Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,003GitHub PoC 13,307VulnCheck XDB 8,182Nuclei 4,217Metasploit 3,462✓ verified onlyrecentpopularrisk
22,786 exploits
Exploit-DB
Microsoft Windows Kernel - 'win32k.sys' Multiple 'NtGdiGetDIBitsInternal' System Call
A Win32k information disclosure vulnerability exists in Microsoft Windows when the win32k component improperly provides
23RISK
open ↗Exploit-DB
Microsoft Windows Kernel - 'win32kfull!SfnINLPUAHDRAWMENUITEM' Stack Memory Disclosure
An information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 10, and W
23RISK
open ↗Exploit-DB
Cisco Catalyst 2960 IOS 12.2(55)SE11 - 'ROCEM' Remote Code Execution
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RISK
open ↗Exploit-DB
Cisco Catalyst 2960 IOS 12.2(55)SE1 - 'ROCEM' Remote Code Execution
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RISK
open ↗Exploit-DB
Apple WebKit / Safari 10.0.3 (12602.4.8) - Synchronous Page Load Universal Cross-Site Scripting
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud b
23RISK
open ↗Exploit-DB
Brother MFC-J6520DW - Authentication Bypass / Password Change
On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a
35RISK
open ↗Exploit-DB
Apple WebKit / Safari 10.0.3 (12602.4.8) - Universal Cross-Site Scripting via a Focus Event and a Link Element
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud b
23RISK
open ↗Exploit-DB
Apple WebKit - 'Document::adoptNode' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open ↗Exploit-DB
Apple WebKit - 'JSC::B3::Procedure::resetReachability' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open ↗Exploit-DB
Apple WebKit - 'JSC::SymbolTableEntry::isWatchable' Heap Buffer Overflow
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open ↗Exploit-DB
Xen - Broken Check in 'memory_exchange()' Permits PV Guest Breakout
An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The e
23RISK
open ↗Exploit-DB
Quest Privilege Manager 6.0.0 - Arbitrary File Write
pmmasterd in Quest Privilege Manager before 6.0.0.061, when configured as a policy server, allows remote attackers to wr
28RISK
open ↗Exploit-DB
Moxa MXview 2.8 - Denial of Service
Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView
28RISK
open ↗Exploit-DB
Moxa MX AOPC-Server 1.5 - XML External Entity Injection
XML External Entity via ".AOP" files used by Moxa MX-AOPC Server 1.5 result in remote file disclosure.
23RISK
open ↗Exploit-DB
Moxa MXview 2.8 - Private Key Disclosure
Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.
28RISK
open ↗Exploit-DB
QNAP TVS-663 QTS < 4.2.4 build 20170313 - Command Injection
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands vi
28RISK
open ↗Exploit-DB
QNAP TVS-663 QTS < 4.2.4 build 20170313 - Command Injection
QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.
35RISK
open ↗Exploit-DB
Intellinet NFC-30IR Camera - Multiple Vulnerabilities
Directory traversal vulnerability in the web-based management site on the Intellinet NFC-30ir IP Camera with firmware LM
28RISK
open ↗Exploit-DB
Adobe (Multiple Products) - XML Injection File Content Disclosure
Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Service
100RISK
open ↗Exploit-DB
D-Link DWR-116 / DWR-116A1 - Arbitrary File Download
Directory traversal vulnerability in the web interface on the D-Link DWR-116 device with firmware before V1.05b09 allows
28RISK
open ↗Exploit-DB
QNAP TVS-663 QTS < 4.2.4 build 20170313 - Command Injection
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information
35RISK
open ↗Exploit-DB
Intellinet NFC-30IR Camera - Multiple Vulnerabilities
Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI scr
28RISK
open ↗Exploit-DB
Moodle 2.x/3.x - SQL Injection
In Moodle 2.x and 3.x, SQL injection can occur via user preferences.
28RISK
open ↗Exploit-DB
Cesanta Mongoose OS - Use-After-Free
Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embed
28RISK
open ↗Exploit-DB
SpiceWorks 7.5 TFTP - Remote File Overwrite / Upload
The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spicewor
23RISK
open ↗Exploit-DB
Faveo Helpdesk Community 1.9.3 - Cross-Site Request Forgery
public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.
23RISK
open ↗Exploit-DB
HelpDEZK 1.1.1 - Cross-Site Request Forgery / Code Execution
HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.
23RISK
open ↗Exploit-DB
D-Link DIR-615 - Cross-Site Request Forgery
D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacke
23RISK
open ↗Exploit-DB
HelpDEZK 1.1.1 - Cross-Site Request Forgery / Code Execution
HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.
23RISK
open ↗Exploit-DB
Apple WebKit 10.0.2 (12602.3.12.0.1) - 'disconnectSubframes' Universal Cross-Site Scripting
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.