Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,492GitHub PoC 14,286VulnCheck XDB 8,703Nuclei 4,314Metasploit 3,474✓ verified onlyrecentpopularrisk
77,620 exploits
Exploit-DB
ZKTeco ZEM/ZMM 8.88 - Missing Authentication
Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct r
41RISK
open ↗Exploit-DB
Label Studio 1.5.0 - Authenticated Server Side Request Forgery (SSRF)
A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.
23RISK
open ↗Exploit-DB
ReQlogic v11.3 - Reflected Cross-Site Scripting (XSS)
Multiple cross-site scripting (XSS) vulnerabilities in ReQlogic v11.3 allow attackers to execute arbitrary web scripts o
48RISK
open ↗Exploit-DB
X-Skipper-Proxy v0.13.237 - Server Side Request Forgery (SSRF)
Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
53RISK
open ↗GitHub PoC
Bash Script for Checking Command Injection Vulnerability on CentOS Web Panel [CWP] (CVE-2022-44877)
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISK
open ↗Exploit-DB✓ VexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
Stored Cross-Site Scripting Vulnerability In File Parameter in zoneminder
41RISK
open ↗Exploit-DB✓ VexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
Denial of service through logs in zoneminder
33RISK
open ↗Exploit-DB✓ VexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
CSRF key bypass using HTTP methods in zoneminder
41RISK
open ↗VulnCheck XDB
initial-access
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISK
open ↗VulnCheck XDB
initial-access
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8
85RISK
open ↗GitHub PoC★ 319
EXP for CVE-2023-28434 MinIO unauthorized to RCE
MinIO is vulnerable to privilege escalation on Linux/MacOS
71RISK
open ↗GitHub PoC★ 2
通过vulhub的复现过程实现了,基本的批量检测。比较垃圾但是勉强能用
Minio Information Disclosure in Cluster Deployment
100RISK
open ↗GitHub PoC★ 3
Arbitrary File Disclosure Vulnerability in Icinga Web 2 <2.8.6, <2.9.6, <2.10
Path traversal in Icinga Web 2
78RISK
open ↗VulnCheck XDB
remote-with-credentials
MinIO is vulnerable to privilege escalation on Linux/MacOS
71RISK
open ↗Exploit-DB
FortiOS_ FortiProxy_ FortiSwitchManager v7.2.1 - Authentication Bypass
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open ↗Exploit-DB✓ VexDay Proof
Grafana <=6.2.4 - HTML Injection
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the
35RISK
open ↗GitHub PoC
PoC for CVE-2022-39952 affecting Fortinet FortiNAC.
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8
85RISK
open ↗VulnCheck XDB
initial-access
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open ↗GitHub PoC★ 5
0xNahim/CVE-2023-23752
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗VulnCheck XDB
initial-access
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISK
open ↗VulnCheck XDB
initial-access
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISK
open ↗GitHub PoC★ 1
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information.
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗GitHub PoC★ 3
Unauthenticated RCE in Open Web Analytics version <1.7.4
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISK
open ↗GitHub PoC★ 1
pfBlockerNG <= 2.1.4_26 Unauth RCE (CVE-2022-31814)
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISK
open ↗GitHub PoC★ 3
pfBlockerNG <= 2.1.4_26 Unauth RCE (CVE-2022-31814)
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.