Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,104GitHub PoC 15,075VulnCheck XDB 8,883Nuclei 4,365Metasploit 3,493✓ verified onlyrecentpopularrisk
79,305 exploits
Exploit-DB✓ VexDay Proof
DomainMOD 4.11.01 - 'assets/edit/host.php?whid=5' Cross-Site Scripting
DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field.
38RISK
open ↗Exploit-DB
Rukovoditel Project Management CRM 2.4.1 - Cross-Site Scripting
Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring.
23RISK
open ↗GitHub PoC★ 658
PoC for CVE-2019-5736
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open ↗Exploit-DB
Apple macOS 10.13.5 - Local Privilege Escalation
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Windows Ser
23RISK
open ↗Exploit-DB
runc < 1.0-rc6 (Docker < 18.09.2) - Container Breakout (2)
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open ↗GitHub PoC★ 69
exploit for CVE-2018-4193
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Windows Ser
23RISK
open ↗VulnCheck XDB
local
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open ↗VulnCheck XDB
local
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open ↗Exploit-DB
runc < 1.0-rc6 (Docker < 18.09.2) - Container Breakout (1)
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open ↗Exploit-DB
Skyworth GPON HomeGateways and Optical Network Terminals - Stack Overflow
An issue was discovered on Shenzhen Skyworth DT741 Converged Intelligent Terminal (G/EPON+IPTV) SDOTBGN1, DT721-cb SDOTB
35RISK
open ↗GitHub PoC★ 681
Linux privilege escalation exploit via snapd (CVE-2019-7304)
Local privilege escalation via snapd socket
53RISK
open ↗Exploit-DB✓ VexDay Proof
Android - binder Use-After-Free via fdget() Optimization
In several functions of binder.c, there is possible memory corruption due to a use after free. This could lead to local
23RISK
open ↗Exploit-DB✓ VexDay Proof
Android - binder Use-After-Free of VMA via race Between reclaim and munmap
In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking. This could lead to
23RISK
open ↗Exploit-DB✓ VexDay Proof
BlogEngine.NET 3.3.6 - Directory Traversal / Remote Code Execution
An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in Po
35RISK
open ↗GitHub PoC★ 210
Unweaponized Proof of Concept for CVE-2019-5736 (Docker escape)
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open ↗Exploit-DB✓ VexDay Proof
NUUO NVRmini - upgrade_handle.php Remote Command Execution (Metasploit)
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir par
100RISK
open ↗Exploit-DB
CentOS Web Panel 0.9.8.763 - Persistent Cross-Site Scripting
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.763 is vulnerable to Stored/Persistent XSS for the "Package
23RISK
open ↗Exploit-DB
Indusoft Web Studio 8.1 SP2 - Remote Code Execution
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition)
28RISK
open ↗Exploit-DB
Indusoft Web Studio 8.1 SP2 - Remote Code Execution
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition)
28RISK
open ↗Exploit-DB✓ VexDay Proof
Evince - CBT File Command Injection (Metasploit)
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to e
50RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - DeleteRangeTimelineOperation Type Confusion (Metasploit)
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as
100RISK
open ↗GitHub PoC
Takes advantage of CVE-2018-10933
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open ↗GitHub PoC★ 67
Programa ideal para robar toda la información de un dispositivo remotamente a través de la aplicación AirDroid. [CVE-2019-9599] (https://www.exploit-db.com/exploits/46337)
The AirDroid application through 4.2.1.6 for Android allows remote attackers to cause a denial of service (service crash
28RISK
open ↗VulnCheck XDB
initial-access
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web U
100RISK
open ↗GitHub PoC★ 5
VMware NSX SD-WAN command injection vulnerability
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web U
100RISK
open ↗GitHub PoC
cve-2018-15877
The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell meta
60RISK
open ↗Metasploit600
RARLAB WinRAR ACE Format Input Validation Remote Code Execution
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open ↗Exploit-DB
OpenMRS Platform < 2.24.0 - Insecure Object Deserialization
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RISK
open ↗Exploit-DB
Zyxel VMG3312-B10B DSL-491HNU-B1B v2 Modem - Cross-Site Request Forgery
ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF.
28RISK
open ↗Metasploit300
OpenMRS Java Deserialization RCE
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.