Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,459Referência 22,721GitHub PoC 14,946VulnCheck XDB 8,829Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
24,458 exploits
Exploit-DB
Sudo 1.9.17 Host Option - Elevation of Privilege
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISK
open ↗Exploit-DB
Sudo chroot 1.9.17 - Local Privilege Escalation
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open ↗Exploit-DB
Microsoft Outlook - Remote Code Execution (RCE)
Microsoft Outlook Remote Code Execution Vulnerability
33RISK
open ↗Exploit-DB
Stacks Mobile App Builder 5.2.3 - Authentication Bypass via Account Takeover
WordPress Stacks Mobile App Builder plugin <= 5.2.3 - Account Takeover vulnerability
63RISK
open ↗Exploit-DB
Microsoft PowerPoint 2019 - Remote Code Execution (RCE)
Microsoft PowerPoint Remote Code Execution Vulnerability
41RISK
open ↗Exploit-DB
Moodle 4.4.0 - Authenticated Remote Code Execution
Moodle: remote code execution via calculated question types
78RISK
open ↗Exploit-DB
Wing FTP Server 7.4.3 - Unauthenticated Remote Code Execution (RCE)
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open ↗Exploit-DB
gogs 0.13.0 - Remote Code Execution (RCE)
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code
48RISK
open ↗Exploit-DB
Microsoft SharePoint 2019 - NTLM Authentication
Microsoft SharePoint Server Remote Code Execution Vulnerability
46RISK
open ↗Exploit-DB
OneTrust SDK 6.33.0 - Denial Of Service (DoS)
An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __
33RISK
open ↗Exploit-DB
Sitecore 10.4 - Remote Code Execution (RCE)
Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through
60RISK
open ↗Exploit-DB
PX4 Military UAV Autopilot 1.12.3 - Denial of Service (DoS)
PX4-Autopilot TRAJECTORY_REPRESENTATION_WAYPOINTS Message mavlink_receiver.cpp stack-based overflow
33RISK
open ↗Exploit-DB
Microsoft Excel 2024 Use after free - Remote Code Execution (RCE)
Microsoft Excel Remote Code Execution Vulnerability
41RISK
open ↗Exploit-DB
Pterodactyl Panel 1.11.11 - Remote Code Execution (RCE)
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open ↗Exploit-DB
McAfee Agent 5.7.6 - Insecure Storage of Sensitive Information
Improper Verification of Cryptographic Signature by McAfee Agent
33RISK
open ↗Exploit-DB
Social Warfare WordPress Plugin 3.5.2 - Remote Code Execution (RCE)
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open ↗Exploit-DB
FortiOS SSL-VPN 7.4.4 - Insufficient Session Expiration & Cookie Reuse
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, ve
33RISK
open ↗Exploit-DB✓ VexDay Proof
Ingress-NGINX 4.11.0 - Remote Code Execution (RCE)
ingress-nginx admission controller RCE escalation
85RISK
open ↗Exploit-DB
Microsoft Excel LTSC 2024 - Remote Code Execution (RCE)
Microsoft Word Remote Code Execution Vulnerability
41RISK
open ↗Exploit-DB
PCMan FTP Server 2.0.7 - Buffer Overflow
PCMan FTP Server RMD Command buffer overflow
33RISK
open ↗Exploit-DB
Parrot and DJI variants Drone OSes - Kernel Panic Exploit
dm-bufio: don't schedule in atomic context
23RISK
open ↗Exploit-DB
PHP CGI Module 8.3.4 - Remote Code Execution (RCE)
Argument Injection in PHP-CGI
100RISK
open ↗Exploit-DB
Microsoft Excel Use After Free - Local Code Execution
Microsoft Excel Remote Code Execution Vulnerability
41RISK
open ↗Exploit-DB
Anchor CMS 0.12.7 - Stored Cross Site Scripting (XSS)
A stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript
33RISK
open ↗Exploit-DB
Windows 11 SMB Client - Privilege Escalation & Remote Code Execution (RCE)
Windows SMB Client Elevation of Privilege Vulnerability
93RISK
open ↗Exploit-DB
Windows File Explorer Windows 10 Pro x64 - TAR Extraction
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open ↗Exploit-DB
Freefloat FTP Server 1.0 - Remote Buffer Overflow
FreeFloat FTP Server NOOP Command buffer overflow
38RISK
open ↗Exploit-DB
Roundcube 1.6.10 - Remote Code Execution (RCE)
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open ↗Exploit-DB
Laravel Pulse 1.3.1 - Arbitrary Code Injection
Laravel Pulse Allows Remote Code Execution via Unprotected Query Method
46RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.