Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,464Referência 22,936GitHub PoC 15,010VulnCheck XDB 8,846Nuclei 4,361Metasploit 3,490✓ verified onlyrecentpopularrisk
79,107 exploits
VulnCheck XDB
initial-access
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISK
open ↗GitHub PoC★ 1
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, City
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, o
23RISK
open ↗Exploit-DB
Comodo Unified Threat Management Web Console 2.7.0 - Remote Code Execution
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RISK
open ↗Metasploit600
Micro Focus Operations Bridge Reporter shrboadmin default password
An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The
23RISK
open ↗Exploit-DB
BlackCat CMS 1.3.6 - Cross-Site Request Forgery
An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote
23RISK
open ↗Exploit-DB
Mida eFramework 2.9.0 - Back Door Access
Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restric
28RISK
open ↗GitHub PoC
johnpathe/zerologon-cve-2020-1472-notes
Netlogon Elevation of Privilege Vulnerability
100RISK
open ↗GitHub PoC★ 1
A simple implementation/code smash of a bunch of other repos
Netlogon Elevation of Privilege Vulnerability
100RISK
open ↗GitHub PoC★ 10
CVE-2020-1472复现时使用的py文件整理打包
Netlogon Elevation of Privilege Vulnerability
100RISK
open ↗Exploit-DB
Mantis Bug Tracker 2.3.0 - Remote Code Execution (Unauthenticated)
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value
60RISK
open ↗Exploit-DB
SpamTitan 7.07 - Remote Code Execution (Authenticated)
An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.
23RISK
open ↗Exploit-DB
SpamTitan 7.07 - Remote Code Execution (Authenticated)
An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php woul
23RISK
open ↗Metasploit600
Sophos UTM WebAdmin SID Command Injection
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511
100RISK
open ↗Exploit-DB
SpamTitan 7.07 - Remote Code Execution (Authenticated)
An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page ma
23RISK
open ↗Exploit-DB
SpamTitan 7.07 - Remote Code Execution (Authenticated)
An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with th
23RISK
open ↗GitHub PoC
Scripts to verify and execute CVE-2019-14287 as part of Research
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open ↗Exploit-DB
Mantis Bug Tracker 2.3.0 - Remote Code Execution (Unauthenticated)
MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.
35RISK
open ↗Exploit-DB
Microsoft SQL Server Reporting Services 2016 - Remote Code Execution
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RISK
open ↗VulnCheck XDB
initial-access
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open ↗VulnCheck XDB
initial-access
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISK
open ↗GitHub PoC★ 61
Test script for CVE-2020-1472 for both RPC/TCP and RPC/SMB
Netlogon Elevation of Privilege Vulnerability
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.