Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,104GitHub PoC 15,075VulnCheck XDB 8,883Nuclei 4,365Metasploit 3,493✓ verified onlyrecentpopularrisk
79,386 exploits
Exploit-DB
ZTE MF65 BD_HDV6MF65V1.0.0B05 - Cross-Site Scripting
All versions up to V1.0.0B05 of ZTE MF65 and all versions up to V1.0.0B02 of ZTE MF65M1 are impacted by cross-site scrip
23RISK
open ↗GitHub PoC★ 678
ES File Explorer Open Port Vulnerability - CVE-2019-6447
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISK
open ↗Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src
60RISK
open ↗Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.50 and earlier in src/main/java/org/jenkinsci/
23RISK
open ↗Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea
100RISK
open ↗Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins
60RISK
open ↗Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/
100RISK
open ↗Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISK
open ↗Exploit-DB
Roxy Fileman 1.4.5 - Unrestricted File Upload / Directory Traversal
Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.
60RISK
open ↗GitHub PoC
poc for 0263
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
76RISK
open ↗Exploit-DB
MyBB OUGC Awards Plugin 1.8.3 - Persistent Cross-Site Scripting
The OUGC Awards plugin before 1.8.19 for MyBB allows XSS via a crafted award reason that is mishandled on the awards pag
23RISK
open ↗Exploit-DB
Ajera Timesheets 9.10.16 - Deserialization of Untrusted Data
Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserializ
28RISK
open ↗Exploit-DB
Huawei E5330 21.210.09.00.158 - Cross-Site Request Forgery (Send SMS)
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13S
23RISK
open ↗GitHub PoC★ 12
漏洞利用工具
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open ↗Exploit-DB
Roxy Fileman 1.4.5 - Unrestricted File Upload / Directory Traversal
Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.
28RISK
open ↗Exploit-DB
PLC Wireless Router GPN2.4P21-C-CN - Cross-Site Scripting
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage
23RISK
open ↗Exploit-DB
KioWare Server Version 4.9.6 - Weak Folder Permissions Privilege Escalation
KioWare Server version 4.9.6 and older installs by default to "C:\kioware_com" with weak folder permissions granting any
23RISK
open ↗Exploit-DB
LayerBB 1.1.1 - Persistent Cross-Site Scripting
LayerBB 1.1.1 allows XSS via the titles of conversations (PMs).
23RISK
open ↗GitHub PoC
cve-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗GitHub PoC★ 1
cve-2018-11776
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open ↗GitHub PoC
cve-2018-7600
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open ↗GitHub PoC
cve-2015-5602
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is d
23RISK
open ↗GitHub PoC
CVE-2018-6389 PoC node js multisite with proxy
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISK
open ↗GitHub PoC
cve-2015-1427
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RISK
open ↗GitHub PoC
cve-2016-7434
The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a craf
35RISK
open ↗GitHub PoC
cve-2016-6515
The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password a
35RISK
open ↗GitHub PoC
CVE-2009-1324 - ASX to MP3 Converter Local Buffer Overflow. Tested on Windows XP Professional SP3
Stack-based buffer overflow in Mini-stream ASX to MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary cod
28RISK
open ↗GitHub PoC
cve-2015-3306
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISK
open ↗GitHub PoC
cve-2014-0160
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.