Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,622cataloged exploits
36,681CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,475Referência 23,233GitHub PoC 15,165VulnCheck XDB 8,883Nuclei 4,373Metasploit 3,493✓ verified onlyrecentpopularrisk
79,596 exploits
VulnCheck XDB
client-side
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RISK
open ↗GitHub PoC
Setup, exploit and patch for CVE-2009-4092 Simplog CSRF
Cross-site request forgery (CSRF) vulnerability in user.php in Simplog 0.9.3.2, and possibly earlier, allows remote atta
23RISK
open ↗GitHub PoC★ 1
Wordpress plugin Site-Editor v1.1.1 LFI exploit
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RISK
open ↗GitHub PoC★ 10
PHPMyAdmin v4.8.0 and v.4.8.1 LFI exploit
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open ↗VulnCheck XDB
initial-access
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RISK
open ↗GitHub PoC★ 5
CMS Made Simple 2.2.7 RCE exploit
In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code ex
28RISK
open ↗VulnCheck XDB
remote-with-credentials
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open ↗GitHub PoC★ 3
beraphin/CVE-2018-6789
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISK
open ↗VulnCheck XDB
remote-with-credentials
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open ↗VulnCheck XDB
initial-access
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISK
open ↗GitHub PoC
matlink/CVE-2018-17456
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RISK
open ↗Metasploit300
WordPress WP GDPR Compliance Plugin Privilege Escalation
The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to exe
60RISK
open ↗GitHub PoC
来自:https://www.freebuf.com/articles/web/31700.html
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open ↗Exploit-DB
OpenSLP 2.0.0 - Multiple Vulnerabilities
Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have
28RISK
open ↗Exploit-DB✓ VexDay Proof
FaceTime - RTP Video Processing Heap Corruption
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1,
23RISK
open ↗Exploit-DB✓ VexDay Proof
FaceTime - 'VCPDecompressionDecodeFrame' Memory Corruption
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.
23RISK
open ↗Exploit-DB✓ VexDay Proof
FaceTime - 'readSPSandGetDecoderParams' Stack Corruption
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.
23RISK
open ↗Exploit-DB
libiec61850 1.3 - Stack Based Buffer Overflow
An issue has been found in libIEC61850 v1.3. It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_pu
28RISK
open ↗Exploit-DB✓ VexDay Proof
blueimp's jQuery 9.22.0 - (Arbitrary) File Upload (Metasploit)
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISK
open ↗VulnCheck XDB
local
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for
86RISK
open ↗Exploit-DB
CMS Made Simple 2.2.7 - (Authenticated) Remote Code Execution
In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code ex
28RISK
open ↗GitHub PoC★ 14
Exploit for PlaySMS 1.4 authenticated RCE
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RISK
open ↗VulnCheck XDB
local
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open ↗GitHub PoC★ 21
an RCE (remote command execution) approach of CVE-2018-7750
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x
28RISK
open ↗Metasploit500
VyOS restricted-shell Escape and Privilege Escalation
A privilege escalation issue was discovered in VyOS 1.1.8. The default configuration also allows operator users to execu
23RISK
open ↗Exploit-DB
PHP Proxy 3.0.3 - Local File Inclusion
In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI UR
50RISK
open ↗Exploit-DB
LiquidVPN 1.36 / 1.37 - Privilege Escalation
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RISK
open ↗Exploit-DB
LiquidVPN 1.36 / 1.37 - Privilege Escalation
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RISK
open ↗Exploit-DB
Advantech WebAccess SCADA 8.3.2 - Remote Code Execution
Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could
23RISK
open ↗Exploit-DB
Advantech WebAccess SCADA 8.3.2 - Remote Code Execution
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any f
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.