Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,023GitHub PoC 13,334VulnCheck XDB 8,195Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
22,786 exploits
Exploit-DB
Linux Kernel 3.10.0 (CentOS / RHEL 7.1) - 'Wacom' Multiple Nullpointer Dereferences
The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate
23RISK
open ↗Exploit-DB
Linux Kernel 3.10.0 (CentOS / RHEL 7.1) - visor 'treo_attach' Nullpointer Dereference
The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attack
23RISK
open ↗Exploit-DB
Linux Kernel 3.10.0 (CentOS / RHEL 7.1) - 'digi_acceleport' Nullpointer Dereference
The digi_port_init function in drivers/usb/serial/digi_acceleport.c in the Linux kernel before 4.5.1 allows physically p
23RISK
open ↗Exploit-DB
Linux Kernel 3.10.0 (CentOS / RHEL 7.1) - 'aiptek' Nullpointer Dereference
The aiptek_probe function in drivers/input/tablet/aiptek.c in the Linux kernel before 4.4 allows physically proximate at
23RISK
open ↗Exploit-DB
Linux Kernel 3.10.0 (CentOS / RHEL 7.1) - visor clie_5_attach Nullpointer Dereference
The clie_5_attach function in drivers/usb/serial/visor.c in the Linux kernel through 4.4.1 allows physically proximate a
23RISK
open ↗Exploit-DB
Linux Kernel 3.10/3.18 /4.4 - Netfilter IPT_SO_SET_REPLACE Memory Corruption
The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local us
23RISK
open ↗Exploit-DB
Linux Kernel 3.10.0 (CentOS / RHEL 7.1) - 'mct_u232' Nullpointer Dereference
The mct_u232_msr_to_state function in drivers/usb/serial/mct_u232.c in the Linux kernel before 4.5.1 allows physically p
23RISK
open ↗Exploit-DB
Linux Kernel 3.10/3.18 /4.4 - Netfilter IPT_SO_SET_REPLACE Memory Corruption
Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel through 4.5.2 on 32
23RISK
open ↗Exploit-DB
ATutor LMS - '/install_modules.php' Cross-Site Request Forgery / Remote Code Execution
Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to
23RISK
open ↗Exploit-DB
Microsoft Windows 7 (x64) - 'afd.sys' Dangling Pointer Privilege Escalation (MS14-040)
Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Wind
28RISK
open ↗Exploit-DB
Avast! - Authenticode Parsing Memory Corruption
Avast allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a
23RISK
open ↗Exploit-DB
McAfee VirusScan Enterprise 8.8 - Security Restrictions Bypass
The McAfee VirusScan Console (mcconsol.exe) in McAfee VirusScan Enterprise 8.8.0 before Hotfix 1123565 (8.8.0.1546) on W
23RISK
open ↗Exploit-DB
McAfee VirusScan Enterprise 8.8 - Security Restrictions Bypass
The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.
23RISK
open ↗Exploit-DB
PHPLib < 7.4 - SQL Injection
SQL injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a allows remote attackers to execute
23RISK
open ↗Exploit-DB
PHPLib < 7.4 - SQL Injection
Eval injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a, when index.php3 from the PHPLib d
23RISK
open ↗Exploit-DB
DropBearSSHD 2015.71 - Command Injection
CRLF injection vulnerability in Dropbear SSH before 2016.72 allows remote authenticated users to bypass intended shell-c
28RISK
open ↗Exploit-DB
Schneider Electric SBO / AS - Multiple Vulnerabilities
Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows
28RISK
open ↗Exploit-DB
Gallery 2 < 2.0.2 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in Gallery 2 up to 2.0.2 allows remote attackers to inject arbitrary web script
23RISK
open ↗Exploit-DB
Gallery 2 < 2.0.2 - Multiple Vulnerabilities
Directory traversal vulnerability in the session handling class (GallerySession.class) in Gallery 2 up to 2.0.2 allows r
23RISK
open ↗Exploit-DB
Netgear NMS300 ProSafe Network Management System - Arbitrary File Upload (Metasploit)
Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allow
60RISK
open ↗Exploit-DB
ATutor 2.2.1 - SQL Injection / Remote Code Execution (Metasploit)
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RISK
open ↗Exploit-DB
Microsoft Windows - 'srv2.sys' SMB Code Execution (Python) (MS09-050)
Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process t
35RISK
open ↗Exploit-DB
Zimbra 8.0.9 GA - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) be
23RISK
open ↗Exploit-DB
Microsoft Windows - 'srv2.sys' SMB Code Execution (Python) (MS09-050)
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISK
open ↗Exploit-DB
Microsoft Windows - 'srv2.sys' SMB Code Execution (Python) (MS09-050)
Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets
45RISK
open ↗Exploit-DB
phpRPC < 0.7 - Remote Code Execution
Eval injection vulnerability in the decode function in rpc_decoder.php for phpRPC 0.7 and earlier, as used by runcms, ex
23RISK
open ↗Exploit-DB
Microsoft Windows - 'NetAPI32.dll' Code Execution (Python) (MS08-067)
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISK
open ↗Exploit-DB
IBM Lotus Domino R8 - Password Hash Extraction
Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hid
60RISK
open ↗Exploit-DB
Mambo < 4.5.3h - Multiple Vulnerabilities
SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arb
23RISK
open ↗Exploit-DB
libxml2 - xmlDictAddString Heap Buffer Overread
The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS befo
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.