Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,104GitHub PoC 15,075VulnCheck XDB 8,883Nuclei 4,365Metasploit 3,493✓ verified onlyrecentpopularrisk
79,305 exploits
GitHub PoC★ 5
Exploiting CVE-2016-10277 for Secure Boot and Device Locking bypass
An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute
23RISK
open ↗GitHub PoC
cve-2018-3811
SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthentica
35RISK
open ↗GitHub PoC
cve-2018-3810
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RISK
open ↗Exploit-DB
SureMDM < 2018-11 Patch - Local / Remote File Inclusion
An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 - Sandbox Escapes due to Type Confusions and Memory Safety Issues in iohideventsystem
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.1
23RISK
open ↗GitHub PoC★ 16
iOS 12.0 -> 12.1.2 Incomplete Osiris Jailbreak with CVE-2019-6225 by GeoSn0w (FCE365)
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.
28RISK
open ↗Exploit-DB✓ VexDay Proof
macOS XNU - Copy-on-Write Behaviour Bypass via Partial-Page Truncation of File
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Moja
23RISK
open ↗Exploit-DB✓ VexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 - Arbitrary mach Port Name Deallocation in XPC Services due to Invalid mach Message Parsing in _xpc_serializer_unpack
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave
23RISK
open ↗Exploit-DB✓ VexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 XNU - 'vm_map_copy' Optimization which Requires Atomicity isn't Atomic
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 12.1.3, macOS Moja
23RISK
open ↗Exploit-DB✓ VexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 - Kernel Heap Overflow in PF_KEY due to Lack of Bounds Checking when Retrieving Statistics
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3,
23RISK
open ↗VulnCheck XDB
initial-access
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open ↗Exploit-DB✓ VexDay Proof
iOS/macOS 10.13.6 - 'if_ports_used_update_wakeuuid()' 16-byte Uninitialized Kernel Stack Disclosure
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input
23RISK
open ↗GitHub PoC★ 1
NSE script to scan for Cisco routers vulnerable to CVE-2019-1653
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open ↗GitHub PoC★ 1
Python 3 implementation of an existing CVE-2011-3556 proof of concept (PoC).
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and ear
60RISK
open ↗GitHub PoC
Exploit script for Crossfire 1.9.0
Buffer overflow in the SetUp function in socket/request.c in CrossFire 1.9.0 allows remote attackers to execute arbitrar
28RISK
open ↗VulnCheck XDB
initial-access
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open ↗Exploit-DB
Rundeck Community Edition < 3.0.13 - Persistent Cross-Site Scripting
An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascrip
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco Firepower Management Center 6.2.2.2 / 6.2.3 - Cross-Site Scripting
Cisco Firepower Management Center Cross-Site Scripting Vulnerability
33RISK
open ↗Exploit-DB
AirTies Air5341 Modem 1.0.0.12 - Cross-Site Request Forgery
AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF.
28RISK
open ↗Exploit-DB
CloudMe Sync 1.11.2 Buffer Overflow - WoW64 (DEP Bypass)
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RISK
open ↗Exploit-DB
MyBB IP History Logs Plugin 1.0.2 - Cross-Site Scripting
An issue was discovered in the User IP History Logs (aka IP_History_Logs) plugin 1.0.2 for MyBB. There is XSS via the ad
23RISK
open ↗Exploit-DB
Sricam gSOAP 2.8 - Denial of Service
Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server
28RISK
open ↗Exploit-DB
LogonBox Limited / Hypersocket Nervepoint Access Manager - (Unauthenticated) Insecure Direct Object Reference
An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 thr
23RISK
open ↗Exploit-DB
Cisco RV300 / RV320 - Information Disclosure
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open ↗GitHub PoC★ 2
DVR username password recovery.
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open ↗VulnCheck XDB
remote-with-credentials
Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-in
35RISK
open ↗Metasploit600
Schneider Electric Pelco Endura NET55XX Encoder
A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 wh
50RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco RV320 Dual Gigabit WAN VPN Router 1.4.2.15 - Command Injection
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RISK
open ↗Exploit-DB✓ VexDay Proof
iOS/macOS - 'task_swap_mach_voucher()' Use-After-Free
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.
28RISK
open ↗Exploit-DB
Lua 5.3.5 - 'debug.upvaluejoin' Use After Free
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attack
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.