Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,697cataloged exploits
36,715CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,475Referência 23,264GitHub PoC 15,172VulnCheck XDB 8,920Nuclei 4,373Metasploit 3,493✓ verified onlyrecentpopularrisk
79,596 exploits
Exploit-DB
Git Submodule - Arbitrary Code Execution
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris - RSH Stack Clash Privilege Escalation (Metasploit)
An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficie
38RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris - RSH Stack Clash Privilege Escalation (Metasploit)
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported versio
38RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris - RSH Stack Clash Privilege Escalation (Metasploit)
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions t
38RISK
open ↗Exploit-DB
Centos Web Panel 0.9.8.480 - Multiple Vulnerabilities
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has XSS via the admin/fileManager2.php fm_current_dir parameter
23RISK
open ↗Exploit-DB
Centos Web Panel 0.9.8.480 - Multiple Vulnerabilities
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/ind
28RISK
open ↗Exploit-DB
NoMachine < 5.3.27 - Remote Code Execution
NoMachine before 5.3.27 and 6.x before 6.3.6 allows attackers to gain privileges via a Trojan horse wintab32.dll file lo
23RISK
open ↗Exploit-DB
Centos Web Panel 0.9.8.480 - Multiple Vulnerabilities
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/
60RISK
open ↗VulnCheck XDB
remote-with-credentials
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RISK
open ↗GitHub PoC★ 61
PoC + Docker Environment for Python PIL/Pillow Remote Shell Command Execution via Ghostscript CVE-2018-16509
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RISK
open ↗VulnCheck XDB
infoleak
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open ↗GitHub PoC★ 15
Automated version of CVE-2018-14847 (MikroTik Exploit)
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open ↗Exploit-DB
SugarCRM 6.5.26 - Cross-Site Scripting
Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthentic
23RISK
open ↗Exploit-DB
D-Link Routers - Plaintext Password
An issue was discovered on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.
28RISK
open ↗Exploit-DB
Phoenix Contact WebVisit 2985725 - Authentication Bypass
The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.
28RISK
open ↗Exploit-DB
Phoenix Contact WebVisit 2985725 - Authentication Bypass
The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism i
28RISK
open ↗Exploit-DB
D-Link Routers - Directory Traversal
Directory traversal vulnerability in the web interface on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L t
50RISK
open ↗Exploit-DB
D-Link Routers - Command Injection
An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02
60RISK
open ↗Metasploit0
Nuuo Central Management Server Authenticated Arbitrary File Upload
NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite co
23RISK
open ↗Metasploit300
Nuuo Central Management Authenticated SQL Server SQLi
NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can b
50RISK
open ↗Metasploit300
Nuuo Central Management Server Authenticated Arbitrary File Download
NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be res
23RISK
open ↗Metasploit300
Nuuo Central Management Server User Session Token Bruteforce
NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft SQL Server Management Studio 17.9 - '.xel' XML External Entity Injection
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft SQL Server Management Studio 17.9 - '.xmla' XML External Entity Injection
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious
28RISK
open ↗Exploit-DB
Phoenix Contact WebVisit 6.40.00 - Password Disclosure
Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coinciden
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft SQL Server Management Studio 17.9 - XML External Entity Injection
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious X
28RISK
open ↗Exploit-DB✓ VexDay Proof
jQuery-File-Upload 9.22.0 - Arbitrary File Upload
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISK
open ↗Exploit-DB
MicroTik RouterOS < 6.43rc3 - Remote Root
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open ↗Exploit-DB
Ektron CMS 9.20 SP2 - Improper Access Restrictions
Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote at
28RISK
open ↗Exploit-DB✓ VexDay Proof
ghostscript - executeonly Bypass with errorhandler Setup
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving err
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.