Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,051GitHub PoC 15,051VulnCheck XDB 8,883Nuclei 4,361Metasploit 3,493✓ verified onlyrecentpopularrisk
79,305 exploits
Exploit-DB
Apache Axis 1.4 - Remote Code Execution
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2
45RISK
open ↗GitHub PoC★ 22
Confluence Widget Connector path traversal (CVE-2019-3396)
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open ↗Exploit-DB
Microsoft Windows - AppX Deployment Service Privilege Escalation
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RISK
open ↗Exploit-DB
TP-LINK TL-WR940N / TL-WR941ND - Buffer Overflow
TP-Link TL-WR940N is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the ipAddrDispos
28RISK
open ↗Metasploit300
AppXSvc Hard Link Privilege Escalation
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RISK
open ↗GitHub PoC
xiaoshuier/CVE-2019-3396
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open ↗VulnCheck XDB
initial-access
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open ↗Exploit-DB✓ VexDay Proof
QNAP Netatalk < 3.1.12 - Authentication Bypass
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking
70RISK
open ↗Exploit-DB
ShoreTel Connect ONSITE < 19.49.1500.0 - Multiple Vulnerabilities
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attack
23RISK
open ↗Exploit-DB
ManageEngine ServiceDesk Plus 9.3 - User Enumeration
Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticat
23RISK
open ↗Exploit-DB
Apache 2.4.17 < 2.4.38 - 'apache2ctl graceful' 'logrotate' Local Privilege Escalation
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privilege
83RISK
open ↗Exploit-DB
SaLICru -SLC-20-cube3(5) - HTML Injection
A reflected HTML injection vulnerability on Salicru SLC-20-cube3(5) devices running firmware version cs121-SNMP v4.54.82
23RISK
open ↗Exploit-DB
ShoreTel Connect ONSITE < 19.49.1500.0 - Multiple Vulnerabilities
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to
23RISK
open ↗Exploit-DB
Bolt CMS 3.6.6 - Cross-Site Request Forgery / Remote Code Execution
Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to ex
23RISK
open ↗Exploit-DB
ShoreTel Connect ONSITE < 19.49.1500.0 - Multiple Vulnerabilities
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Core 5.0.0 - Crop-image Shell Upload (Metasploit)
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can
60RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Core 5.0.0 - Crop-image Shell Upload (Metasploit)
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RISK
open ↗GitHub PoC★ 239
PoC code for CVE-2019-0841 Privilege Escalation vulnerability
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RISK
open ↗GitHub PoC★ 1
likekabin/CVE-2019-0604_sharepoint_CVE
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RISK
open ↗GitHub PoC★ 4
ManageEngine Service Desk Plus 10.0 Privilaged account Hijacking
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session
28RISK
open ↗Exploit-DB✓ VexDay Proof
SpiderMonkey - IonMonkey Compiled Code Fails to Update Inferred Property Types (Type Confusion)
Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
iOS < 12.2 / macOS < 10.14.4 XNU - pidversion Increment During execve is Unsafe
A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebKit JavaScriptCore - CodeBlock Dangling Watchpoints Use-After-Free
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebKit JavaScriptCore - 'createRegExpMatchesArray' Type Confusion
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS
76RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco RV320 and RV325 - Unauthenticated Remote Code Execution (Metasploit)
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco RV320 and RV325 - Unauthenticated Remote Code Execution (Metasploit)
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open ↗Exploit-DB✓ VexDay Proof
WebKit JavaScriptCore - Out-Of-Bounds Access in FTL JIT due to LICM Moving Array Access Before the Bounds Check
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12
28RISK
open ↗GitHub PoC
Example and demo setup for Heartbleed vulnerability (CVE-2014-0160). This should be used for testing purposes only!💔
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open ↗GitHub PoC
artofscripting-zz/cmty-ssl-heartbleed-CVE-2014-0160-HTTP-HTTPS
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.