Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,596cataloged exploits
36,656CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,475Referência 23,212GitHub PoC 15,164VulnCheck XDB 8,883Nuclei 4,369Metasploit 3,493✓ verified onlyrecentpopularrisk
79,596 exploits
GitHub PoC
cve-2018-14667 demo
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RISK
open ↗GitHub PoC★ 83
Tool for CVE-2018-16323
ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that ha
35RISK
open ↗GitHub PoC★ 3
CVE-2018-16509 (Ghostscript contains multiple -dSAFER sandbox bypass vulnerabilities)
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RISK
open ↗Exploit-DB✓ VexDay Proof
Linux - Broken uid/gid Mapping for Nested User Namespaces
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISK
open ↗Exploit-DB
DomainMOD 4.11.01 - 'raid' Cross-Site Scripting
DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter.
38RISK
open ↗GitHub PoC
Implementation of CVE-2018-10933 with CIDR block scanner
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open ↗Metasploit500
Linux Nested User Namespace idmap Limit Local Privilege Escalation
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISK
open ↗Exploit-DB
PHP-Proxy 5.1.0 - Local File Inclusion
PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users w
28RISK
open ↗Exploit-DB
WordPress Plugin Ninja Forms 3.3.17 - Cross-Site Scripting
XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes
38RISK
open ↗Exploit-DB✓ VexDay Proof
Dell OpenManage Network Manager 6.2.0.51 SP3 - Multiple Vulnerabilities
Improper Authorization Vulnerability
28RISK
open ↗Metasploit600
Nagios XI Magpie_debug.php Root Remote Code Execution
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.
50RISK
open ↗Exploit-DB
ntpd 4.2.8p10 - Out-of-Bounds Read (PoC)
The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-
28RISK
open ↗Metasploit600
Nagios XI Magpie_debug.php Root Remote Code Execution
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP r
60RISK
open ↗Exploit-DB✓ VexDay Proof
Dell OpenManage Network Manager 6.2.0.51 SP3 - Multiple Vulnerabilities
Insecure MySQL Configuration Vulnerability
23RISK
open ↗Exploit-DB
Advanced Comment System 1.0 - SQL Injection
internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability bec
23RISK
open ↗Exploit-DB
SwitchVPN for macOS 2.1012.03 - Privilege Escalation
A local privilege escalation vulnerability has been identified in the SwitchVPN client 2.1012.03 for macOS. Due to over-
23RISK
open ↗Exploit-DB
CentOS Web Panel 0.9.8.740 - Cross-Site Request Forgery / Cross-Site Scripting
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as dem
23RISK
open ↗Exploit-DB✓ VexDay Proof
Evince 3.24.0 - Command Injection
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to e
50RISK
open ↗Exploit-DB
CentOS Web Panel 0.9.8.740 - Cross-Site Request Forgery / Cross-Site Scripting
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demo
23RISK
open ↗Exploit-DB
CentOS Web Panel 0.9.8.740 - Cross-Site Request Forgery / Cross-Site Scripting
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco Immunet < 6.2.0 / Cisco AMP For Endpoints 6.2.0 - Denial of Service
Cisco Immunet and Cisco AMP for Endpoints System Scan Denial of Service Vulnerability
33RISK
open ↗Exploit-DB
ClipperCMS 1.3.3 - Cross-Site Request Forgery (File Upload)
ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an
23RISK
open ↗Metasploit400
Redis Replication Code Execution
Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10,
30RISK
open ↗Exploit-DB
xorg-x11-server < 1.20.1 - Local Privilege Escalation
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RISK
open ↗GitHub PoC
My first try to code my own LPE exploit.
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RISK
open ↗Exploit-DB
WordPress Plugin Media File Manager 1.4.2 - Directory Traversal / Cross-Site Scripting
The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the di
28RISK
open ↗Exploit-DB
WordPress Plugin Media File Manager 1.4.2 - Directory Traversal / Cross-Site Scripting
The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the
23RISK
open ↗Exploit-DB
WordPress Plugin Media File Manager 1.4.2 - Directory Traversal / Cross-Site Scripting
The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename)
28RISK
open ↗Exploit-DB
WordPress Plugin Media File Manager 1.4.2 - Directory Traversal / Cross-Site Scripting
The Media File Manager plugin 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir para
28RISK
open ↗GitHub PoC★ 9
CVE-2016-4657 web-kit vulnerability for ios 9.3, nintendo switch browser vulnerability
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.