Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,534GitHub PoC 13,654VulnCheck XDB 8,213Nuclei 4,218Metasploit 3,464✓ verified onlyrecentpopularrisk
24,443 exploits
Exploit-DB
Incredible PBX 2.0.6.5.0 - Remote Command Execution
reminders/index.php in Incredible PBX 11 2.0.6.5.0 allows remote authenticated users to execute arbitrary commands via s
23RISK
open ↗Exploit-DB
CBN CH6640E/CG6640E Wireless Gateway Series - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in Compal Broadband Networks (CBN) CH6640E and CG6640E Wirele
23RISK
open ↗Exploit-DB✓ VexDay Proof
HP Operations Agent - Cross-Site Scripting iFrame Injection
Cross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communicatio
23RISK
open ↗Exploit-DB
CBN CH6640E/CG6640E Wireless Gateway Series - Multiple Vulnerabilities
The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH have a d
28RISK
open ↗Exploit-DB
WordPress Plugin CP Multi View Event Calendar 1.01 - SQL Injection
SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to exe
50RISK
open ↗Exploit-DB
Microsoft Windows - OLE Remote Code Execution 'Sandworm' (MS14-060)
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISK
open ↗Exploit-DB
Microsoft Windows - OLE Remote Code Execution 'Sandworm' (MS14-060)
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISK
open ↗Exploit-DB
WordPress Plugin 0.9.7 / Joomla! Component 2.0.0 Creative Contact Form - Arbitrary File Upload
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery
60RISK
open ↗Exploit-DB
Magento Server MAGMI Plugin 0.7.17a - Remote File Inclusion
Unrestricted file upload vulnerability in magmi/web/magmi.php in the MAGMI (aka Magento Mass Importer) plugin 0.7.17a an
23RISK
open ↗Exploit-DB
Dell EqualLogic Storage - Directory Traversal
Directory traversal vulnerability in Dell EqualLogic PS4000 with firmware 6.0 allows remote attackers to read arbitrary
23RISK
open ↗Exploit-DB
Axway Secure Transport 5.1 SP2 - Arbitrary File Upload (via Cross-Site Request Forgery)
Cross-site request forgery (CSRF) vulnerability in Axway SecureTransport 5.1 SP2 and earlier allows remote attackers to
23RISK
open ↗Exploit-DB
iBackup 10.0.0.32 - Local Privilege Escalation
iBackup 10.0.0.32 and earlier uses weak permissions (Everyone: Full Control) for ib_service.exe, which allows local user
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Akeeba Kickstart - Unserialize Remote Code Execution (Metasploit)
Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeb
50RISK
open ↗Exploit-DB✓ VexDay Proof
Numara / BMC Track-It! FileStorageService - Arbitrary File Upload (Metasploit)
BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbit
60RISK
open ↗Exploit-DB✓ VexDay Proof
Linux PolicyKit - Race Condition Privilege Escalation (Metasploit)
Race condition in the pkexec utility and polkitd daemon in PolicyKit (aka polkit) 0.96 allows local users to gain privil
38RISK
open ↗Exploit-DB
Aireplay-ng 1.2 beta3 - 'tcp_test' Length Stack Overflow
Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attac
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (MS14-060) (Metasploit)
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISK
open ↗Exploit-DB
Microsoft Windows - OLE Package Manager SandWorm
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (MS14-060) (Metasploit)
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISK
open ↗Exploit-DB
Microsoft Windows - OLE Package Manager SandWorm
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISK
open ↗Exploit-DB✓ VexDay Proof
SAP NetWeaver Enqueue Server - Denial of Service
The Standalone Enqueue Server in SAP Netweaver 7.20, 7.01, and earlier allows remote attackers to cause a denial of serv
23RISK
open ↗Exploit-DB✓ VexDay Proof
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISK
open ↗Exploit-DB✓ VexDay Proof
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (PoC) (Reset Password) (2)
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISK
open ↗Exploit-DB✓ VexDay Proof
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (PoC) (Reset Password) (1)
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Bluetooth Personal Area Networking - 'BthPan.sys' Local Privilege Escalation (Metasploit)
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write
43RISK
open ↗Exploit-DB✓ VexDay Proof
Centreon < 2.5.1 / Centreon Enterprise Server < 2.2 - SQL Injection / Command Injection (Metasploit)
Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3
60RISK
open ↗Exploit-DB✓ VexDay Proof
Centreon < 2.5.1 / Centreon Enterprise Server < 2.2 - SQL Injection / Command Injection (Metasploit)
displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remot
60RISK
open ↗Exploit-DB
Croogo 2.0.0 - Multiple Persistent Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary we
23RISK
open ↗Exploit-DB✓ VexDay Proof
YourMembers Plugin - Blind SQL Injection
SQL injection vulnerability in includes/ym-download_functions.include.php in the Code Futures YourMembers plugin for Wor
23RISK
open ↗Exploit-DB
Tenda A32 Router - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN a
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.