Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,666cataloged exploits
32,032CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,896GitHub PoC 13,204VulnCheck XDB 8,127Nuclei 4,191Metasploit 3,462✓ verified onlyrecentpopularrisk
22,786 exploits
Exploit-DB
DomainMOD 4.11.01 - Owner name Field Cross-Site Scripting
DomainMOD through 4.11.01 has XSS via the assets/add/account-owner.php Owner name field.
38RISK
open ↗Exploit-DB
NUUO NVRMini2 3.9.1 - (Authenticated) Command Injection
NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted reques
28RISK
open ↗Exploit-DB
Microsoft Lync for Mac 2011 - Injection Forced Browsing/Download
A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messa
35RISK
open ↗Exploit-DB
Rockwell Automation Allen-Bradley PowerMonitor 1000 - Incorrect Access Control Authentication Bypass
An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. An unauthenticated user can add/edit/rem
35RISK
open ↗Exploit-DB
DomainMOD 4.11.01 - Custom SSL Fields Cross-Site Scripting
DomainMOD through 4.11.01 has XSS via the admin/ssl-fields/add.php notes field for Custom SSL Fields.
38RISK
open ↗Exploit-DB
NEC Univerge Sv9100 WebPro - 6.00 - Predictable Session ID / Clear Text Password Storage
NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.
28RISK
open ↗Exploit-DB
FreshRSS 1.11.1 - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject
23RISK
open ↗Exploit-DB
DomainMOD 4.11.01 - Custom Domain Fields Cross-Site Scripting
DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Doma
23RISK
open ↗Exploit-DB
Apache Superset < 0.23 - Remote Code Execution
Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to pos
35RISK
open ↗Exploit-DB
CyberArk 9.7 - Memory Disclosure
CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replay
28RISK
open ↗Exploit-DB
Schneider Electric PLC - Session Calculation Authentication Bypass
A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware ver
35RISK
open ↗Exploit-DB
xorg-x11-server < 1.20.3 - 'modulepath' Local Privilege Escalation
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RISK
open ↗Exploit-DB
VBScript - 'OLEAUT32!VariantClear' and 'scrrun!VBADictionary::put_Item' Use-After-Free
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
35RISK
open ↗Exploit-DB
VBScript - 'rtFilter' Out-of-Bounds Read
An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which coul
35RISK
open ↗Exploit-DB
PhpSpreadsheet < 1.5.0 - XML External Entity (XXE)
securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 enco
23RISK
open ↗Exploit-DB
Unitrends Enterprise Backup - bpserverd Privilege Escalation (Metasploit)
It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL i
50RISK
open ↗Exploit-DB
WebKit JIT - 'ByteCodeParser::handleIntrinsicCall' Type Confusion
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RISK
open ↗Exploit-DB
WebKit JSC - BytecodeGenerator::hoistSloppyModeFunctionIfNecessary Does not Invalidate the 'ForInContext' Object
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RISK
open ↗Exploit-DB
WebKit JSC JIT - 'JSPropertyNameEnumerator' Type Confusion
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
35RISK
open ↗Exploit-DB
Mac OS X - libxpc MITM Privilege Escalation (Metasploit)
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
43RISK
open ↗Exploit-DB
PHP imap_open - Remote Code Execution (Metasploit)
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh c
60RISK
open ↗Exploit-DB
Linux - Nested User Namespace idmap Limit Local Privilege Escalation (Metasploit)
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISK
open ↗Exploit-DB
Netgear Devices - (Unauthenticated) Remote Command Execution (Metasploit)
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear
100RISK
open ↗Exploit-DB
Xorg X11 Server - SUID privilege escalation (Metasploit)
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RISK
open ↗Exploit-DB
Ticketly 1.0 - 'kind_id' SQL Injection
AbiSoft Ticketly 1.0 is affected by multiple SQL Injection vulnerabilities through the parameters name, category_id and
23RISK
open ↗Exploit-DB
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (ldpreload Method)
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISK
open ↗Exploit-DB
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (cron Method)
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISK
open ↗Exploit-DB
Microsoft Windows - DfMarshal Unsafe Unmarshaling Privilege Escalation
An elevation of privilege exists in Windows COM Aggregate Marshaler, aka "Windows COM Elevation of Privilege Vulnerabili
23RISK
open ↗Exploit-DB
ImageMagick - Memory Leak
ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that ha
35RISK
open ↗Exploit-DB
DomainMOD 4.11.01 - 'raid' Cross-Site Scripting
DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter.
38RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.