Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,978GitHub PoC 13,282VulnCheck XDB 8,176Nuclei 4,202Metasploit 3,462✓ verified onlyrecentpopularrisk
22,786 exploits
Exploit-DB
Apple iOS < 10.3.1 - Kernel
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISK
open ↗Exploit-DB
Apple iOS < 10.3.1 - Kernel
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISK
open ↗Exploit-DB
Apple iOS < 10.3.1 - Kernel
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISK
open ↗Exploit-DB
Apple iOS < 10.3.1 - Kernel
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISK
open ↗Exploit-DB
Apple iOS < 10.3.1 - Kernel
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISK
open ↗Exploit-DB
Apple iOS < 10.3.1 - Kernel
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISK
open ↗Exploit-DB
Apple iOS < 10.3.1 - Kernel
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RISK
open ↗Exploit-DB
libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities
The gig::Instrument::UpdateRegionKeyTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial
23RISK
open ↗Exploit-DB
libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities
The gig::DimensionRegion::CreateVelocityTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a den
23RISK
open ↗Exploit-DB
Wireless Repeater BE126 - Local File Inclusion
There is LFD (local file disclosure) on BE126 WIFI repeater 1.0 devices that allows attackers to read the entire filesys
28RISK
open ↗Exploit-DB
libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities
The gig::Region::GetSampleFromWavePool function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of
23RISK
open ↗Exploit-DB
libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities
The LoadString function in helper.h in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer d
23RISK
open ↗Exploit-DB
libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities
The gig::Region::Region function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL p
23RISK
open ↗Exploit-DB
Automated Logic WebCTRL 6.5 - Unrestricted File Upload / Remote Code Execution
An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL
23RISK
open ↗Exploit-DB
Automated Logic WebCTRL 6.5 - Local Privilege Escalation
An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan
23RISK
open ↗Exploit-DB
Automated Logic WebCTRL 6.1 - Path Traversal / Arbitrary File Write
A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5;
23RISK
open ↗Exploit-DB
IBM OpenAdmin Tool - SOAP welcomeServer PHP Code Execution (Metasploit)
IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system a
60RISK
open ↗Exploit-DB
PHPMyWind 5.3 - Cross-Site Scripting
PHPMyWind 5.3 has XSS in shoppingcart.php, related to message.php, admin/message.php, and admin/message_update.php.
23RISK
open ↗Exploit-DB
Apache2Triad 1.5.4 - Multiple Vulnerabilities
Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID pa
28RISK
open ↗Exploit-DB
Apache2Triad 1.5.4 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or
23RISK
open ↗Exploit-DB
Apache2Triad 1.5.4 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack the authenticati
23RISK
open ↗Exploit-DB
PDF-XChange Viewer 2.5 Build 314.0 - Code Execution
The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code vi
23RISK
open ↗Exploit-DB
Apple macOS Sierra 10.12.1 - 'IOFireWireFamily' FireWire Port Denial of Service
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "IOFireWireF
23RISK
open ↗Exploit-DB
WebKitGTK 2.1.2 (Ubuntu 14.04) - Heap based Buffer Overflow
Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox
35RISK
open ↗Exploit-DB
Symantec Messaging Gateway 10.6.3-2 - Root Remote Command Execution
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situ
83RISK
open ↗Exploit-DB
NoviFlow NoviWare < NW400.2.6 - Multiple Vulnerabilities
The novish command-line interface, included in the NoviWare software distribution through NW400.2.6 and deployed on Novi
28RISK
open ↗Exploit-DB
ZKTime Web Software 2.0 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hi
23RISK
open ↗Exploit-DB
NoviFlow NoviWare < NW400.2.6 - Multiple Vulnerabilities
A network interface of the novi_process_manager_daemon service, included in the NoviWare software distribution through N
28RISK
open ↗Exploit-DB
NoviFlow NoviWare < NW400.2.6 - Multiple Vulnerabilities
Network interfaces of the cliengine and noviengine services, included in the NoviWare software distribution through NW40
28RISK
open ↗Exploit-DB
QuantaStor Software Defined Storage < 4.3.1 - Multiple Vulnerabilities
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.