Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,534GitHub PoC 13,654VulnCheck XDB 8,213Nuclei 4,218Metasploit 3,464✓ verified onlyrecentpopularrisk
24,443 exploits
Exploit-DB✓ VexDay Proof
Rowhammer - NaCl Sandbox Escape
Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not properly set refresh rates fo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Rowhammer - NaCl Sandbox Escape
NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.
28RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel (x86-64) - Rowhammer Privilege Escalation
NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.
28RISK
open ↗Exploit-DB
Elastix 2.x - Blind SQL Injection
SQL injection vulnerability in a2billing/customer/iridium_threed.php in Elastix 2.5.0 and earlier allows remote attacker
23RISK
open ↗Exploit-DB
ProjectSend r561 - SQL Injection
SQL injection vulnerability in client-edit.php in ProjectSend (formerly cFTP) r561 allows remote authenticated users to
23RISK
open ↗Exploit-DB
PHP Betoffice (Betster) 1.0.4 - Authentication Bypass / SQL Injection
Multiple SQL injection vulnerabilities in Betster (aka PHP Betoffice) 1.0.4 allow remote attackers to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
HP Data Protector 8.10 - Remote Command Execution (Metasploit)
Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown
60RISK
open ↗Exploit-DB✓ VexDay Proof
Seagate Business NAS - Remote Command Execution (Metasploit)
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-
50RISK
open ↗Exploit-DB✓ VexDay Proof
Seagate Business NAS - Remote Command Execution (Metasploit)
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof
60RISK
open ↗Exploit-DB
Linux Kernel 3.15.6 - PPP-over-L2TP Socket Level Handling Crash (PoC)
The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by
23RISK
open ↗Exploit-DB
SolarWinds Orion Service - SQL Injection
Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwin
50RISK
open ↗Exploit-DB
Linux Kernel 3.16.3 - Associative Array Garbage Collection Crash (PoC)
The assoc_array_gc function in the associative-array implementation in lib/assoc_array.c in the Linux kernel before 3.16
23RISK
open ↗Exploit-DB
Linux Kernel 3.17.5 - IRET Instruction #SS Fault Handling Crash (PoC)
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack S
23RISK
open ↗Exploit-DB✓ VexDay Proof
Symantec Web Gateway 5 - 'restore.php' (Authenticated) Command Injection (Metasploit)
The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to exe
50RISK
open ↗Exploit-DB✓ VexDay Proof
Seagate Business NAS - Remote Command Execution (Metasploit)
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root
50RISK
open ↗Exploit-DB
PHPMoAdmin - Unauthorized Remote Code Execution
The saveObject function in moadmin.php in phpMoAdmin 1.1.2 allows remote attackers to execute arbitrary commands via she
50RISK
open ↗Exploit-DB
WordPress Theme Photocrati 4.x - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in ecomm-sizes.php in the Photocrati theme 4.x for WordPress allows remote attackers to exec
23RISK
open ↗Exploit-DB✓ VexDay Proof
vBulletin vBSEO 4.x - 'visitormessage.php' Remote Code Injection
functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code v
28RISK
open ↗Exploit-DB✓ VexDay Proof
Seagate Business NAS 2014.00319 - Remote Code Execution
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root
50RISK
open ↗Exploit-DB
Persistent Systems Client Automation - Command Injection Remote Code Execution (Metasploit)
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RISK
open ↗Exploit-DB✓ VexDay Proof
D-Link/TRENDnet - NCC Service Command Injection (Metasploit)
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr
100RISK
open ↗Exploit-DB
SQLite3 3.8.6 - Controlled Memory Corruption (PoC)
Multiple unspecified vulnerabilities in SQLite before 3.8.10.2, as used in Apple iOS before 9, have unknown impact and a
23RISK
open ↗Exploit-DB✓ VexDay Proof
HP Client - Automation Command Injection (Metasploit)
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RISK
open ↗Exploit-DB
Beehive Forum 1.4.4 - Persistent Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in edit_prefs.php in Beehive Forum 1.4.4 allow remote attackers to i
23RISK
open ↗Exploit-DB
Zeuscart 4.0 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in ZeusCart 4.0 and earlier allows remote attackers to inject arbitrary web scr
23RISK
open ↗Exploit-DB
phpBugTracker 1.6.0 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbi
23RISK
open ↗Exploit-DB
PHP DateTime - Use-After-Free
Multiple use-after-free vulnerabilities in ext/date/php_date.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x befo
35RISK
open ↗Exploit-DB
Zeuscart 4.0 - Multiple Vulnerabilities
ZeusCart 4 allows remote attackers to obtain configuration information via a getphpinfo action to admin/, which calls th
23RISK
open ↗Exploit-DB
Zeuscart 4.0 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in ZeusCart 4 allow remote attackers to inject arbitrary web script
23RISK
open ↗Exploit-DB
phpBugTracker 1.6.0 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attac
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.