Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
80,184cataloged exploits
37,029CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,476Referência 23,521GitHub PoC 15,321VulnCheck XDB 8,970Nuclei 4,394Metasploit 3,502✓ verified onlyrecentpopularrisk
24,476 exploits
Exploit-DB
Netgear NMS300 ProSafe Network Management System - Multiple Vulnerabilities
Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote
60RISK
open ↗Exploit-DB
Netgear NMS300 ProSafe Network Management System - Multiple Vulnerabilities
Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allow
60RISK
open ↗Exploit-DB
D-Link DVGN5402SP - Multiple Vulnerabilities
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root accou
28RISK
open ↗Exploit-DB
D-Link DVGN5402SP - Multiple Vulnerabilities
Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remot
50RISK
open ↗Exploit-DB✓ VexDay Proof
GE Industrial Solutions UPS SNMP Adapter < 4.8 - Multiple Vulnerabilities
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authentica
28RISK
open ↗Exploit-DB
D-Link DVGN5402SP - Multiple Vulnerabilities
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and
28RISK
open ↗Exploit-DB
Viprinet Multichannel VPN Router 300 - Persistent Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the old and new interfaces in Viprinet Multichannel VPN Router 30
23RISK
open ↗Exploit-DB
eClinicalWorks (CCMR) - Multiple Vulnerabilities
eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remo
23RISK
open ↗Exploit-DB
eClinicalWorks (CCMR) - Multiple Vulnerabilities
eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allow
23RISK
open ↗Exploit-DB
eClinicalWorks (CCMR) - Multiple Vulnerabilities
eClinicalWorks Population Health (CCMR) suffers from a cross-site request forgery (CSRF) vulnerability in portalUserServ
23RISK
open ↗Exploit-DB
eClinicalWorks (CCMR) - Multiple Vulnerabilities
eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the a
23RISK
open ↗Exploit-DB
Microsoft Internet Explorer 11 - javascript Code Execution
JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial o
83RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX / iOS Kernel - iokit Registry Iterator Manipulation Double-Free
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISK
open ↗Exploit-DB✓ VexDay Proof
iOS Kernel - AppleOscarAccelerometer Use-After-Free
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri
23RISK
open ↗Exploit-DB✓ VexDay Proof
iOS Kernel - IOReportHub Use-After-Free
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX / iOS - Multiple Kernel Uninitialized Variable Bugs Leading to Code Execution Vulnerabilities
The kernel in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges o
23RISK
open ↗Exploit-DB
SAP HANA 1.00.095 - hdbindexserver Memory Corruption
The index server (hdbindexserver) in SAP HANA 1.00.095 allows remote attackers to execute arbitrary code or cause a deni
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX - 'gst_configure' Kernel Buffer Overflow
The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial
23RISK
open ↗Exploit-DB✓ VexDay Proof
iOS Kernel - AppleOscarCompass Use-After-Free
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX - 'IOHDIXControllerUserClient::convertClient' Buffer Integer Overflow
The Disk Images component in Apple iOS before 9.1 and OS X before 10.11.1 misparses images, which allows attackers to ex
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX / iOS Kernel - IOHDIXControllUserClient::clientClose Use-After-Free/Double-Free
The Disk Images component in Apple OS X before 10.11.2 and tvOS before 9.1 allows local users to gain privileges or caus
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX / iOS - NECP System Control Socket Packet Parsing Kernel Code Execution Integer Overflow
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Kernel - Hypervisor Driver Use-After-Free
Use-after-free vulnerability in Hypervisor in Apple OS X before 10.11.2 allows local users to gain privileges via vector
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX / iOS - Unsandboxable Kernel Use-After-Free in Mach Vouchers
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX - 'IntelAccelerator::gstqConfigure' Kernel NULL Dereference
The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Kernel - no-more-senders Use-After-Free
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISK
open ↗Exploit-DB✓ VexDay Proof
iOS Kernel - AppleOscarGyro Use-After-Free
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX - io_service_close Use-After-Free
IOKit in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cau
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX / iOS - Unsandboxable Kernel Code Exection Due to iokit Double Release in IOKit
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Kernel - IOAccelDisplayPipeUserClient2 Use-After-Free
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.