Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,832GitHub PoC 14,991VulnCheck XDB 8,829Nuclei 4,357Metasploit 3,489✓ verified onlyrecentpopularrisk
24,695 exploits
Exploit-DB✓ VexDay Proof
Foxit Reader 9.0.1.1049 - Remote Code Execution
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1
50RISK
open ↗Exploit-DB✓ VexDay Proof
Foxit Reader 9.0.1.1049 - Remote Code Execution
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RISK
open ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 4.8.1 - (Authenticated) Local File Inclusion (2)
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 4.8.1 - (Authenticated) Local File Inclusion (1)
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 10 - Desktop Bridge Activation Arbitrary Directory Creation Privilege Escalation
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache CouchDB < 2.1.0 - Remote Code Execution
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 10 - Desktop Bridge Virtual Registry CVE-2018-0880 Incomplete Fix Privilege Escalation
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
23RISK
open ↗Exploit-DB✓ VexDay Proof
glibc - 'realpath()' Privilege Escalation (Metasploit)
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISK
open ↗Exploit-DB✓ VexDay Proof
DHCP Client - Command Injection 'DynoRoot' (Metasploit)
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 10 - Child Process Restriction Mitigation Bypass
An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows
23RISK
open ↗Exploit-DB✓ VexDay Proof
Google Chrome - Integer Overflow when Processing WebAssembly Locals
An integer overflow on 32-bit systems in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker t
23RISK
open ↗Exploit-DB✓ VexDay Proof
TrendMicro OfficeScan XG 11.0 - Change Prevention Bypass
A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to take a series of steps to bypass or
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebRTC - VP9 Missing Frame Processing Out-of-Bounds Memory Access
Out of bounds array access in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially per
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebKit - Use-After-Free when Resuming Generator
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebRTC - VP9 Frame Processing Out-of-Bounds Memory Access
Incorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to pot
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebKit - WebAssembly Compilation Info Leak
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
28RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS Kernel - Heap Overflow Due to Lack of Lower Size Check in getvolattrlist
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
28RISK
open ↗Exploit-DB✓ VexDay Proof
PHP 7.2.2 - 'php_stream_url_wrap_http_ex' Buffer Overflow
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer
45RISK
open ↗Exploit-DB✓ VexDay Proof
XNU Kernel - Heap Overflow Due to Bad Bounds Checking in MPTCP
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS Kernel - Use-After-Free Due to Lack of Locking in nvidia GeForce Driver
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "NVIDIA Grap
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebKit - not_number defineProperties UAF (Metasploit)
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RISK
open ↗Exploit-DB✓ VexDay Proof
MyBB Recent Threads Plugin 1.0 - Cross-Site Scripting
The Recent Threads plugin before 1.1 for MyBB allows XSS via a thread subject.
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebKit - not_number defineProperties UAF (Metasploit)
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RISK
open ↗Exploit-DB✓ VexDay Proof
WebKit - not_number defineProperties UAF (Metasploit)
The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denia
91RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - EntrySimpleObjectSlotGetter Type Confusion
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RISK
open ↗Exploit-DB✓ VexDay Proof
Dolibarr ERP/CRM 7.0.0 - (Authenticated) SQL Injection
SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vecto
60RISK
open ↗Exploit-DB✓ VexDay Proof
MachForm < 4.2.3 - SQL Injection / Path Traversal / Upload Bypass
An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically
23RISK
open ↗Exploit-DB✓ VexDay Proof
MachForm < 4.2.3 - SQL Injection / Path Traversal / Upload Bypass
An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
MachForm < 4.2.3 - SQL Injection / Path Traversal / Upload Bypass
An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path fr
28RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle WebCenter Sites 11.1.1.8.0/12.2.1.x - Cross-Site Scripting
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.