Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,978GitHub PoC 13,282VulnCheck XDB 8,176Nuclei 4,202Metasploit 3,462✓ verified onlyrecentpopularrisk
22,786 exploits
Exploit-DB
Zoom Linux Client 2.0.106600.0904 - Stack-Based Buffer Overflow (PoC)
Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote
28RISK
open ↗Exploit-DB
Western Digital MyCloud - 'multi_uploadify' File Upload (Metasploit)
An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquer
60RISK
open ↗Exploit-DB
Zoom Linux Client 2.0.106600.0904 - Command Injection
The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when c
28RISK
open ↗Exploit-DB
Linux kernel < 4.10.15 - Race Condition Privilege Escalation
Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denia
28RISK
open ↗Exploit-DB
Sync Breeze 10.2.12 - Denial of Service
The Enterprise version of SyncBreeze 10.2.12 and earlier is affected by a Remote Denial of Service vulnerability. The we
23RISK
open ↗Exploit-DB
Linksys WVBR0 - 'User-Agent' Remote Command Injection
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authe
60RISK
open ↗Exploit-DB
Piwigo 2.9.1 - 'cat_true' / 'cat_false' SQL Injection
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitra
23RISK
open ↗Exploit-DB
Advantech WebAccess 8.2-2017.03.31 - Webvrpcs Service Opcode 80061 Stack Buffer Overflow (Metasploit)
A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The applicati
43RISK
open ↗Exploit-DB
Readymade Video Sharing Script 3.2 - HTML Injection
Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter.
23RISK
open ↗Exploit-DB
Palo Alto Networks Firewalls - Root Remote Code Execution
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RISK
open ↗Exploit-DB
Paid To Read Script 2.0.5 - 'uid' / 'fnum' / 'fn' SQL Injection
Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum para
23RISK
open ↗Exploit-DB
FS Lynda Clone 1.0 - SQL Injection
FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
23RISK
open ↗Exploit-DB
Bus Booking Script 1.0 - 'txtname' SQL Injection
Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.
23RISK
open ↗Exploit-DB
GNU C Library Dynamic Loader glibc ld.so - Memory Leak / Buffer Overflow
A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environ
23RISK
open ↗Exploit-DB
vBulletin 5.x - 'cacheTemplates' Remote Arbitrary File Deletion
In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file delet
28RISK
open ↗Exploit-DB
Meinberg LANTIME Web Configuration Utility 6.16.008 - Arbitrary File Read
The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote attackers to read
23RISK
open ↗Exploit-DB
GNU C Library Dynamic Loader glibc ld.so - Memory Leak / Buffer Overflow
A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environme
23RISK
open ↗Exploit-DB
Joomla! Component JEXTN Question And Answer 3.1.0 - SQL Injection
The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action
23RISK
open ↗Exploit-DB
Joomla! Component JEXTN Video Gallery 3.0.5 - 'id' SQL Injection
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
23RISK
open ↗Exploit-DB
Joomla! Component JBuildozer 1.4.1 - 'appid' SQL Injection
The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.
23RISK
open ↗Exploit-DB
Apple XNU Kernel - Memory Corruption due to Integer Overflow in __offsetof Usage in posix_spawn on 32-bit Platforms
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISK
open ↗Exploit-DB
Apple macOS/iOS - Multiple Kernel Use-After-Frees due to Incorrect IOKit Object Lifetime Management in IOTimeSyncClockManagerUserClient
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The is
23RISK
open ↗Exploit-DB
Apple macOS - Kernel Code Execution due to Lack of Bounds Checking in AppleIntelCapriController::GetLinkConfig
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graph
23RISK
open ↗Exploit-DB
Apple macOS/iOS - Kernel Double Free due to Incorrect API Usage in Flow Divert Socket Option Handling
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISK
open ↗Exploit-DB
Accesspress Anonymous Post Pro < 3.2.0 - Arbitrary File Upload
An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper in
28RISK
open ↗Exploit-DB
Advanced World Database 2.0.5 - SQL Injection
Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country pa
23RISK
open ↗Exploit-DB
Apple macOS/iOS - Kernel Double Free due to IOSurfaceRootUserClient not Respecting MIG Ownership Rules
An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. watchOS be
43RISK
open ↗Exploit-DB
MikroTik 6.40.5 ICMP - Denial of Service
MikroTik v6.40.5 devices allow remote attackers to cause a denial of service via a flood of ICMP packets.
23RISK
open ↗Exploit-DB
Vanguard 1.4 - Arbitrary File Upload
Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product
23RISK
open ↗Exploit-DB
Resume Clone Script 2.0.5 - SQL Injection
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.