Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,863cataloged exploits
32,152CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,978GitHub PoC 13,279VulnCheck XDB 8,156Nuclei 4,202Metasploit 3,462✓ verified onlyrecentpopularrisk
22,786 exploits
Exploit-DB
Sync Breeze Enterprise 10.1.16 - Denial of Service
In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability. The at
23RISK
open ↗Exploit-DB
Synology DiskStation Manager (DSM) < 6.1.3-15152 - 'forget_passwd.cgi' User Enumeration
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allo
60RISK
open ↗Exploit-DB
FiberHome LM53Q1 - Multiple Vulnerabilities
Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining informati
35RISK
open ↗Exploit-DB
Vanilla < 2.1.5 - Cross-Site Request Forgery
Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access
23RISK
open ↗Exploit-DB
VX Search Enterprise 10.1.12 - Denial of Service
In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. The atta
23RISK
open ↗Exploit-DB
FiberHome LM53Q1 - Multiple Vulnerabilities
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact
35RISK
open ↗Exploit-DB
Disk Pulse Enterprise 10.1.18 - Denial of Service
In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The att
28RISK
open ↗Exploit-DB
FiberHome LM53Q1 - Multiple Vulnerabilities
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact
23RISK
open ↗Exploit-DB
Microsoft Windows win32k - Using SetClassLong to Switch Between CS_CLASSDC and CS_OWNDC Corrupts DC Cache
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Wi
28RISK
open ↗Exploit-DB
Gespage 7.4.8 - SQL Injection
Multiple SQL injection vulnerabilities in Gespage before 7.4.9 allow remote attackers to execute arbitrary SQL commands
28RISK
open ↗Exploit-DB
gps-server.net GPS Tracking Software < 3.1 - Multiple Vulnerabilities
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords
23RISK
open ↗Exploit-DB
gps-server.net GPS Tracking Software < 3.1 - Multiple Vulnerabilities
The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote a
23RISK
open ↗Exploit-DB
Ayukov NFTP FTP Client 2.0 - Remote Buffer Overflow (Metasploit)
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
50RISK
open ↗Exploit-DB
Cisco IOS - Remote Code Execution
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabiliti
93RISK
open ↗Exploit-DB
Linksys WVBR0-25 - User-Agent Command Execution (Metasploit)
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authe
60RISK
open ↗Exploit-DB
Xplico - Remote Code Execution (Metasploit)
Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name
60RISK
open ↗Exploit-DB
Oracle WebLogic < 10.3.6 - 'wls-wsat' Component Deserialisation Remote Command Execution
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open ↗Exploit-DB
Multiple CPUs - 'Spectre' Information Disclosure
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RISK
open ↗Exploit-DB
Multiple CPUs - 'Spectre' Information Disclosure
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RISK
open ↗Exploit-DB
WordPress Plugin Smart Google Code Inserter < 3.5 - Authentication Bypass / SQL Injection
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RISK
open ↗Exploit-DB
EMC xPression 4.5SP1 Patch 13 - 'model.jobHistoryId' SQL Injection
xDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL I
23RISK
open ↗Exploit-DB
WordPress Plugin Smart Google Code Inserter < 3.5 - Authentication Bypass / SQL Injection
SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthentica
35RISK
open ↗Exploit-DB
HP Mercury LoadRunner Agent magentproc.exe - Remote Command Execution (Metasploit)
Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before 9.50 allows remote
60RISK
open ↗Exploit-DB
Cambium ePMP1000 - 'get_chart' Shell via Command Injection (Metasploit)
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web
60RISK
open ↗Exploit-DB
PHP Melody 2.7.1 - 'playlist' SQL Injection
PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist.
23RISK
open ↗Exploit-DB
NetTransport 2.96L - Remote Buffer Overflow (DEP Bypass)
A buffer overflow vulnerability in NetTransport.exe in NetTransport Download Manager 2.96L and earlier could allow remot
50RISK
open ↗Exploit-DB
ALLMediaServer 0.95 - Remote Buffer Overflow (Metasploit)
A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow
50RISK
open ↗Exploit-DB
ALLMediaServer 0.95 - Buffer Overflow (PoC)
A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow
50RISK
open ↗Exploit-DB
SysGauge Server 3.6.18 - Denial of Service
In Flexense SysGauge Server 3.6.18, the Control Protocol suffers from a denial of service. The attack vector is a crafte
23RISK
open ↗Exploit-DB
Ubiquiti UniFi Video 3.7.3 - Local Privilege Escalation
Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local u
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.