Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,832GitHub PoC 14,991VulnCheck XDB 8,829Nuclei 4,357Metasploit 3,489✓ verified onlyrecentpopularrisk
24,695 exploits
Exploit-DB✓ VexDay Proof
Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code (Metasploit)
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RISK
open ↗Exploit-DB✓ VexDay Proof
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execut
50RISK
open ↗Exploit-DB✓ VexDay Proof
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker
50RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS - ReportCrash mach port Replacement due to Failure to Respect MIG Ownership Rules
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2
23RISK
open ↗Exploit-DB✓ VexDay Proof
Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code Execution (PoC)
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Overflow when Playing Sound
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Heap Overflow vulnerability. Successful exploitat
28RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Out-of-Bounds Write in blur Filtering
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exp
28RISK
open ↗Exploit-DB✓ VexDay Proof
ASUS infosvr - Authentication Bypass Command Execution (Metasploit)
common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC
60RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Overflow in Slab Rendering
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exp
28RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Info Leak in Image Inflation
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful expl
28RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Weblogic Server 10.3.6.0 / 12.1.3.0 / 12.2.1.2 / 12.2.1.3 - Deserialization Remote Command Execution
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open ↗Exploit-DB✓ VexDay Proof
Match Clone Script 1.0.4 - Cross-Site Scripting
PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to searchbyid.php (aka the "View Search By Id" sc
23RISK
open ↗Exploit-DB✓ VexDay Proof
Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (Metasploit)
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open ↗Exploit-DB✓ VexDay Proof
Ultra MiniHTTPd 1.2 - 'GET' Remote Stack Buffer Overflow (PoC)
Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resour
50RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'nt!NtQueryVirtualMemory (MemoryImageInformation)' Kernel 64-bit Stack Memory Disclosure
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'nt!NtQueryFullAttributesFile' Kernel Stack Memory Disclosure
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'nt!NtQueryAttributesFile' Kernel Stack Memory Disclosure
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'nt!NtQuerySystemInformation (SystemPageFileInformation(Ex))' Kernel 64-bit Stack Memory Disclosure
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'nt!NtQueryInformationProcess (ProcessImageFileName)' Kernel 64-bit Pool/Stack Memory Disclosure
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'nt!NtQueryVolumeInformationFile' Kernel Stack Memory Disclosure
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'nt!NtQueryVirtualMemory (Memory(Privileged)BasicInformation)' Kernel 64-bit Stack Memory Disclosure
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'CiSetFileCache' TOCTOU Incomplete Fix
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security F
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'nt!NtQueryInformationTransactionManager (TransactionManagerRecoveryInformation)' Kernel Pool Memory Disclosure
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open ↗Exploit-DB✓ VexDay Proof
Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open ↗Exploit-DB✓ VexDay Proof
Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (PoC)
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open ↗Exploit-DB✓ VexDay Proof
WebKit - WebAssembly Parsing Does not Correctly Check Section Order
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud b
28RISK
open ↗Exploit-DB✓ VexDay Proof
Cobub Razor 0.7.2 - Cross-Site Request Forgery
An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/manage/chann
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Defender - 'mpengine.dll' Memory Corruption
A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a speci
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Multiple Use-After-Free Issues in jscript Array Methods
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Se
35RISK
open ↗Exploit-DB✓ VexDay Proof
Google Chrome V8 - 'ElementsAccessorBase::CollectValuesOrEntriesImpl' Type Confusion
Type Confusion in the implementation of __defineGetter__ in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.