Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,832GitHub PoC 14,991VulnCheck XDB 8,829Nuclei 4,357Metasploit 3,489✓ verified onlyrecentpopularrisk
24,695 exploits
Exploit-DB✓ VexDay Proof
Symantec Endpoint Protection 12.1 - Tamper-Protection Bypass
Prior to SEP 14 RU1 Symantec Endpoint Protection product can encounter an issue of Tamper-Protection Bypass, which is a
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP 7.1.8 - Heap Buffer Overflow
In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian hand
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 11 - 'jscript!JsErrorToString' Use-After-Free
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Window
35RISK
open ↗Exploit-DB✓ VexDay Proof
tnftp - 'savefile' Arbitrary Command Execution (Metasploit)
The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 thro
50RISK
open ↗Exploit-DB✓ VexDay Proof
Ipswitch WS_FTP Professional < 12.6.0.3 - Local Buffer Overflow (SEH)
Ipswitch WS_FTP Professional before 12.6.0.3 has buffer overflows in the local search field and the backup locations fie
23RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Java SE - Web Start jnlp XML External Entity Processing Information Disclosure
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affecte
23RISK
open ↗Exploit-DB✓ VexDay Proof
Unitrends UEB 9 - bpserverd Authentication Bypass Remote Command Execution (Metasploit)
It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xin
50RISK
open ↗Exploit-DB✓ VexDay Proof
Unitrends UEB 9 - http api/storage Remote Root (Metasploit)
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of
60RISK
open ↗Exploit-DB✓ VexDay Proof
Kaltura < 13.2.0 - Remote Code Execution
The getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, wh
60RISK
open ↗Exploit-DB✓ VexDay Proof
Ayukov NFTP FTP Client < 2.0 - Remote Buffer Overflow
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
50RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox < 55 - Denial of Service
If a long user name is used in a username/password combination in a site URL (such as " http://UserName:Password@example
28RISK
open ↗Exploit-DB✓ VexDay Proof
Xen - Pagetable De-typing Unbounded Recursion
An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to cause a denial of service (unbounded recu
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'nt!NtQueryObject (ObjectNameInformation)' Kernel Pool Memory Disclosure
The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Wind
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - 'RegexHelper::StringReplace' Must Call the Callback Function with Updating ImplicitCallFlags
ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 11 (Windows 7 x86) - 'mshtml.dll' Remote Code Execution (MS17-007)
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilde
93RISK
open ↗Exploit-DB✓ VexDay Proof
Apple iOS 10.2 (14C92) - Remote Code Execution
An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. The issue invo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - 'StackScriptFunction::BoxState::Box' Accesses to Uninitialized Pointers (Denial of Service)
ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker
35RISK
open ↗Exploit-DB✓ VexDay Proof
Tomcat - Remote Code Execution via JSP Upload Bypass (Metasploit)
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - Incorrect GenerateBailOut Calling Patterns
ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 11 (Windows 7 x86) - 'mshtml.dll' Remote Code Execution (MS17-007)
Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via
75RISK
open ↗Exploit-DB✓ VexDay Proof
Apache Solr 7.0.1 - XML External Entity Expansion / Remote Code Execution
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction wi
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 10 - WLDP/MSHTML CLSID UMCI Bypass
The Microsoft Device Guard on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (2)
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISK
open ↗Exploit-DB✓ VexDay Proof
PyroBatchFTP 3.17 - Buffer Overflow (SEH)
EmTec PyroBatchFTP before 3.18 allows remote servers to cause a denial of service (application crash).
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebKit JSC - 'BytecodeGenerator::emitGetByVal' Incorrect Optimization (2)
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud befor
28RISK
open ↗Exploit-DB✓ VexDay Proof
Dnsmasq < 2.78 - Stack Overflow
Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execu
45RISK
open ↗Exploit-DB✓ VexDay Proof
Dnsmasq < 2.78 - Integer Underflow
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-su
35RISK
open ↗Exploit-DB✓ VexDay Proof
phpCollab 2.5.1 - Arbitrary File Upload
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authentica
60RISK
open ↗Exploit-DB✓ VexDay Proof
Dnsmasq < 2.78 - Lack of free() Denial of Service
Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote
45RISK
open ↗Exploit-DB✓ VexDay Proof
Dnsmasq < 2.78 - Information Leak
dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vect
35RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.