Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,051GitHub PoC 15,051VulnCheck XDB 8,883Nuclei 4,361Metasploit 3,493✓ verified onlyrecentpopularrisk
79,305 exploits
Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - Out-of-Bounds Read in CI!CipFixImageType While Parsing Malformed PE File
An information disclosure vulnerability exists in the way that the Windows Code Integrity Module handles objects in memo
23RISK
open ↗GitHub PoC★ 2
The study of vulnerability CVE-2017-3066. Java deserialization
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier hav
100RISK
open ↗Exploit-DB✓ VexDay Proof
XNU - Remote Double-Free via Data Race in IPComp Input Path
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15, tvOS
23RISK
open ↗VulnCheck XDB
initial-access
From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the su
50RISK
open ↗VulnCheck XDB
initial-access
Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.
35RISK
open ↗GitHub PoC★ 2
KRAMER VIAware 2.5.0719.1034 - Remote Code Execution
Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.
28RISK
open ↗GitHub PoC
Investigation of CVE-2018-11776 vulnerability that allows attackers to remotely execute code and gain control over Apache Struts-based applications.
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open ↗Exploit-DB
IBM Bigfix Platform 9.5.9.62 - Arbitrary File Upload
IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root pr
53RISK
open ↗Exploit-DB
vBulletin 5.0 < 5.5.4 - 'updateAvatar' Authenticated Remote Code Execution
vBulletin through 5.5.4 mishandles custom avatars.
28RISK
open ↗Exploit-DB
Subrion 4.2.1 - 'Email' Persistant Cross-Site Scripting
Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" i
23RISK
open ↗Exploit-DB
CheckPoint Endpoint Security Client/ZoneAlarm 15.4.062.17802 - Privilege Escalation
A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security clien
23RISK
open ↗GitHub PoC★ 4
infiniteLoopers/CVE-2019-11932
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open ↗GitHub PoC★ 4
Double-Free BUG in WhatsApp exploit poc.
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open ↗Exploit-DB✓ VexDay Proof
Android - Binder Driver Use-After-Free
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open ↗GitHub PoC★ 79
timwr/CVE-2019-2215
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open ↗VulnCheck XDB
local
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open ↗GitHub PoC★ 209
Simple POC for exploiting WhatsApp double-free bug in DDGifSlurp in decoding.c in libpl_droidsonroids_gif
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open ↗GitHub PoC
Rails 3 PoC of CVE-2019-5418
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open ↗GitHub PoC★ 4
This is a Automated Generate Payload for CVE-2019-11932 (WhatsApp Remote Code Execution)
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open ↗GitHub PoC
Remediation task for CVE-2018-15686, CVE-2018-16866, and CVE-2018-16888 affecting SystemD in EL7
systemd: reexec state injection: fgets() on overlong lines leads to line splitting
41RISK
open ↗Exploit-DB
AnchorCMS < 0.12.3a - Information Disclosure
An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contain
60RISK
open ↗GitHub PoC★ 8
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 | XSS to RCE
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the mali
23RISK
open ↗Exploit-DB
mintinstall 7.9.9 - Code Execution
mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by a
23RISK
open ↗GitHub PoC★ 267
double-free bug in WhatsApp exploit poc
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open ↗Exploit-DB✓ VexDay Proof
DOUBLEPULSAR - Payload Execution and Neutralization (Metasploit)
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open ↗Exploit-DB✓ VexDay Proof
DOUBLEPULSAR - Payload Execution and Neutralization (Metasploit)
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open ↗VulnCheck XDB
initial-access
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISK
open ↗Exploit-DB✓ VexDay Proof
DOUBLEPULSAR - Payload Execution and Neutralization (Metasploit)
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open ↗GitHub PoC★ 1
CVE-2019-17080
mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by a
23RISK
open ↗Exploit-DB✓ VexDay Proof
DOUBLEPULSAR - Payload Execution and Neutralization (Metasploit)
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.