Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,697cataloged exploits
36,715CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,475Referência 23,264GitHub PoC 15,172VulnCheck XDB 8,920Nuclei 4,373Metasploit 3,493✓ verified onlyrecentpopularrisk
79,697 exploits
Exploit-DB
Joomla! Component Timetable Schedule 3.6.8 - SQL Injection
SQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Super Cms Blog Pro 1.0 - SQL Injection
SQL Injection exists in authors_post.php in Super Cms Blog Pro 1.0 via the author parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Social Factory 3.8.3 - SQL Injection
SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radiu
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Article Factory Manager 4.3.9 - SQL Injection
SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_e
23RISK
open ↗Exploit-DB
Joomla! Component Collection Factory 4.1.9 - SQL Injection
SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir para
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Penny Auction Factory 2.0.4 - SQL Injection
SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order p
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Swap Factory 2.2.1 - SQL Injection
SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Jobs Factory 2.0.4 - SQL Injection
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
23RISK
open ↗Exploit-DB
Joomla! Component AlphaIndex Dictionaries 1.0 - SQL Injection
SQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::SVGTRefElement::updateReferencedText' Use-After-Free
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::RenderLayer::updateDescendantDependentFlags' Use-After-Free
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::SVGTextLayoutAttributes::context' Use-After-Free
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Raffle Factory 3.5.2 - SQL Injection
SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order paramete
23RISK
open ↗Metasploit0
Google Chrome 67, 68 and 69 Object.create exploit
Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbit
100RISK
open ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::RenderMultiColumnSet::updateMinimumColumnHeight' Use-After-Free
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::RenderTreeBuilder::removeAnonymousWrappersForInlineChildrenIfNeeded' Use-After-Free
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::AXObjectCache::handleMenuItemSelected' Use-After-Free
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISK
open ↗Exploit-DB✓ VexDay Proof
Solaris - 'EXTREMEPARR' dtappgather Privilege Escalation (Metasploit)
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Common Desktop Environment (C
38RISK
open ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::InlineTextBox::paint' Out-of-Bounds Read
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::SVGAnimateElementBase::resetAnimatedType' Use-After-Free
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
28RISK
open ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::Node::ensureRareData' Use-After-Free
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISK
open ↗Exploit-DB
MyBB Visual Editor 1.8.18 - Cross-Site Scripting
A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.
45RISK
open ↗Exploit-DB
Joomla! Component CW Article Attachments 1.0.6 - 'id' SQL Injection
The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 fo
23RISK
open ↗Exploit-DB
LG SuperSign EZ CMS 2.5 - Remote Code Execution
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getT
50RISK
open ↗VulnCheck XDB
infoleak
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open ↗GitHub PoC★ 113
DVR-Exploiter a Bash Script Program Exploit The DVR's Based on CVE-2018-9995
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open ↗VulnCheck XDB
info-leak
The HTTP web-management application on Edgewater Networks Edgemarc appliances has a hidden page that allows for user-def
35RISK
open ↗Exploit-DB✓ VexDay Proof
WebRTC - FEC Out-of-Bounds Read
An out of bounds read in forward error correction code in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebRTC - VP9 Processing Use-After-Free
A use after free in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.