Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,464Referência 22,936GitHub PoC 15,010VulnCheck XDB 8,846Nuclei 4,361Metasploit 3,490✓ verified onlyrecentpopularrisk
79,057 exploits
GitHub PoC★ 9
A Remote Code Execution (RCE) exploit for Huawei HG532d based on CVE-2017-17215 vulnerability. Modded from original PoC code from exploit-db.com
Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could se
45RISK
open ↗VulnCheck XDB
remote-with-credentials
Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could se
45RISK
open ↗GitHub PoC
DHCP exploitation with DynoRoot (CVE-2018-1111)
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RISK
open ↗GitHub PoC★ 1
nex1less/CVE-2015-4852
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RISK
open ↗Metasploit600
Monitorr unauthenticated Remote Code Execution (RCE)
Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the s
40RISK
open ↗VulnCheck XDB
initial-access
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RISK
open ↗Metasploit600
WordPress AIT CSV Import Export Unauthenticated Remote Code Execution
AIT CSV import/export <= 3.0.3 - Unauthenticated Arbitrary File Upload
43RISK
open ↗Exploit-DB✓ VexDay Proof
Apache Tomcat - AJP 'Ghostcat' File Read/Inclusion (Metasploit)
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open ↗VulnCheck XDB
infoleak
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open ↗Exploit-DB
OpenCart Theme Journal 3.1.0 - Sensitive Data Exposure
The Journal theme before 3.1.0 for OpenCart allows exposure of sensitive data via SQL errors.
23RISK
open ↗GitHub PoC
rvermeulen/apache-struts-cve-2017-9805
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISK
open ↗GitHub PoC★ 12
Hikvision IP camera access bypass exploit, developed by golang.
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open ↗GitHub PoC★ 57
Exploit for Laravel Remote Code Execution with API_KEY (CVE-2018-15133)
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open ↗VulnCheck XDB
remote-with-credentials
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open ↗Exploit-DB
October CMS Build 465 - Arbitrary File Read Exploit (Authenticated)
Local File read vulnerability in OctoberCMS
33RISK
open ↗GitHub PoC★ 1
CVE-2020-25213 Wordpress File Manager 6.7 Plugin 0day exploit
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISK
open ↗GitHub PoC★ 5
xfiftyone/CVE-2020-14882
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open ↗GitHub PoC★ 7
Detection of RCE in Oracle's WebLogic Server CVE-2020-14882 / CVE-2020-14750
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open ↗VulnCheck XDB
initial-access
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted d
100RISK
open ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗GitHub PoC★ 2
A very simple buffer overflow using CVE-2013-4730 against PCman's FTP server
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RISK
open ↗VulnCheck XDB
initial-access
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open ↗GitHub PoC★ 3
zavke/CVE-2020-10189-ManageEngine
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted d
100RISK
open ↗GitHub PoC
MuirlandOracle/CVE-2014-6271-IPFire
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗GitHub PoC★ 36
海康威视未授权访问检测poc及口令爆破
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open ↗Metasploit600
Acronis TrueImage XPC Privilege Escalation
Acronis True Image 2019 update 1 through 2021 update 1 on macOS allows local privilege escalation due to an insecure XPC
18RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.