Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
80,557cataloged exploits
37,313CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,478Referência 23,776GitHub PoC 15,367VulnCheck XDB 9,019Nuclei 4,415Metasploit 3,502✓ verified onlyrecentpopularrisk
24,478 exploits
Exploit-DB✓ VexDay Proof
HP LoadRunner - lrFileIOService ActiveX WriteFileString Remote Code Execution (Metasploit)
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown ve
50RISK
open ↗Exploit-DB✓ VexDay Proof
KingView 6.53 - 'SuperGrid' Insecure ActiveX Control
The SUPERGRIDLib.SuperGrid ActiveX control in SuperGrid.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53
28RISK
open ↗Exploit-DB
WordPress Plugin IndiaNIC Testimonial - Multiple Vulnerabilities
SQL injection vulnerability in testimonial.php in the IndiaNIC Testimonial plugin 2.2 for WordPress allows remote attack
23RISK
open ↗Exploit-DB
Oracle Java lookUpByteBI - Heap Buffer Overflow
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 U
28RISK
open ↗Exploit-DB
WordPress Plugin IndiaNIC Testimonial - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in the IndiaNIC Testimonial plugin 2.2 for WordPress allow re
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.8.4 - Local Privilege Escalation
sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypas
38RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX - Sudo Password Bypass (Metasploit)
sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypas
38RISK
open ↗Exploit-DB✓ VexDay Proof
AVTECH DVR Firmware 1017-1003-1009-1003 - Multiple Vulnerabilities
Buffer overflow in cgi-bin/user/Config.cgi in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possi
23RISK
open ↗Exploit-DB✓ VexDay Proof
VMware - Setuid VMware-mount Unsafe popen(3) (Metasploit)
vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allo
38RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox - XMLSerializer Use-After-Free (Metasploit)
Use-after-free vulnerability in the serializeToStream implementation in the XMLSerializer component in Mozilla Firefox b
50RISK
open ↗Exploit-DB✓ VexDay Proof
HP LoadRunner - lrFileIOService ActiveX Remote Code Execution (Metasploit)
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown ve
50RISK
open ↗Exploit-DB✓ VexDay Proof
AVTECH DVR Firmware 1017-1003-1009-1003 - Multiple Vulnerabilities
AVTECH AVN801 DVR has a security bypass via the administration login captcha
43RISK
open ↗Exploit-DB✓ VexDay Proof
AVTECH DVR Firmware 1017-1003-1009-1003 - Multiple Vulnerabilities
Buffer overflow in the RTSP Packet Handler in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Aloaha PDF Suite - Remote Stack Buffer Overflow
Stack-based buffer overflow in AloahaPDFViewer 5.0.0.7 and earlier in Aloaha PDF Suite FREE allows remote attackers to e
23RISK
open ↗Exploit-DB✓ VexDay Proof
cm3 Acora CMS - 'top.aspx' Information Disclosure
DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote at
23RISK
open ↗Exploit-DB✓ VexDay Proof
Winamp 5.63 - 'winamp.ini' Local Overflow
Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial
28RISK
open ↗Exploit-DB
Loftek Nexus 543 IP Cameras - Multiple Vulnerabilities
The Loftek Nexus 543 IP Camera allows remote attackers to obtain (1) IP addresses via a request to get_realip.cgi or (2)
23RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Endeca Server - Remote Command Execution (Metasploit)
Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 7.4.0 and 7.5.1.1 allows rem
50RISK
open ↗Exploit-DB✓ VexDay Proof
SearchBlox - Multiple Information Disclosure Vulnerabilities
servlet/CollectionListServlet in SearchBlox before 7.5 build 1 allows remote attackers to read usernames and passwords v
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ovidentia 7.9.4 - Multiple Vulnerabilities
SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open ↗Exploit-DB✓ VexDay Proof
VMware - Setuid VMware-mount Popen lsb_release Privilege Escalation
vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allo
38RISK
open ↗Exploit-DB
Netgear ProSafe - Denial of Service
NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier, GS748Tv4 5.4.1.14, and GS510TP 5.0.4.4 allows
23RISK
open ↗Exploit-DB
Netgear ProSafe - Information Disclosure
NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier; GS748Tv4 with firmware 5.4.1.14; GS510TP with
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.