Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,697cataloged exploits
36,715CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,475Referência 23,264GitHub PoC 15,172VulnCheck XDB 8,920Nuclei 4,373Metasploit 3,493✓ verified onlyrecentpopularrisk
24,475 exploits
Exploit-DB
Intelbras IWR 3000N 1.5.0 - Cross-Site Request Forgery
A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstr
23RISK
open ↗Exploit-DB
Spring Cloud Config 2.1.x - Path Traversal (Metasploit)
Directory Traversal with spring-cloud-config-server
60RISK
open ↗Exploit-DB✓ VexDay Proof
AIS logistics ESEL-Server - Unauthenticated SQL Injection Remote Code Execution (Metasploit)
SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app)
50RISK
open ↗Exploit-DB✓ VexDay Proof
Pimcore < 5.71 - Unserialize Remote Code Execution (Metasploit)
An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/c
50RISK
open ↗Exploit-DB
HumHub 1.3.12 - Cross-Site Scripting
A cross-site scripting (XSS) vulnerability in HumHub 1.3.12 allows remote attackers to inject arbitrary web script or HT
23RISK
open ↗Exploit-DB
Apache Pluto 3.0.0 / 3.0.1 - Persistent Cross-Site Scripting
The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XS
28RISK
open ↗Exploit-DB✓ VexDay Proof
systemd - DynamicUser can Create setuid Binaries when Assisted by Another Process
It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of
33RISK
open ↗Exploit-DB✓ VexDay Proof
systemd - DynamicUser can Create setuid Binaries when Assisted by Another Process
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allo
33RISK
open ↗Exploit-DB
JioFi 4G M2S 1.0.2 - Denial of Service
cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices allows a DoS (Hang) via the mask POST parameter.
23RISK
open ↗Exploit-DB
JioFi 4G M2S 1.0.2 - 'mask' Cross-Site Scripting
cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices has XSS and HTML injection via the mask POST parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
RARLAB WinRAR 5.61 - ACE Format Input Validation Remote Code Execution (Metasploit)
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open ↗Exploit-DB✓ VexDay Proof
VirtualBox 6.0.4 r128413 - COM RPC Interface Code Injection Host Privilege Escalation
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RISK
open ↗Exploit-DB✓ VexDay Proof
systemd - Lack of Seat Verification in PAM Module Permits Spoofing Active Session to polkit
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using t
33RISK
open ↗Exploit-DB
Msvod 10 - Cross-Site Request Forgery (Change User Information)
Msvod v10 has a CSRF vulnerability to change user information via the admin/member/edit.html URI.
23RISK
open ↗Exploit-DB
UliCMS 2019.2 / 2019.1 - Multiple Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitra
23RISK
open ↗Exploit-DB
74CMS 5.0.1 - Cross-Site Request Forgery (Add New Admin User)
74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.
23RISK
open ↗Exploit-DB
QNAP myQNAPcloud Connect 1.3.4.0317 - 'Username/Password' Denial of Service
Buffer Overflow vulnerability in myQNAPcloud Connect 1.3.3.0925 and earlier could allow remote attackers to crash the pr
23RISK
open ↗Exploit-DB✓ VexDay Proof
SystemTap 1.3 - MODPROBE_OPTIONS Privilege Escalation (Metasploit)
The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allow
38RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Business Intelligence 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 - Directory Traversal
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publi
50RISK
open ↗Exploit-DB✓ VexDay Proof
Atlassian Confluence Widget Connector Macro - Velocity Template Injection (Metasploit)
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Business Intelligence / XML Publisher 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 - XML External Entity Injection
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publi
100RISK
open ↗Exploit-DB✓ VexDay Proof
LibreOffice < 6.0.7 / 6.1.3 - Macro Code Execution (Metasploit)
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could
68RISK
open ↗Exploit-DB
Evernote 7.9 - Code Execution via Path Traversal
Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file
23RISK
open ↗Exploit-DB
Netwide Assembler (NASM) 2.14rc15 - NULL Pointer Dereference (PoC)
asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a deni
23RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Java Runtime Environment - Heap Corruption During TTF font Rendering in GlyphIterator::setCurrGlyphID
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Ja
28RISK
open ↗Exploit-DB
ASUS HG100 - Denial of Service
ASUS HG100 devices allow denial of service via an IPv4 packet flood.
28RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Java Runtime Environment - Heap Corruption During TTF font Rendering in sc_FindExtrema4
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Ja
28RISK
open ↗Exploit-DB
Zyxel ZyWall 310 / ZyWall 110 / USG1900 / ATP500 / USG40 - Login Page Cross-Site Scripting
On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, U
43RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 10 1809 - LUAFV Delayed Virtualization MAXIMUM_ACCESS DesiredAccess Privilege Escalation
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 10 1809 - LUAFV NtSetCachedSigningLevel Device Guard Bypass
A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Wind
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.