Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,324cataloged exploits
36,054CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,721GitHub PoC 14,477VulnCheck XDB 8,829Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
78,291 exploits
VulnCheck XDB
client-side
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open ↗GitHub PoC★ 12
exiftool arbitrary code execution vulnerability
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open ↗GitHub PoC★ 1
0xm4ud/Cacti-CVE-2020-8813
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RISK
open ↗GitHub PoC★ 96
Python exploit for the CVE-2021-22204 vulnerability in Exiftool
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open ↗Metasploit300
Windows IIS HTTP Protocol Stack DOS
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open ↗Metasploit600
Microsoft SharePoint Unsafe Control and ViewState RCE
Microsoft SharePoint Remote Code Execution Vulnerability
48RISK
open ↗Metasploit500
Linux eBPF ALU32 32-bit Invalid Bounds Tracking LPE
Linux kernel eBPF bitwise ops ALU32 bounds tracking
41RISK
open ↗VulnCheck XDB
initial-access
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,
50RISK
open ↗GitHub PoC★ 3
Exploit for Node-jose < 0.11.0 written in Ruby
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISK
open ↗VulnCheck XDB
client-side
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open ↗GitHub PoC★ 3
POC Exploit written in Ruby
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISK
open ↗GitHub PoC
fu2x2000/CVE-2017-17058-woo_exploit
The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/wooco
46RISK
open ↗VulnCheck XDB
initial-access
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RISK
open ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open ↗Exploit-DB
Microweber CMS 1.1.20 - Remote Code Execution (Authenticated)
A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to g
28RISK
open ↗GitHub PoC★ 3
Check YouTube - https://youtu.be/O0ZnLXRY5Wo
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open ↗Metasploit300
Apache 2.4.49/2.4.50 Traversal RCE scanner
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open ↗Metasploit600
Apache 2.4.49/2.4.50 Traversal RCE
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open ↗Metasploit600
Apache 2.4.49/2.4.50 Traversal RCE
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗Metasploit300
Apache 2.4.49/2.4.50 Traversal RCE scanner
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC★ 6
CVE-2017-7494 python exploit
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open ↗VulnCheck XDB
initial-access
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open ↗VulnCheck XDB
initial-access
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,
50RISK
open ↗VulnCheck XDB
local
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open ↗VulnCheck XDB
initial-access
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISK
open ↗GitHub PoC★ 3
CVE-2019-2215
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open ↗VulnCheck XDB
initial-access
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,
50RISK
open ↗Exploit-DB
b2evolution 7-2-2 - 'cf_name' SQL Injection
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive dat
23RISK
open ↗Metasploit600
Cisco HyperFlex HX Data Platform unauthenticated file upload to RCE (CVE-2021-1499)
Cisco HyperFlex HX Data Platform File Upload Vulnerability
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.