Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,051GitHub PoC 15,051VulnCheck XDB 8,883Nuclei 4,361Metasploit 3,493✓ verified onlyrecentpopularrisk
24,460 exploits
Exploit-DB
RSA NetWitness Platform 12.2 - Incorrect Access Control / Code Execution
Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Wi
23RISK
open ↗Exploit-DB
X2CRM v6.6/6.9 - Stored Cross-Site Scripting (XSS) (Authenticated)
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via
33RISK
open ↗Exploit-DB
Goanywhere Encryption helper 7.1.1 - Remote Code Execution (RCE)
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RISK
open ↗Exploit-DB
Pentaho BA Server EE 9.3.0.0-428 - Remote Code Execution (RCE) (Unauthenticated)
Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions
100RISK
open ↗Exploit-DB
Pentaho BA Server EE 9.3.0.0-428 - Remote Code Execution (RCE) (Unauthenticated)
Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
100RISK
open ↗Exploit-DB
FortiRecorder 6.4.3 - Denial of Service
An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below
33RISK
open ↗Exploit-DB
Palo Alto Cortex XSOAR 6.5.0 - Stored Cross-Site Scripting (XSS)
Cortex XSOAR: Stored Cross-Site Scripting (XSS) Vulnerability in Web Interface
33RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! v4.2.8 - Unauthenticated information disclosure
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗Exploit-DB
Adobe Connect 11.4.5 - Local File Disclosure
Adobe Connect Improper Access Control Security feature bypass
70RISK
open ↗Exploit-DB
pfsenseCE v2.6.0 - Anti-brute force protection bypass
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22
48RISK
open ↗Exploit-DB
Suprema BioStar 2 v2.8.16 - SQL Injection
Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/abs
33RISK
open ↗Exploit-DB
Docker based datastores for IBM Instana 241-2 243-0 - No Authentication
IBM Observability with Instana missing authentication
48RISK
open ↗Exploit-DB
Tenda N300 F3 12.01.01.48 - Malformed HTTP Request Header Processing
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RISK
open ↗Exploit-DB
MAC 1200R - Directory Traversal
A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-stati
41RISK
open ↗Exploit-DB
IBM Aspera Faspex 4.4.1 - YAML deserialization (RCE)
IBM Aspera Faspex code execution
100RISK
open ↗Exploit-DB
Wondershare Dr Fone 12.9.6 - Privilege Escalation
Wondershare Dr.Fone v12.9.6 was discovered to contain weak permissions for the service WsDrvInst. This vulnerability all
41RISK
open ↗Exploit-DB
NotrinosERP 0.7 - Authenticated Blind SQL Injection
NotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/s
23RISK
open ↗Exploit-DB✓ VexDay Proof
Best pos Management System v1.0 - Remote Code Execution (RCE) on File Upload
SourceCodester Best POS Management System Image save_settings unrestricted upload
33RISK
open ↗Exploit-DB✓ VexDay Proof
Employee Task Management System v1.0 - Broken Authentication
SourceCodester Employee Task Management System changePasswordForEmployee.php improper authentication
41RISK
open ↗Exploit-DB✓ VexDay Proof
Intern Record System v1.0 - SQL Injection (Unauthenticated)
SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType
48RISK
open ↗Exploit-DB✓ VexDay Proof
Simple Food Ordering System v1.0 - Cross-Site Scripting (XSS)
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RISK
open ↗Exploit-DB✓ VexDay Proof
Music Gallery Site v1.0 - SQL Injection on music_list.php
SourceCodester Music Gallery Site GET Request music_list.php sql injection
33RISK
open ↗Exploit-DB✓ VexDay Proof
Employee Task Management System v1.0 - SQL Injection on (task-details.php?task_id=?)
SourceCodester Employee Task Management System task-details.php sql injection
33RISK
open ↗Exploit-DB✓ VexDay Proof
Music Gallery Site v1.0 - SQL Injection on page view_music_details.php
SourceCodester Music Gallery Site GET Request view_music_details.php sql injection
33RISK
open ↗Exploit-DB✓ VexDay Proof
Music Gallery Site v1.0 - SQL Injection on page Master.php
SourceCodester Music Gallery Site GET Request Master.php sql injection
33RISK
open ↗Exploit-DB✓ VexDay Proof
Music Gallery Site v1.0 - Broken Access Control
SourceCodester Music Gallery Site POST Request Users.php access control
41RISK
open ↗Exploit-DB✓ VexDay Proof
Art Gallery Management System Project in PHP v 1.0 - SQL injection
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid par
23RISK
open ↗Exploit-DB
Mitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversal and LFI
A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.