Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,104GitHub PoC 15,075VulnCheck XDB 8,883Nuclei 4,365Metasploit 3,493✓ verified onlyrecentpopularrisk
24,460 exploits
Exploit-DB✓ VexDay Proof
Movable Type 7 r.5002 - XMLRPC API OS Command Injection (Metasploit)
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISK
open ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 4.8.1 - Remote Code Execution (RCE)
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open ↗Exploit-DB
Hikvision Web Server Build 210702 - Command Injection
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open ↗Exploit-DB
WordPress Plugin TaxoPress 3.0.7.1 - Stored Cross-Site Scripting (XSS) (Authenticated)
TaxoPress < 3.0.7.2 - Authenticated Stored Cross-Site Scripting (XSS)
23RISK
open ↗Exploit-DB
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (2)
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open ↗Exploit-DB
Jetty 9.4.37.v20210219 - Information Disclosure
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contai
70RISK
open ↗Exploit-DB
SonicWall SMA 10.2.1.0-17sv - Password Reset
An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal
45RISK
open ↗Exploit-DB
WordPress Theme Enfold 4.8.3 - Reflected Cross-Site Scripting (XSS)
Enfold Theme < 4.8.4 - Reflected Cross-Site Scripting (XSS)
23RISK
open ↗Exploit-DB
myfactory FMS 7.1-911 - 'Multiple' Reflected Cross-Site Scripting (XSS)
myfactory.FMS before 7.1-912 allows XSS via the UID parameter.
38RISK
open ↗Exploit-DB
myfactory FMS 7.1-911 - 'Multiple' Reflected Cross-Site Scripting (XSS)
myfactory.FMS before 7.1-912 allows XSS via the Error parameter.
38RISK
open ↗Exploit-DB
Mitsubishi Electric & INEA SmartRTU - Source Code Disclosure
Mitsubishi Electric Europe B.V. SmartRTU devices allow remote attackers to obtain sensitive information (directory listi
28RISK
open ↗Exploit-DB
Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traver
100RISK
open ↗Exploit-DB
Mitsubishi Electric & INEA SmartRTU - Reflected Cross-Site Scripting (XSS)
Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.
23RISK
open ↗Exploit-DB
Plastic SCM 10.0.16.5622 - WebAdmin Server Access
Plastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface.
23RISK
open ↗Exploit-DB
i-Panel Administration System 2.0 - Reflected Cross-site Scripting (XSS)
A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enable
38RISK
open ↗Exploit-DB
Sonicwall SonicOS 7.0 - Host Header Injection
A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management
43RISK
open ↗Exploit-DB✓ VexDay Proof
Apache HTTP Server 2.4.50 - Path Traversal & Remote Code Execution (RCE)
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open ↗Exploit-DB
Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using
50RISK
open ↗Exploit-DB
Maian-Cart 3.8 - Remote Code Execution (RCE) (Unauthenticated)
Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the
50RISK
open ↗Exploit-DB
django-unicorn 0.35.3 - Stored Cross-Site Scripting (XSS)
The Unicorn framework through 0.35.3 for Django allows XSS via component.name.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Google SLO-Generator 2.0.0 - Code Execution
Code execution in SLO Generator via YAML Payload
33RISK
open ↗Exploit-DB
Atlassian Jira Server Data Center 8.16.0 - Arbitrary File Read
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr
100RISK
open ↗Exploit-DB✓ VexDay Proof
Apache HTTP Server 2.4.49 - Path Traversal & Remote Code Execution (RCE)
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗Exploit-DB
Atlassian Confluence 7.12.2 - Pre-Authorization Arbitrary File Read
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authoriza
100RISK
open ↗Exploit-DB
WhatsUpGold 21.0.3 - Stored Cross-Site Scripting (XSS)
In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input.
23RISK
open ↗Exploit-DB
WordPress Plugin Select All Categories and Taxonomies 1.3.1 - Reflected Cross-Site Scripting (XSS)
Select All Categories and Taxonomies < 1.3.2 - Reflected Cross-Site Scripting (XSS)
43RISK
open ↗Exploit-DB
WordPress Plugin Redirect 404 to Parent 1.3.0 - Reflected Cross-Site Scripting
Redirect 404 to Parent < 1.3.1 - Reflected Cross-Site Scripting (XSS)
43RISK
open ↗Exploit-DB
WordPress Plugin Popup 1.10.4 - Reflected Cross-Site Scripting (XSS)
Popup by Supsystic < 1.10.5 - Reflected Cross-Site scripting (XSS)
43RISK
open ↗Exploit-DB
WordPress Plugin TranslatePress 2.0.8 - Stored Cross-Site Scripting (XSS) (Authenticated)
TranslatePress < 2.0.9 - Authenticated Stored Cross-Site Scripting
23RISK
open ↗Exploit-DB
WordPress Plugin Ultimate Maps 1.2.4 - Reflected Cross-Site Scripting (XSS)
Ultimate Maps by Supsystic < 1.2.5 - Reflected Cross-Site scripting (XSS)
43RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.