Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,526cataloged exploits
36,593CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,475Referência 23,152GitHub PoC 15,158VulnCheck XDB 8,883Nuclei 4,365Metasploit 3,493✓ verified onlyrecentpopularrisk
24,460 exploits
Exploit-DB
Prima Access Control 2.3.35 - 'HwName' Persistent Cross-Site Scripting
Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being ret
23RISK
open ↗Exploit-DB
eMerge E3 Access Controller 4.6.07 - Remote Code Execution
Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).
28RISK
open ↗Exploit-DB
CBAS-Web 19.0.0 - Information Disclosure
Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.
23RISK
open ↗Exploit-DB
Adrenalin Core HCM 5.4.0 - 'strAction' Reflected Cross-Site Scripting
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied
23RISK
open ↗Exploit-DB
Optergy 2.3.0a - Remote Code Execution (Backdoor)
Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.
60RISK
open ↗Exploit-DB
CBAS-Web 19.0.0 - Username Enumeration
Computrols CBAS 18.0.0 allows Username Enumeration.
23RISK
open ↗Exploit-DB
Computrols CBAS-Web 19.0.0 - 'username' Reflected Cross-Site Scripting
Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and passw
23RISK
open ↗Exploit-DB
Prima Access Control 2.3.35 - Arbitrary File Upload
Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when
28RISK
open ↗Exploit-DB
eMerge E3 1.00-06 - Remote Code Execution
Linear eMerge E3-Series devices allow Command Injections.
100RISK
open ↗Exploit-DB
CBAS-Web 19.0.0 - Cross-Site Request Forgery (Add Super Admin)
Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.
23RISK
open ↗Exploit-DB
Optergy 2.3.0a - Remote Code Execution
Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.
28RISK
open ↗Exploit-DB
Atlassian Confluence 6.15.1 - Directory Traversal
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
100RISK
open ↗Exploit-DB
eMerge E3 1.00-06 - Unauthenticated Directory Traversal
Linear eMerge E3-Series devices allow File Inclusion.
60RISK
open ↗Exploit-DB
Optergy 2.3.0a - Cross-Site Request Forgery (Add Admin)
Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF).
23RISK
open ↗Exploit-DB
eMerge E3 1.00-06 - Privilege Escalation
Linear eMerge E3-Series devices allow File Inclusion.
60RISK
open ↗Exploit-DB
eMerge E3 1.00-06 - 'layout' Reflected Cross-Site Scripting
Linear eMerge E3-Series devices allow XSS.
50RISK
open ↗Exploit-DB
eMerge50P 5000P 4.6.07 - Remote Code Execution
Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.
35RISK
open ↗Exploit-DB
FlexAir Access Control 2.3.35 - Authentication Bypass
Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash valu
28RISK
open ↗Exploit-DB
eMerge E3 1.00-06 - Cross-Site Request Forgery
Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).
28RISK
open ↗Exploit-DB
eMerge E3 1.00-06 - Arbitrary File Upload
Linear eMerge E3-Series devices allow Unrestricted File Upload.
35RISK
open ↗Exploit-DB
Adrenalin Core HCM 5.4.0 - 'prntDDLCntrlName' Reflected Cross-Site Scripting
Adrenalin HRMS version 5.4.0 contains a Reflected Cross Site Scripting (XSS) vulnerability in the ApplicationtEmployeeSe
23RISK
open ↗Exploit-DB✓ VexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
An out-of-bounds read was addressed with improved input validation.
28RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed OTF Font (CFF Table)
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed JBIG2Globals Stream
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RISK
open ↗Exploit-DB✓ VexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS
23RISK
open ↗Exploit-DB
Jenkins build-metrics plugin 1.3 - 'label' Cross-Site Scripting
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML
50RISK
open ↗Exploit-DB✓ VexDay Proof
Android Janus - APK Signature Bypass (Metasploit)
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RISK
open ↗Exploit-DB✓ VexDay Proof
rConfig - install Command Execution (Metasploit)
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RISK
open ↗Exploit-DB
Adive Framework 2.0.7 - Privilege Escalation
Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an ad
23RISK
open ↗Exploit-DB✓ VexDay Proof
JavaScriptCore - Type Confusion During Bailout when Reconstructing Arguments Objects
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPad
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.