Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,910GitHub PoC 14,997VulnCheck XDB 8,843Nuclei 4,358Metasploit 3,489✓ verified onlyrecentpopularrisk
78,958 exploits
VulnCheck XDB
initial-access
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open ↗GitHub PoC
wood03mm/CVE-2016-3088
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open ↗VulnCheck XDB
remote-with-credentials
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open ↗GitHub PoC
Insecure Folder permission that lead to privilege escalation
The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory
23RISK
open ↗Exploit-DB
GitLab 11.4.7 - RCE (Authenticated) (2)
GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection
28RISK
open ↗GitHub PoC★ 7
Weblogic Server CVE-2020-14645 EXP for Python (complete in one step)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
60RISK
open ↗Exploit-DB
GitLab 11.4.7 - RCE (Authenticated) (2)
GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an
28RISK
open ↗GitHub PoC
Webmin Exploit Scanner CVE-2020-35606 CVE-2019-12840
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can ex
28RISK
open ↗GitHub PoC
Webmin Exploit Scanner CVE-2020-35606 CVE-2019-12840
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISK
open ↗GitHub PoC★ 4
Supervisord远程命令执行漏洞脚本
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RISK
open ↗VulnCheck XDB
remote-with-credentials
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RISK
open ↗Exploit-DB
Spiceworks 7.5 - HTTP Header Injection
Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious we
23RISK
open ↗Exploit-DB
SCO Openserver 5.0.7 - 'section' Reflected XSS
A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote at
38RISK
open ↗VulnCheck XDB
initial-access
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open ↗Exploit-DB
Flexmonster Pivot Table & Charts 2.7.17 - 'To OLAP' Reflected XSS
Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Tab
23RISK
open ↗Exploit-DB
SCO Openserver 5.0.7 - 'outputform' Command Injection
Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in ou
35RISK
open ↗GitHub PoC★ 35
Laravel RCE exploit. CVE-2018-15133
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open ↗Exploit-DB
Flexmonster Pivot Table & Charts 2.7.17 - 'Remote Report' Reflected XSS
Cross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Cha
23RISK
open ↗Exploit-DB
Flexmonster Pivot Table & Charts 2.7.17 - 'Remote JSON' Reflected XSS
Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table
23RISK
open ↗Exploit-DB
Flexmonster Pivot Table & Charts 2.7.17 - 'To remote CSV' Reflected XSS
Cross Site Scripting (XSS) vulnerability in the "To Remote CSV" component under "Open" Menu in Flexmonster Pivot Table &
23RISK
open ↗GitHub PoC★ 1
POC for CVE-2018-0114 written in Go
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISK
open ↗GitHub PoC★ 2
DirtyCOW Exploit for Android
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open ↗VulnCheck XDB
local
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RISK
open ↗GitHub PoC
https://github.com/awakened1712/CVE-2019-11932://github.com/awakened1712/CVE-2019-11932
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open ↗VulnCheck XDB
local
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open ↗GitHub PoC★ 2
Collection of PoCs created for SmarterMail < Build 6985 RCE
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co
60RISK
open ↗Metasploit600
Nagios XI Prior to 5.8.0 - Plugins Filename Authenticated Remote Code Exection
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature
60RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.