Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,967GitHub PoC 13,264VulnCheck XDB 8,156Nuclei 4,201Metasploit 3,462✓ verified onlyrecentpopularrisk
22,786 exploits
Exploit-DB
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allo
28RISK
open ↗Exploit-DB
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could
50RISK
open ↗Exploit-DB
WAGO e!DISPLAY 7300T - Multiple Vulnerabilities
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions
23RISK
open ↗Exploit-DB
WAGO e!DISPLAY 7300T - Multiple Vulnerabilities
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerabilit
35RISK
open ↗Exploit-DB
Microsoft Windows - POP/MOV SS Local Privilege Elevation (Metasploit)
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RISK
open ↗Exploit-DB
Zeta Producer Desktop CMS 14.2.0 - Remote Code Execution / Local File Disclosure
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated remote code
28RISK
open ↗Exploit-DB
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow auth
28RISK
open ↗Exploit-DB
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authe
28RISK
open ↗Exploit-DB
Apache CouchDB - Arbitrary Command Execution (Metasploit)
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RISK
open ↗Exploit-DB
Grundig Smart Inter@ctive 3.0 - Cross-Site Request Forgery
Grundig Smart Inter@ctive TV 3.0 devices allow CSRF attacks via a POST request to TCP port 8085 containing a predictable
23RISK
open ↗Exploit-DB
G DATA Total Security 25.4.0.3 - Activex Buffer Overflow
The GDASPAMLib.AntiSpam ActiveX control ASK\GDASpam.dll in G DATA Total Security 25.4.0.3 has a buffer overflow via a lo
23RISK
open ↗Exploit-DB
phpMyAdmin - (Authenticated) Remote Code Execution (Metasploit)
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open ↗Exploit-DB
Zeta Producer Desktop CMS 14.2.0 - Remote Code Execution / Local File Disclosure
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclos
38RISK
open ↗Exploit-DB
Cela Link CLR-M20 2.7.1.6 - Arbitrary File Upload
CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml)
28RISK
open ↗Exploit-DB
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticate
50RISK
open ↗Exploit-DB
WAGO e!DISPLAY 7300T - Multiple Vulnerabilities
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerabilit
23RISK
open ↗Exploit-DB
Apache CouchDB - Arbitrary Command Execution (Metasploit)
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RISK
open ↗Exploit-DB
Microsoft Edge Chakra JIT - BoundFunction::NewInstance Out-of-Bounds Read
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
35RISK
open ↗Exploit-DB
Microsoft Edge Chakra JIT - Out-of-Bounds Reads/Writes
An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could
35RISK
open ↗Exploit-DB
Microsoft Edge Chakra JIT - Type Confusion with Hoisted SetConcatStrMultiItemBE Instructions
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISK
open ↗Exploit-DB
IBM QRadar SIEM - Remote Code Execution (Metasploit)
IBM QRadar Incident Forensics (IBM QRadar SIEM 7.2, and 7.3) could allow a remote attacker to bypass authentication and
60RISK
open ↗Exploit-DB
IBM QRadar SIEM - Remote Code Execution (Metasploit)
IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM
50RISK
open ↗Exploit-DB
Instagram-Clone Script 2.0 - Cross-Site Scripting
edit_requests.php in yTakkar Instagram-clone through 2018-04-23 has XSS via an onmouseover payload because of an inadequ
23RISK
open ↗Exploit-DB
JavaScript Core - Arbitrary Code Execution
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
28RISK
open ↗Exploit-DB
IBM QRadar SIEM - Remote Code Execution (Metasploit)
IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be r
43RISK
open ↗Exploit-DB
Linux Kernel < 4.13.9 (Ubuntu 16.04 / Fedora 27) - Local Privilege Escalation
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open ↗Exploit-DB
Activision Infinity Ward Call of Duty Modern Warfare 2 - Buffer Overflow
Stack-based buffer overflow in Activision Infinity Ward Call of Duty Modern Warfare 2 before 2018-04-26 allows remote at
35RISK
open ↗Exploit-DB
Tor Browser < 0.3.2.10 - Use After Free (PoC)
A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of se
28RISK
open ↗Exploit-DB
Oracle WebLogic 12.1.2.0 - RMI Registry UnicastRef Object Java Deserialization Remote Code Execution
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RISK
open ↗Exploit-DB
Airties AIR5444TT - Cross-Site Scripting
Airties 5444 1.0.0.18 and 5444TT 1.0.0.18 devices allow XSS.
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.