Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,980cataloged exploits
36,899CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,476Referência 23,400GitHub PoC 15,250VulnCheck XDB 8,959Nuclei 4,393Metasploit 3,502✓ verified onlyrecentpopularrisk
24,476 exploits
Exploit-DB✓ VexDay Proof
Advantech WebAccess 8.2-2017.03.31 - Webvrpcs Service Opcode 80061 Stack Buffer Overflow (Metasploit)
A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The applicati
43RISK
open ↗Exploit-DB
Readymade Video Sharing Script 3.2 - HTML Injection
Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
FS Lynda Clone 1.0 - SQL Injection
FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
23RISK
open ↗Exploit-DB
Linksys WVBR0 - 'User-Agent' Remote Command Injection
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authe
60RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component JEXTN Video Gallery 3.0.5 - 'id' SQL Injection
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component JEXTN Question And Answer 3.1.0 - SQL Injection
The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action
23RISK
open ↗Exploit-DB✓ VexDay Proof
GNU C Library Dynamic Loader glibc ld.so - Memory Leak / Buffer Overflow
A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environme
23RISK
open ↗Exploit-DB
Meinberg LANTIME Web Configuration Utility 6.16.008 - Arbitrary File Read
The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote attackers to read
23RISK
open ↗Exploit-DB
vBulletin 5.x - 'cacheTemplates' Remote Arbitrary File Deletion
In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file delet
28RISK
open ↗Exploit-DB✓ VexDay Proof
GNU C Library Dynamic Loader glibc ld.so - Memory Leak / Buffer Overflow
A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environ
23RISK
open ↗Exploit-DB
Accesspress Anonymous Post Pro < 3.2.0 - Arbitrary File Upload
An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper in
28RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS - Multiple Kernel Use-After-Frees due to Incorrect IOKit Object Lifetime Management in IOTimeSyncClockManagerUserClient
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The is
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple XNU Kernel - Memory Corruption due to Integer Overflow in __offsetof Usage in posix_spawn on 32-bit Platforms
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component JBuildozer 1.4.1 - 'appid' SQL Injection
The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS - Kernel Double Free due to Incorrect API Usage in Flow Divert Socket Option Handling
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS - Kernel Code Execution due to Lack of Bounds Checking in AppleIntelCapriController::GetLinkConfig
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graph
23RISK
open ↗Exploit-DB✓ VexDay Proof
Foodspotting Clone Script 1.0 - 'quicksearch.php?q' SQL Injection
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS XNU Kernel - Memory Disclosure due to bug in Kernel API for Detecting Kernel Memory Disclosures
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISK
open ↗Exploit-DB✓ VexDay Proof
Readymade PHP Classified Script 3.3 - 'subctid' / 'mctid' SQL Injection
Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.
23RISK
open ↗Exploit-DB
MLM Forex Market Plan Script 2.0.4 - 'newid' / 'eventid' SQL Injection
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eve
23RISK
open ↗Exploit-DB✓ VexDay Proof
Kickstarter Clone Acript 2.0 - 'projid' SQL Injection
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Laundry Booking Script 1.0 - 'list?city' SQL Injection
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Responsive Events & Movie Ticket Booking Script 3.2.1 - 'findcity.php?q' SQL Injection
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Multiplex Movie Theater Booking Script 3.1.5 - 'moid' / 'eid' SQL Injection
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php
23RISK
open ↗Exploit-DB✓ VexDay Proof
Single Theater Booking Script 3.2.1 - 'findcity.php?q' SQL Injection
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Groupon Clone Script 3.01 - 'state_id' / 'search' SQL Injection
Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Muslim Matrimonial Script 3.02 - 'succid' SQL Injection
Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.
23RISK
open ↗Exploit-DB
Advanced World Database 2.0.5 - SQL Injection
Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country pa
23RISK
open ↗Exploit-DB✓ VexDay Proof
Vanguard 1.4 - SQL Injection
Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS - 'necp_get_socket_attributes' so_pcb Type Confusion
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.