Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,497GitHub PoC 13,627VulnCheck XDB 8,198Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
24,443 exploits
Exploit-DB
Endian Firewall < 3.0.0 - OS Command Injection
Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW
50RISK
open ↗Exploit-DB
DeDeCMS < 5.7-sp1 - Remote File Inclusion
A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.
35RISK
open ↗Exploit-DB
XOOPS < 2.0.11 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.11 and earlier allow remote attackers to inject arbitra
23RISK
open ↗Exploit-DB
XOOPS < 2.0.11 - Multiple Vulnerabilities
SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote att
23RISK
open ↗Exploit-DB
Endian Firewall < 3.0.0 - OS Command Injection (Metasploit)
Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW
50RISK
open ↗Exploit-DB✓ VexDay Proof
Havij - OLE Automation Array Remote Code Execution
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RISK
open ↗Exploit-DB
Thycotic Secret Server 8.8.000004 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the basic dashboard in Thycotic Secret Server 8.6.x, 8.7.x, and 8.8.x before
23RISK
open ↗Exploit-DB
Koha 3.20.1 - Multiple Cross-Site Scripting / Cross-Site Request Forgery Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x
23RISK
open ↗Exploit-DB
Koha 3.20.1 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and
23RISK
open ↗Exploit-DB
ManageEngine Asset Explorer 6.1 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 allows remote attacker
23RISK
open ↗Exploit-DB
Koha 3.20.1 - Multiple Cross-Site Scripting / Cross-Site Request Forgery Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before
23RISK
open ↗Exploit-DB
Koha 3.20.1 - Directory Traversal
Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08
50RISK
open ↗Exploit-DB
GeniXCMS 0.0.3 - Cross-Site Scripting
OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, a
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - ClientCopyImage Win32k (MS15-051) (Metasploit)
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local
98RISK
open ↗Exploit-DB✓ VexDay Proof
Vesta Control Panel 0.9.8 - OS Command Injection
Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharac
28RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - ShaderJob Buffer Overflow (Metasploit)
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460
60RISK
open ↗Exploit-DB
GeniXCMS 0.0.3 - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the MetalGenix GeniXCMS 0.0.3 allow remote attackers to inject ar
23RISK
open ↗Exploit-DB
GeniXCMS 0.0.3 - 'register.php' SQL Injection
Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote
23RISK
open ↗Exploit-DB✓ VexDay Proof
Photoshop CC2014 / Bridge CC 2014 - '.png' Parsing Memory Corruption
Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allow attackers to execute arbitrary code
28RISK
open ↗Exploit-DB✓ VexDay Proof
Photoshop CC2014 / Bridge CC 2014 - '.gif' Parsing Memory Corruption
Integer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attackers to ex
28RISK
open ↗Exploit-DB✓ VexDay Proof
Photoshop CC2014 / Bridge CC 2014 - '.png' Parsing Memory Corruption
Heap-based buffer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attac
28RISK
open ↗Exploit-DB✓ VexDay Proof
CUPS < 2.0.3 - Multiple Vulnerabilities
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-va
28RISK
open ↗Exploit-DB
ManageEngine SupportCenter Plus 7.90 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Zoho ManageEngine SupportCenter Plus 7.90 allow remote authentica
23RISK
open ↗Exploit-DB
ManageEngine SupportCenter Plus 7.90 - Multiple Vulnerabilities
Directory traversal vulnerability in Zoho ManageEngine SupportCenter Plus 7.90 allows remote authenticated users to writ
28RISK
open ↗Exploit-DB✓ VexDay Proof
Tango DropBox 3.1.5 + PRO - Activex HeapSpray
Buffer overflow in the GetWebStoreURL function in a certain ActiveX control in eSellerateControl365.dll 3.6.5.0 in eSell
23RISK
open ↗Exploit-DB✓ VexDay Proof
Lively Cart - SQL Injection
SQL injection vulnerability in LivelyCart 1.2.0 allows remote attackers to execute arbitrary SQL commands via the search
23RISK
open ↗Exploit-DB
BlackCat CMS 1.1.1 - Arbitrary File Download
Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbit
28RISK
open ↗Exploit-DB
TYPO3 Extension Akronymmanager 0.5.0 - SQL Injection
SQL injection vulnerability in mod1/index.php in the Akronymmanager (sb_akronymmanager) extension before 7.0.0 for TYPO3
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 3.13.0 < 3.19 (Ubuntu 12.04/14.04/14.10/15.04) - 'overlayfs' Local Privilege Escalation (Access /etc/shadow)
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 3.13.0 < 3.19 (Ubuntu 12.04/14.04/14.10/15.04) - 'overlayfs' Local Privilege Escalation
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.