Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,295cataloged exploits
36,048CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,721GitHub PoC 14,464VulnCheck XDB 8,813Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
78,258 exploits
GitHub PoC★ 3
WordPress File Upload Vulnerability, Modern Events Calendar Lite WordPress plugin before 5.16.5
Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE
60RISK
open ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 1
Sudo Heap Overflow Baron Samedit
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open ↗GitHub PoC
WpDiscuz 7.0.4 Arbitrary File Upload Exploit
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RISK
open ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RISK
open ↗VulnCheck XDB
local
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open ↗Exploit-DB
Altova MobileTogether Server 7.3 - XML External Entity Injection (XXE)
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workfl
35RISK
open ↗GitHub PoC
Jerry-zhuang/CVE-2017-1000117
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RISK
open ↗GitHub PoC
Zeek Package to detect cve-2017-2741
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmwa
60RISK
open ↗GitHub PoC★ 5
Scanner for CVE-2021-34473, ProxyShell, A Microsoft Exchange On-premise Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open ↗GitHub PoC★ 46
nuclei scanner for proxyshell ( CVE-2021-34473 )
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗VulnCheck XDB
client-side
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly
83RISK
open ↗VulnCheck XDB
initial-access
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open ↗GitHub PoC
ZeroShell命令执行漏洞批量扫描poc+exp
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open ↗Exploit-DB
Cockpit CMS 0.11.1 - 'Username Enumeration & Password Reset' NoSQL Injection
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
60RISK
open ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗Exploit-DB
Amica Prodigy 1.7 - Privilege Escalation
A vulnerability was found in CIR 2000 / Gestionale Amica Prodigy v1.7. The Amica Prodigy's executable "RemoteBackup.Serv
23RISK
open ↗Exploit-DB
Xiaomi browser 10.2.4.g - Browser Search History Disclosure
Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider
28RISK
open ↗GitHub PoC★ 10
Windows Font Driver Type 1 VToHOrigin stack corruption
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly
83RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.