Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,104GitHub PoC 15,075VulnCheck XDB 8,883Nuclei 4,365Metasploit 3,493✓ verified onlyrecentpopularrisk
24,460 exploits
Exploit-DB
WordPress Plugin BBPress 2.5 - Unauthenticated Privilege Escalation
An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Regi
35RISK
open ↗Exploit-DB
VMware vCenter Server 6.7 - Authentication Bypass
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RISK
open ↗Exploit-DB
QuickBox Pro 2.1.8 - Authenticated Remote Code Execution
QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execut
28RISK
open ↗Exploit-DB✓ VexDay Proof
Pi-hole 4.4.0 - Remote Code Execution (Authenticated)
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RISK
open ↗Exploit-DB✓ VexDay Proof
Plesk/myLittleAdmin - ViewState .NET Deserialization (Metasploit)
The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcod
60RISK
open ↗Exploit-DB✓ VexDay Proof
Synology DiskStation Manager - smart.cgi Remote Command Execution (Metasploit)
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authe
60RISK
open ↗Exploit-DB✓ VexDay Proof
WebLogic Server - Deserialization RCE - BadAttributeValueExpException (Metasploit)
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISK
open ↗Exploit-DB✓ VexDay Proof
Druva inSync Windows Client 6.6.3 - Local Privilege Escalation
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitra
38RISK
open ↗Exploit-DB
OpenEDX platform Ironwood 2.5 - Remote Code Execution
Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>Ne
28RISK
open ↗Exploit-DB
BIND - 'TSIG' Denial of Service
A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c
78RISK
open ↗Exploit-DB✓ VexDay Proof
Pi-Hole - heisenbergCompensator Blocklist OS Command Execution (Metasploit)
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RISK
open ↗Exploit-DB
Submitty 20.04.01 - Persistent Cross-Site Scripting
Submitty through 20.04.01 allows XSS via upload of an SVG document, as demonstrated by an attack by a Student against a
23RISK
open ↗Exploit-DB
Mikrotik Router Monitoring System 1.2.3 - 'community' SQL Injection
An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community
23RISK
open ↗Exploit-DB
Oracle Hospitality RES 3700 5.7 - Remote Code Execution
Vulnerability in the Oracle Hospitality RES 3700 component of Oracle Food and Beverage Applications. The supported versi
28RISK
open ↗Exploit-DB
HP LinuxKI 6.01 - Remote Command Injection
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
60RISK
open ↗Exploit-DB
Cisco Digital Network Architecture Center 1.3.1.4 - Persistent Cross-Site Scripting
Cisco Digital Network Architecture Center Stored Cross-Site Scripting Vulnerability
33RISK
open ↗Exploit-DB
WordPress Plugin ChopSlider 3.4 - 'id' SQL Injection
A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in
60RISK
open ↗Exploit-DB
SolarWinds MSP PME Cache Service 1.1.14 - Insecure File Permissions
An issue was discovered in SolarWinds MSP PME (Patch Management Engine) Cache Service before 1.1.15 in the Advanced Moni
28RISK
open ↗Exploit-DB
Pi-hole < 4.4 - Authenticated Remote Code Execution
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RISK
open ↗Exploit-DB
Pi-hole < 4.4 - Authenticated Remote Code Execution / Privileges Escalation
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RISK
open ↗Exploit-DB
Saltstack 3000.1 - Remote Code Execution
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open ↗Exploit-DB
Saltstack 3000.1 - Remote Code Execution
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open ↗Exploit-DB
Apache OFBiz 17.12.03 - Cross-Site Request Forgery (Account Takeover)
Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.
35RISK
open ↗Exploit-DB✓ VexDay Proof
Apache Shiro 1.2.4 - Cookie RememberME Deserial RCE (Metasploit)
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RISK
open ↗Exploit-DB✓ VexDay Proof
Druva inSync Windows Client 6.5.2 - Local Privilege Escalation
Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, u
38RISK
open ↗Exploit-DB✓ VexDay Proof
Docker-Credential-Wincred.exe - Privilege Escalation (Metasploit)
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-c
98RISK
open ↗Exploit-DB
Source Engine CS:GO BuildID: 4937372 - Arbitrary Code Execution
Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in
23RISK
open ↗Exploit-DB
Oracle Solaris Common Desktop Environment 1.6 - Local Privilege Escalation
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment). Supported version
41RISK
open ↗Exploit-DB
Neowise CarbonFTP 1.4 - Insecure Proprietary Password Encryption
CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FT
23RISK
open ↗Exploit-DB✓ VexDay Proof
Unraid 6.8.0 - Auth Bypass PHP Code Execution (Metasploit)
Unraid through 6.8.0 allows Remote Code Execution.
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.