Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,697cataloged exploits
36,715CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,475Referência 23,264GitHub PoC 15,172VulnCheck XDB 8,920Nuclei 4,373Metasploit 3,493✓ verified onlyrecentpopularrisk
79,697 exploits
Exploit-DB
Cisco Umbrella Roaming Client 2.0.168 - Local Privilege Escalation
Cisco Umbrella Enterprise Roaming Client Privilege Escalation Vulnerability
23RISK
open ↗Exploit-DB
Tenda ADSL Router D152 - Cross-Site Scripting
Tenda D152 ADSL routers allow XSS via a crafted SSID.
23RISK
open ↗GitHub PoC★ 2
Apache Struts version analyzer (Ansible) based on CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open ↗GitHub PoC★ 5
A remote code execution exploit for WebLogic based on CVE-2018-2628
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open ↗VulnCheck XDB
initial-access
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISK
open ↗GitHub PoC★ 95
Primefaces <= 5.2.21, 5.3.8 or 6.0 - Remote Code Execution Exploit
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISK
open ↗GitHub PoC★ 25
CVE-2017-10366: Oracle PeopleSoft 8.54, 8.55, 8.56 Java deserialization exploit
Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Perform
35RISK
open ↗Exploit-DB
D-Link DIR-615 - Denial of Service (PoC)
D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header.
35RISK
open ↗Exploit-DB
FsPro Labs Event Log Explorer v4.6.1.2115 - XML External Entity Injection
FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.
23RISK
open ↗Exploit-DB
DamiCMS 6.0.0 - Cross-Site Request Forgery (Change Admin Password)
An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's pas
23RISK
open ↗Exploit-DB✓ VexDay Proof
Network Manager VPNC 1.2.6 - 'Username' Local Privilege Escalation (Metasploit)
Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attac
56RISK
open ↗GitHub PoC★ 13
Mitigate CVE-2018-6389 WordPress load-scripts / load-styles attacks
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISK
open ↗Exploit-DB
DLink DIR-601 - Credential Disclosure
An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (whi
45RISK
open ↗Exploit-DB✓ VexDay Proof
Cybrotech CyBroHttpServer 1.0.3 - Cross-Site Scripting
Cybrotech CyBroHttpServer 1.0.3 allows XSS via a URI.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cybrotech CyBroHttpServer 1.0.3 - Directory Traversal
Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.
50RISK
open ↗Exploit-DB✓ VexDay Proof
Argus Surveillance DVR 4.0.0.0 - Directory Traversal
Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F
60RISK
open ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 4.7.x - Cross-Site Request Forgery
phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a
23RISK
open ↗GitHub PoC★ 56
This tool takes advantage of CVE-2018-11776 and Shodan to perform mass exploitation of verified and vulnerable Apache Struts servers.
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open ↗Metasploit0
Snap Creek Duplicator WordPress plugin code injection
An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and
30RISK
open ↗VulnCheck XDB
initial-access
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open ↗VulnCheck XDB
initial-access
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open ↗VulnCheck XDB
initial-access
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open ↗GitHub PoC★ 3
tuxotron/cve-2018-11776-docker
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open ↗GitHub PoC★ 16
A simple exploit for Apache Struts RCE S2-057 (CVE-2018-11776)
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open ↗GitHub PoC★ 2
Tiny script to enumerate users using CVE-2017-9554 (forget_passwd.cgi)
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allo
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - JScript RegExp.lastIndex Use-After-Free
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
35RISK
open ↗VulnCheck XDB
initial-access
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allo
60RISK
open ↗Exploit-DB✓ VexDay Proof
Responsive FileManager < 9.13.4 - Directory Traversal
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in arc
23RISK
open ↗Exploit-DB
Gleez CMS 1.2.0 - Cross-Site Request Forgery (Add Admin)
There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add.
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.