Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,104GitHub PoC 15,075VulnCheck XDB 8,883Nuclei 4,365Metasploit 3,493✓ verified onlyrecentpopularrisk
79,386 exploits
Exploit-DB
OpenSSH < 7.7 - User Enumeration (2)
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open ↗Exploit-DB
Xorg X11 Server (AIX) - Local Privilege Escalation
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RISK
open ↗Exploit-DB
NEC Univerge Sv9100 WebPro - 6.00 - Predictable Session ID / Clear Text Password Storage
NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure vi
28RISK
open ↗Exploit-DB
NEC Univerge Sv9100 WebPro - 6.00 - Predictable Session ID / Clear Text Password Storage
NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.
28RISK
open ↗Exploit-DB
DomainMOD 4.11.01 - Owner name Field Cross-Site Scripting
DomainMOD through 4.11.01 has XSS via the assets/add/account-owner.php Owner name field.
38RISK
open ↗Exploit-DB
DomainMOD 4.11.01 - Custom SSL Fields Cross-Site Scripting
DomainMOD through 4.11.01 has XSS via the admin/ssl-fields/add.php notes field for Custom SSL Fields.
38RISK
open ↗Exploit-DB✓ VexDay Proof
Wireshark - 'find_signature' Heap Out-of-Bounds Read
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/v
28RISK
open ↗Exploit-DB
NUUO NVRMini2 3.9.1 - (Authenticated) Command Injection
NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted reques
28RISK
open ↗Exploit-DB
FreshRSS 1.11.1 - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject
23RISK
open ↗Exploit-DB
Dolibarr ERP/CRM 8.0.3 - Cross-Site Scripting
Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS.
23RISK
open ↗Exploit-DB
DomainMOD 4.11.01 - Registrar Cross-Site Scripting
DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar.
38RISK
open ↗Exploit-DB
DomainMOD 4.11.01 - Custom Domain Fields Cross-Site Scripting
DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Doma
23RISK
open ↗Exploit-DB
CyberArk 9.7 - Memory Disclosure
CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replay
28RISK
open ↗Exploit-DB
Apache Superset < 0.23 - Remote Code Execution
Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to pos
35RISK
open ↗GitHub PoC
CVE-2014-4511
Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in
60RISK
open ↗GitHub PoC★ 1
A collection of code pertaining to CVE-2016-0728 (various authors)
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISK
open ↗VulnCheck XDB
remote-with-credentials
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISK
open ↗GitHub PoC
This is an exploitation guide for CVE-2016-2233
Stack-based buffer overflow in the inbound_cap_ls function in common/inbound.c in HexChat 2.10.2 allows remote IRC serve
35RISK
open ↗GitHub PoC
A VENOM (CVE-2015-3456) Exploit / PoC written in C.
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a
28RISK
open ↗GitHub PoC
CVE-2016-1240 exploit and patch
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debia
38RISK
open ↗GitHub PoC★ 104
CVE-2018-8021 Proof-Of-Concept and Exploit
Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to pos
35RISK
open ↗GitHub PoC★ 39
PrestaShop (1.6.x <= 1.6.1.23 or 1.7.x <= 1.7.4.4) Back Office Remote Code Execution (CVE-2018-19126)
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file u
28RISK
open ↗Exploit-DB
PhpSpreadsheet < 1.5.0 - XML External Entity (XXE)
securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 enco
23RISK
open ↗Exploit-DB✓ VexDay Proof
VBScript - 'OLEAUT32!VariantClear' and 'scrrun!VBADictionary::put_Item' Use-After-Free
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
35RISK
open ↗Exploit-DB✓ VexDay Proof
VBScript - 'rtFilter' Out-of-Bounds Read
An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which coul
35RISK
open ↗Exploit-DB
Schneider Electric PLC - Session Calculation Authentication Bypass
A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware ver
35RISK
open ↗GitHub PoC★ 50
All about CVE-2018-14667; From what it is to how to successfully exploit it.
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RISK
open ↗VulnCheck XDB
client-side
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RISK
open ↗Exploit-DB
xorg-x11-server < 1.20.3 - 'modulepath' Local Privilege Escalation
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RISK
open ↗Exploit-DB✓ VexDay Proof
Unitrends Enterprise Backup - bpserverd Privilege Escalation (Metasploit)
It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL i
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.