Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,697cataloged exploits
36,715CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,475Referência 23,264GitHub PoC 15,172VulnCheck XDB 8,920Nuclei 4,373Metasploit 3,493✓ verified onlyrecentpopularrisk
79,697 exploits
Exploit-DB
Apache Syncope 2.0.7 - Remote Code Execution
An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and un
28RISK
open ↗Exploit-DB
Apache Portals Pluto 3.0.0 - Remote Code Execution
The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote a
35RISK
open ↗Exploit-DB
SynaMan 4.0 build 1488 - SMTP Credential Disclosure
Synametrics SynaMan 4.0 build 1488 uses cleartext password storage for SMTP credentials.
23RISK
open ↗Exploit-DB
Apple macOS 10.13.4 - Denial of Service (PoC)
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Identity Governance and Intelligence 5.2.3.2 / 5.2.4 - SQL Injection
IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 is vulnerable to SQL injection. A remote attacker co
46RISK
open ↗Exploit-DB
MyBB 1.8.17 - Cross-Site Scripting
An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can gener
23RISK
open ↗VulnCheck XDB
initial-access
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web U
100RISK
open ↗Exploit-DB
SynaMan 4.0 build 1488 - (Authenticated) Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Synametrics SynaMan 4.0 build 1488 via the (1) Main heading or (2
23RISK
open ↗Exploit-DB
CirCarLife SCADA 4.3.0 - Credential Disclosure
CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/lo
50RISK
open ↗Exploit-DB
Rubedo CMS 3.4.0 - Directory Traversal
Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attac
50RISK
open ↗GitHub PoC★ 1
veloCloud VMWare - Vulnerability
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web U
100RISK
open ↗Exploit-DB
LG Smart IP Camera 1508190 - Backup File Download
LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /u
23RISK
open ↗Metasploit600
Adobe ColdFusion CKEditor unrestricted file upload
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISK
open ↗GitHub PoC★ 7
C# implementation of BasuCert/WinboxPoC [Winbox Critical Vulnerability (CVE-2018-14847)]
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open ↗VulnCheck XDB
initial-access
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open ↗Exploit-DB✓ VexDay Proof
Android - 'zygote->init;' Chain from USB Privilege Escalation
In the SELinux permissions of crash_dump.te, there is a permissions bypass due to a missing restriction. This could lead
23RISK
open ↗GitHub PoC★ 2
Simple poc of CVE-2018-8353 Microsoft Scripting Engine Use After Free
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
35RISK
open ↗Exploit-DB✓ VexDay Proof
Ghostscript - Failed Restore Command Execution (Metasploit)
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RISK
open ↗Exploit-DB✓ VexDay Proof
Apache Struts 2 - Namespace Redirect OGNL Injection (Metasploit)
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open ↗Metasploit300
Cisco RV320 and RV325 Unauthenticated Remote Code Execution
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open ↗Metasploit300
Cisco RV320 and RV325 Unauthenticated Remote Code Execution
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RISK
open ↗Exploit-DB
QNAP Photo Station 5.7.0 - Cross-Site Scripting
Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inje
23RISK
open ↗Exploit-DB
Cisco Umbrella Roaming Client 2.0.168 - Local Privilege Escalation
Cisco Umbrella Enterprise Roaming Client Privilege Escalation Vulnerability
23RISK
open ↗Exploit-DB✓ VexDay Proof
Jorani Leave Management 0.6.5 - (Authenticated) 'startdate' SQL Injection
An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permission
23RISK
open ↗Exploit-DB
Cisco Umbrella Roaming Client 2.0.168 - Local Privilege Escalation
Cisco Umbrella Enterprise Roaming Client and Enterprise Roaming Module Privilege Escalation Vulnerability
23RISK
open ↗GitHub PoC
jezzus/CVE-2018-4121
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud b
28RISK
open ↗Exploit-DB
WirelessHART Fieldgate SWG70 3.0 - Directory Traversal
Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename par
43RISK
open ↗Exploit-DB
Apache Roller 5.0.3 - XML External Entity Injection (File Disclosure)
The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks
28RISK
open ↗Exploit-DB
Jorani Leave Management 0.6.5 - Cross-Site Scripting
Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HT
38RISK
open ↗GitHub PoC
jezzus/CVE-2018-11776-Python-PoC
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.