Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,832GitHub PoC 14,991VulnCheck XDB 8,829Nuclei 4,357Metasploit 3,489✓ verified onlyrecentpopularrisk
3,477 exploits
Metasploit300
glibc 'realpath()' Privilege Escalation
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISK
open ↗Metasploit300
GitStack Unauthenticated REST API Requests
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau
60RISK
open ↗Metasploit500
GitStack Unsanitized Argument RCE
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau
60RISK
open ↗Metasploit600
Cambium ePMP1000 'get_chart' Shell via Command Injection (v3.1-3.5-RC7)
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web
60RISK
open ↗Metasploit600
Monstra CMS Authenticated Arbitrary File Upload
Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for exa
30RISK
open ↗Metasploit600
GoAhead Web Server LD_PRELOAD Arbitrary Module Load
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RISK
open ↗Metasploit600
Linksys WVBR0-25 User-Agent Command Execution
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authe
60RISK
open ↗Metasploit400
Commvault Communications Service (cvd) Command Injection
A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain mess
30RISK
open ↗Metasploit600
Apache Spark Unauthenticated Command Execution
From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the su
50RISK
open ↗Metasploit600
Palo Alto Networks readSessionVarsFromFile() Session Corruption
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RISK
open ↗Metasploit600
Mac OS X Root Privilege Escalation
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The is
50RISK
open ↗Metasploit300
Clickjacking Vulnerability In CSRF Error Page pfSense
pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged e
30RISK
open ↗Metasploit0
Microsoft Office CVE-2017-11882
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open ↗Metasploit500
Dup Scout Enterprise Login Buffer Overflow
A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9
40RISK
open ↗Metasploit600
Polycom Shell HDX Series Traceroute Command Execution
Polycom HDX Series Telnet Command Injection via lan traceroute
36RISK
open ↗Metasploit500
Linux BPF Sign Extension Local Privilege Escalation
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open ↗Metasploit300
Roundcube TimeZone Authenticated File Disclosure
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary file
98RISK
open ↗Metasploit300
Samsung Internet Browser SOP Bypass
Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive informat
60RISK
open ↗Metasploit600
Synology DiskStation Manager smart.cgi Remote Command Execution
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authe
60RISK
open ↗Metasploit600
pfSense authenticated group member RCE
pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_
30RISK
open ↗Metasploit400
Advantech WebAccess Webvrpcs Service Opcode 80061 Stack Buffer Overflow
A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The applicati
43RISK
open ↗Metasploit300
Brother Debut http Denial Of Service
The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST requ
50RISK
open ↗Metasploit600
Xplico Remote Code Execution
Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name
60RISK
open ↗Metasploit600
Tuleap 9.6 Second-Order PHP Object Injection
An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentEl
50RISK
open ↗Metasploit300
Ayukov NFTP FTP Client Buffer Overflow
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
50RISK
open ↗Metasploit600
Oracle WebLogic wls-wsat Component Deserialization RCE
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open ↗Metasploit300
Easy Chat Server User Registeration Buffer Overflow (SEH)
There is a remote stack-based buffer overflow (SEH) in register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1
23RISK
open ↗Metasploit600
Trend Micro InterScan Messaging Security (Virtual Appliance) Remote Code Execution
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote att
30RISK
open ↗Metasploit600
Trend Micro InterScan Messaging Security (Virtual Appliance) Remote Code Execution
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote att
30RISK
open ↗Metasploit600
Trend Micro InterScan Messaging Security (Virtual Appliance) Remote Code Execution
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 before CP 1644 has XSS.
18RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.