVE-2021-30551
Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corru
83RISK
open ↗GitHub PoC★ 1
An implementation of CVE-2015-3306
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISK
open ↗GitHub PoC
rood8008/CVE-2021-35464
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RISK
open ↗VulnCheck XDB
infoleak
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RISK
open ↗VulnCheck XDB
client-side
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open ↗VulnCheck XDB
local
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RISK
open ↗VulnCheck XDB
initial-access
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open ↗GitHub PoC★ 11
CVE-2018-19320 LPE Exploit
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RISK
open ↗Exploit-DB
crossfire-server 1.9.0 - 'SetUp()' Remote Buffer Overflow
Buffer overflow in the SetUp function in socket/request.c in CrossFire 1.9.0 allows remote attackers to execute arbitrar
28RISK
open ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open ↗GitHub PoC★ 1
CVE-2019-11932
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open ↗Exploit-DB
SonicWall NetExtender 10.2.0.300 - Unquoted Service Path
SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to
23RISK
open ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RISK
open ↗GitHub PoC★ 1
A tool to crash MySQL servers with CVE-2017-3599
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions t
45RISK
open ↗GitHub PoC★ 1
Multiple Stored XSS Online Doctor Appointment System
Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment S
23RISK
open ↗GitHub PoC★ 30
CVE-2021-34473 Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 1
tools for automate configure Ubuntu 20.04 enviroment for testing CVE-2021-28476.
Windows Hyper-V Remote Code Execution Vulnerability
60RISK
open ↗GitHub PoC
The Heartbleed bug `CVE-2014-0160` is a severe implementation flaw in the OpenSSL library, which enables attackers to steal data from the memory of the victim server. The contents of the stolen data depend on what is there in the memory of the server. It could potentially contain private keys, TLS session keys, usernames, passwords, credit cards, etc. The vulnerability is in the implementation of the Heartbeat protocol, which is used by SSL/TLS to keep the connection alive.
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open ↗VulnCheck XDB
infoleak
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open ↗VulnCheck XDB
infoleak
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open ↗GitHub PoC★ 3
WordPress File Upload Vulnerability, Modern Events Calendar Lite WordPress plugin before 5.16.5
Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE
60RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.