Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,900cataloged exploits
36,847CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,475Referência 23,360GitHub PoC 15,228VulnCheck XDB 8,946Nuclei 4,390Metasploit 3,501✓ verified onlyrecentpopularrisk
24,475 exploits
Exploit-DB
Cockpit CMS 0.4.4 < 0.5.5 - Server-Side Request Forgery
SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to r
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::jsElementScrollHeightGetter' Use-After-Free
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud
23RISK
open ↗Exploit-DB
WordPress Plugin Responsive Cookie Consent 1.7 / 1.6 / 1.5 - (Authenticated) Persistent Cross-Site Scripting
The Responsive Cookie Consent plugin before 1.8 for WordPress mishandles number fields, leading to XSS.
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Form Maker 1.12.20 - CSV Injection
The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code (Metasploit)
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RISK
open ↗Exploit-DB✓ VexDay Proof
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RC
50RISK
open ↗Exploit-DB✓ VexDay Proof
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker
50RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS - ReportCrash mach port Replacement due to Failure to Respect MIG Ownership Rules
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2
23RISK
open ↗Exploit-DB✓ VexDay Proof
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execut
50RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS 10.13.2 - Double mach_port_deallocate in kextd due to Failure to Comply with MIG Ownership Rules
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "kext tools"
23RISK
open ↗Exploit-DB✓ VexDay Proof
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an
43RISK
open ↗Exploit-DB
October CMS User Plugin 1.4.5 - Persistent Cross-Site Scripting
An issue was discovered in the Users (aka Front-end user management) plugin 1.4.5 for October CMS. XSS exists in the nam
23RISK
open ↗Exploit-DB
MyBB Threads to Link Plugin 1.3 - Cross-Site Scripting
An XSS issue was discovered in the Threads to Link plugin 1.3 for MyBB. When editing a thread, the user is given the opt
23RISK
open ↗Exploit-DB
Frog CMS 0.9.5 - Persistent Cross-Site Scripting
Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings.
23RISK
open ↗Exploit-DB
SickRage < v2018.03.09 - Clear-Text Credentials HTTP Response
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
60RISK
open ↗Exploit-DB
Jfrog Artifactory < 4.16 - Arbitrary File Upload / Remote Command Execution
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to
28RISK
open ↗Exploit-DB
Blog Master Pro 1.0 - CSV Injection
A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level pri
23RISK
open ↗Exploit-DB✓ VexDay Proof
Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code Execution (PoC)
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RISK
open ↗Exploit-DB
HRSALE The Ultimate HRM 1.0.2 - Local File Inclusion
A Local File Inclusion vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user.
23RISK
open ↗Exploit-DB
HRSALE The Ultimate HRM 1.0.2 - (Authenticated) Cross-Site Scripting
An Authenticated Stored XSS vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged u
23RISK
open ↗Exploit-DB
HRSALE The Ultimate HRM 1.0.2 - CSV Injection
A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privile
23RISK
open ↗Exploit-DB
Shopy Point of Sale 1.0 - CSV Injection
A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to
23RISK
open ↗Exploit-DB
HRSALE The Ultimate HRM 1.0.2 - 'award_id' SQL Injection
A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privile
23RISK
open ↗Exploit-DB
WSO2 Carbon / WSO2 Dashboard Server 5.3.0 - Persistent Cross-Site Scripting
WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers.
35RISK
open ↗Exploit-DB
VLC Media Player/Kodi/PopcornTime 'Red Chimera' < 2.2.5 - Memory Corruption (PoC)
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an inpu
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Info Leak in Image Inflation
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful expl
28RISK
open ↗Exploit-DB
WUZHI CMS 4.1.0 - Cross-Site Request Forgery
index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member.
23RISK
open ↗Exploit-DB
UK Cookie Consent - Persistent Cross-Site Scripting
A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Conse
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Overflow when Playing Sound
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Heap Overflow vulnerability. Successful exploitat
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.