Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,978GitHub PoC 13,282VulnCheck XDB 8,176Nuclei 4,202Metasploit 3,462✓ verified onlyrecentpopularrisk
8,176 exploits
VulnCheck XDB
client-side
WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerability
68RISK
open ↗VulnCheck XDB
infoleak
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open ↗VulnCheck XDB
initial-access
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open ↗VulnCheck XDB
infoleak
Arbitrary Local File Read via Component Method Invocation in gradio-app/gradio
56RISK
open ↗VulnCheck XDB
client-side
WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerability
68RISK
open ↗VulnCheck XDB
infoleak
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open ↗VulnCheck XDB
infoleak
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open ↗VulnCheck XDB
infoleak
Arbitrary Local File Read via Component Method Invocation in gradio-app/gradio
56RISK
open ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISK
open ↗VulnCheck XDB
infoleak
Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts
48RISK
open ↗VulnCheck XDB
remote-with-credentials
Porto <= 7.1.0 - Authenticated (Contributor+) Local File Inclusion via Post Meta
41RISK
open ↗VulnCheck XDB
infoleak
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open ↗VulnCheck XDB
remote-with-credentials
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open ↗VulnCheck XDB
initial-access
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open ↗VulnCheck XDB
infoleak
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open ↗VulnCheck XDB
initial-access
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open ↗VulnCheck XDB
infoleak
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open ↗VulnCheck XDB
initial-access
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RISK
open ↗VulnCheck XDB
initial-access
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗VulnCheck XDB
initial-access
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗VulnCheck XDB
infoleak
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open ↗VulnCheck XDB
infoleak
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open ↗VulnCheck XDB
initial-access
WordPress Premmerce Permalink Manager for WooCommerce plugin <= 2.3.10 - Local File Inclusion vulnerability
41RISK
open ↗VulnCheck XDB
initial-access
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open ↗VulnCheck XDB
initial-access
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open ↗VulnCheck XDB
initial-access
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open ↗VulnCheck XDB
local
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.