Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,910GitHub PoC 14,997VulnCheck XDB 8,843Nuclei 4,358Metasploit 3,489✓ verified onlyrecentpopularrisk
78,958 exploits
GitHub PoC★ 10
lsw29475/CVE-2018-8611
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "
71RISK
open ↗VulnCheck XDB
initial-access
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability i
100RISK
open ↗Metasploit600
Git LFS Clone Command Exec
malicious repositories can execute remote code while cloning
58RISK
open ↗Exploit-DB
SEO Panel 4.8.0 - 'order_col' Blind SQL Injection (2)
The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads
28RISK
open ↗GitHub PoC★ 1
rebuild cve
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the mod
28RISK
open ↗VulnCheck XDB
local
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open ↗GitHub PoC★ 31
Read my blog for more info -
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open ↗GitHub PoC
edsonjt81/sudo-cve-2019-18634
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISK
open ↗GitHub PoC
edsonjt81/CVE-2019-14287-
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open ↗VulnCheck XDB
client-side
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch
83RISK
open ↗GitHub PoC★ 2
b1tg/CVE-2018-6065-exploit
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch
83RISK
open ↗GitHub PoC★ 66
CVE-2021-1732 poc & exp; tested on 20H2
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open ↗Exploit-DB
DzzOffice 2.02.1 - 'Multiple' Cross-Site Scripting (XSS)
attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter.
23RISK
open ↗Exploit-DB
RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Clinic Name", "Clinic Address", "Clinic City", or "Clinic Cont
23RISK
open ↗GitHub PoC★ 8
Automated tool to exploit sharepoint CVE-2019-0604
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RISK
open ↗VulnCheck XDB
initial-access
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RISK
open ↗VulnCheck XDB
initial-access
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open ↗Exploit-DB
CMS Made Simple 2.2.15 - 'title' Cross-Site Scripting (XSS)
CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > M
23RISK
open ↗Exploit-DB
RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Fever" or "Blood Pressure" field on the patients/register-repo
23RISK
open ↗GitHub PoC★ 13
CVE-2021-22192
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticat
53RISK
open ↗GitHub PoC★ 3
oneoy/CVE-2021-3493
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open ↗Exploit-DB
RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Full Name field on register-patient.php.
23RISK
open ↗Exploit-DB
RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
Stored XSS in Remote Clinic v2.0 in /medicines due to Medicine Name Field.
23RISK
open ↗Exploit-DB
RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Chat" and "Personal Address" field on staff/register.php
23RISK
open ↗GitHub PoC★ 3
POC exploit for CVE-2021-21972
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open ↗VulnCheck XDB
local
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.