Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,978GitHub PoC 13,282VulnCheck XDB 8,176Nuclei 4,202Metasploit 3,462✓ verified onlyrecentpopularrisk
22,786 exploits
Exploit-DB
osTicket 1.10 - SQL Injection (PoC)
In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a
23RISK
open ↗Exploit-DB
Jungo DriverWizard WinDriver < 12.4.0 - Kernel Pool Overflow / Local Privilege Escalation (2)
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must
23RISK
open ↗Exploit-DB
tcprewrite - Heap Buffer Overflow
tcprewrite in Tcpreplay 3.4.4 has a Heap-Based Buffer Overflow vulnerability triggered by a crafted PCAP file, a related
23RISK
open ↗Exploit-DB
Hanbanggaoke IP Camera - Arbitrary Password Change
On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT requ
28RISK
open ↗Exploit-DB
Apache Struts 2.0.1 < 2.3.33 / 2.5 < 2.5.10 - Arbitrary Code Execution
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag in
60RISK
open ↗Exploit-DB
Roteador Wireless Intelbras WRN150 - Cross-Site Scripting
XSS (persistent) on the Intelbras Wireless N 150Mbps router with firmware WRN 240 allows attackers to steal wireless cre
23RISK
open ↗Exploit-DB
McAfee LiveSafe 16.0.3 - Man In The Middle Registry Modification Leading to Remote Command Execution
A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS)
23RISK
open ↗Exploit-DB
Apache Struts 2.5 < 2.5.12 - REST Plugin XStream Remote Code Execution
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISK
open ↗Exploit-DB
Jungo DriverWizard WinDriver < 12.4.0 - Kernel Out-of-Bounds Write Privilege Escalation
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must
23RISK
open ↗Exploit-DB
Jungo DriverWizard WinDriver < 12.4.0 - Kernel Pool Overflow / Local Privilege Escalation (1)
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must
23RISK
open ↗Exploit-DB
FiberHome ADSL AN1020-25 - Improper Access Restrictions
An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to ea
35RISK
open ↗Exploit-DB
Wireless Repeater BE126 - Remote Code Execution
T&W WIFI Repeater BE126 allows remote authenticated users to execute arbitrary code via shell metacharacters in the user
23RISK
open ↗Exploit-DB
Mongoose Web Server 6.5 - Cross-Site Request Forgery / Remote Code Execution
Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the
23RISK
open ↗Exploit-DB
RubyGems < 2.6.13 - Arbitrary File Overwrite
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potenti
28RISK
open ↗Exploit-DB
CodeMeter 6.50 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the "advanced settings - time server" module in Wibu-Systems CodeMeter befor
23RISK
open ↗Exploit-DB
Lotus Notes Diagnostic Tool 8.5/9.0 - Local Privilege Escalation
Notes System Diagnostic (NSD) in IBM Domino 8.5.x before 8.5.3 FP6 IF6 and 9.x before 9.0.1 FP3 IF1 allows local users t
23RISK
open ↗Exploit-DB
IBM Notes 8.5.x/9.0.x - Denial of Service
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it coul
50RISK
open ↗Exploit-DB
WordPress Plugin Participants Database < 1.7.5.10 - Cross-Site Scripting
The Participants Database plugin before 1.7.5.10 for WordPress has XSS.
23RISK
open ↗Exploit-DB
Motorola Bootloader - Kernel Cmdline Injection Secure Boot and Device Locking Bypass
An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute
23RISK
open ↗Exploit-DB
OpenJPEG - 'mqc.c' Heap Buffer Overflow
Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote
23RISK
open ↗Exploit-DB
Joomla! Component Huge-IT Portfolio Gallery Plugin 1.0.7 - SQL Injection
Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla
23RISK
open ↗Exploit-DB
IBM Notes 8.5.x/9.0.x - Denial of Service (Metasploit)
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it coul
50RISK
open ↗Exploit-DB
Joomla! Component Huge-IT Video Gallery 1.0.9 - SQL Injection
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla
23RISK
open ↗Exploit-DB
Git < 2.7.5 - Command Injection (Metasploit)
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RISK
open ↗Exploit-DB
Joomla! Component Huge-IT Portfolio Gallery Plugin 1.0.6 - SQL Injection
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6
23RISK
open ↗Exploit-DB
IBM Notes 8.5.x/9.0.x - Denial of Service (2)
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it woul
43RISK
open ↗Exploit-DB
Oracle Java JDK/JRE < 1.8.0.131 / Apache Xerces 2.11.0 - 'PDF/Docx' Server Side Denial of Service
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supporte
28RISK
open ↗Exploit-DB
Metasploit Web UI < 4.14.1-20170828 - Cross-Site Request Forgery
The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.
23RISK
open ↗Exploit-DB
D-Link DIR-600 - Authentication Bypass
D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?RE
35RISK
open ↗Exploit-DB
Apple iOS < 10.3.1 - Kernel
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.