Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,429GitHub PoC 14,270VulnCheck XDB 8,693Nuclei 4,299Metasploit 3,474✓ verified onlyrecentpopularrisk
22,429 exploits
Referência
CVE-2021-22145
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the abil
60RISK
open ↗Referência✓ VexDay Proof
Kipper 2.01 - Cross-Site Scripting / Local File Inclusion / File Disclosure
Cross-site scripting (XSS) vulnerability in default.php in Kipper 2.01 allows remote attackers to inject arbitrary web s
23RISK
open ↗Referência
CVE-2014-3791
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 6.8 allows remote attackers to execute arbitrary code
60RISK
open ↗Referência
CVE-2022-1162
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE
85RISK
open ↗Referência
CVE-2012-4773
Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack
23RISK
open ↗Referência✓ VexDay Proof
S-CMS 1.1 Stable - Insecure Cookie Handling / Mass Page Delete
SQL injection vulnerability in admin/delete_page.php in S-Cms 1.1 Stable allows remote attackers to execute arbitrary SQ
23RISK
open ↗Referência✓ VexDay Proof
S-CMS 1.1 Stable - Insecure Cookie Handling / Mass Page Delete
S-Cms 1.1 Stable allows remote attackers to bypass authentication and obtain administrative access via an OK value for t
23RISK
open ↗Referência✓ VexDay Proof
pHNews Alpha 1 - 'genbackup.php' Database Disclosure
pHNews Alpha 1 stores sensitive information under the web root with insufficient access control, which allows remote att
23RISK
open ↗Referência✓ VexDay Proof
IBM Director 5.20.3su2 CIM Server - Remote Denial of Service
The CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to cause a denial of se
23RISK
open ↗Referência✓ VexDay Proof
Media Commands - '.m3u' / '.m3l' / '.TXT' / '.LRC' Local Heap Overflow (PoC)
Multiple heap-based buffer overflows in Media Commands 1.0 allow remote attackers to execute arbitrary code or cause a d
23RISK
open ↗Referência✓ VexDay Proof
OneOrZero Helpdesk 1.6.5.7 - Local File Inclusion
Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read
23RISK
open ↗Referência
CVE-2009-0927
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows r
100RISK
open ↗Referência
CVE-2019-9193
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open ↗Referência✓ VexDay Proof
BlogHelper - Remote Configuration File Disclosure
BlogHelper stores common_db.inc under the web root with insufficient access control, which allows remote attackers to do
23RISK
open ↗Referência✓ VexDay Proof
Yahoo! Messenger Webcam 8.1 - ActiveX Remote Buffer Overflow
Buffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows
50RISK
open ↗Referência
CVE-2018-20526
Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.
60RISK
open ↗Referência
CVE-2018-20526
Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.
60RISK
open ↗Referência
CVE-2024-25004
KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insuf
41RISK
open ↗Referência
CVE-2012-4891
Cross-site scripting (XSS) vulnerability in fw/index2.do in ManageEngine Firewall Analyzer 7.2 allows remote attackers t
23RISK
open ↗Referência
CVE-2024-25004
KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insuf
41RISK
open ↗Referência
CVE-2015-8249
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and e
60RISK
open ↗Referência
CVE-2015-8249
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and e
60RISK
open ↗Referência✓ VexDay Proof
Linux Kernel 2.6 (Gentoo / Ubuntu 8.10/9.04) UDEV < 1.4.1 - Local Privilege Escalation (2)
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to ga
60RISK
open ↗Referência
CVE-2017-17560
An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquer
60RISK
open ↗Referência
CVE-2014-7868
Multiple SQL injection vulnerabilities in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT
45RISK
open ↗Referência
CVE-2011-0762
The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a deni
60RISK
open ↗Referência
CVE-2014-9618
The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote att
60RISK
open ↗Referência
CVE-2014-9618
The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote att
60RISK
open ↗Referência
CVE-2016-7202
The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute a
45RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.