Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,023GitHub PoC 13,334VulnCheck XDB 8,195Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
22,786 exploits
Exploit-DB
Acunetix WVS 10 - Local Privilege Escalation
The AcuWVSSchedulerv10 service in Acunetix Web Vulnerability Scanner (WVS) before 10 build 20151125 allows local users t
23RISK
open ↗Exploit-DB
Man-db 2.6.7.1 - Local Privilege Escalation
The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access t
23RISK
open ↗Exploit-DB
abrt (Centos 7.1 / Fedora 22) - Local Privilege Escalation
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
38RISK
open ↗Exploit-DB
ntop-ng 2.0.151021 - Privilege Escalation
ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the u
23RISK
open ↗Exploit-DB
RHEL 7.0/7.1 - 'abrt/sosreport' Local Privilege Escalation
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
38RISK
open ↗Exploit-DB
SAP Sybase Adaptive Server Enterprise - XML External Entity Information Disclosure
The XMLParse procedure in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 ESD 2 allows remote authenticated users to re
23RISK
open ↗Exploit-DB
Microsoft Windows - Race Condition DestroySMWP Use-After-Free (MS15-115)
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RISK
open ↗Exploit-DB
Microsoft Windows - 'ndis.sys' IOCTL 0x170034 (ndis!ndisNsiGetIfNameForIfIndex) Pool Buffer Overflow (MS15-117)
Buffer overflow in the Network Driver Interface Standard (NDIS) implementation in Microsoft Windows Vista SP2, Windows S
23RISK
open ↗Exploit-DB
Nvidia Stereoscopic 3D Driver Service 7.17.13.5382 - Arbitrary Run Key Creation
nvSCPAPISvr.exe in the Stereoscopic 3D Driver Service in the NVIDIA GPU graphics driver R340 before 341.92, R352 before
23RISK
open ↗Exploit-DB
Microsoft Windows - Cursor Object Memory Leak (MS15-115)
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RISK
open ↗Exploit-DB
Joomla! 3.4.4 Component Content History - SQL Injection / Remote Code Execution (Metasploit)
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RISK
open ↗Exploit-DB
vBulletin 5.x - Remote Code Execution
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH
60RISK
open ↗Exploit-DB
Joomla! 3.4.4 Component Content History - SQL Injection / Remote Code Execution (Metasploit)
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.p
60RISK
open ↗Exploit-DB
Microsoft Windows Kernel - Device Contexts and NtGdiSelectBitmap Use-After-Free (MS15-115)
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RISK
open ↗Exploit-DB
Acrobat Reader DC 15.008.20082.15957 - '.PDF' Parsing Memory Corruption
Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.
28RISK
open ↗Exploit-DB
Joomla! 3.4.4 Component Content History - SQL Injection / Remote Code Execution (Metasploit)
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RISK
open ↗Exploit-DB
ZTE ZXHN H108N R1A / ZXV10 W300 Routers - Multiple Vulnerabilities
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote authenticated users to bypass intended access r
23RISK
open ↗Exploit-DB
ZTE ZXHN H108N R1A / ZXV10 W300 Routers - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_
23RISK
open ↗Exploit-DB
ZTE ZXHN H108N R1A / ZXV10 W300 Routers - Multiple Vulnerabilities
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE and ZXV10 W300 devices W300V1.0.0f_ER1_PE allow remote authe
23RISK
open ↗Exploit-DB
ZTE ADSL ZXV10 W300 Modems - Multiple Vulnerabilities
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrato
23RISK
open ↗Exploit-DB
ZTE ZXHN H108N R1A / ZXV10 W300 Routers - Multiple Vulnerabilities
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, whic
28RISK
open ↗Exploit-DB
ZTE ADSL ZXV10 W300 Modems - Multiple Vulnerabilities
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid
23RISK
open ↗Exploit-DB
Chkrootkit - Local Privilege Escalation (Metasploit)
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute a
38RISK
open ↗Exploit-DB
ZTE ADSL ZXV10 W300 Modems - Multiple Vulnerabilities
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain
28RISK
open ↗Exploit-DB
ZTE ZXHN H108N R1A / ZXV10 W300 Routers - Multiple Vulnerabilities
Absolute path traversal vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE
28RISK
open ↗Exploit-DB
ZTE ZXHN H108N R1A / ZXV10 W300 Routers - Multiple Vulnerabilities
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote attackers to discover usernames and password ha
23RISK
open ↗Exploit-DB
Google Chrome - open-vcdiff Out-of-Bounds Read in Browser Process Integer Overflow
Multiple unspecified vulnerabilities in Google Chrome before 46.0.2490.71 allow attackers to cause a denial of service o
23RISK
open ↗Exploit-DB
F5 iControl - 'iCall::Script' Root Command Execution (Metasploit)
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.
50RISK
open ↗Exploit-DB
Horde Groupware 5.2.10 - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Hor
23RISK
open ↗Exploit-DB
IBM i Access 7.1 - Local Buffer Overflow / Code Execution
Buffer overflow in IBM i Access 7.1 on Windows allows local users to gain privileges via unspecified vectors.
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.