Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
79,210 exploits
GitHub PoC★ 108
Salt security backports for CVE-2020-11651 & CVE-2020-11652
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open ↗Metasploit300
SaltStack Salt Master Server Root Key Disclosure
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open ↗Metasploit500
SaltStack Salt Master/Minion Unauthenticated RCE
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open ↗Metasploit500
SaltStack Salt Master/Minion Unauthenticated RCE
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open ↗Metasploit300
SaltStack Salt Master Server Root Key Disclosure
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open ↗Metasploit300
WebLogic Server Deserialization RCE BadAttributeValueExpException ExtComp
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISK
open ↗VulnCheck XDB
initial-access
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open ↗VulnCheck XDB
client-side
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open ↗Metasploit300
Wordpress LearnPress current_items Authenticated SQLi
LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection
50RISK
open ↗VulnCheck XDB
initial-access
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open ↗Metasploit600
TP-Link Cloud Cameras NCXXX Bonjour Command Injection
Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220
40RISK
open ↗Exploit-DB✓ VexDay Proof
Druva inSync Windows Client 6.5.2 - Local Privilege Escalation
Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, u
38RISK
open ↗GitHub PoC★ 1
yukar1z0e/CVE-2018-14847
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open ↗Exploit-DB✓ VexDay Proof
Docker-Credential-Wincred.exe - Privilege Escalation (Metasploit)
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-c
98RISK
open ↗Metasploit600
Netsweeper WebAdmin unixlogin.php Python Code Injection
Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain
40RISK
open ↗Metasploit600
GOG GalaxyClientService Privilege Escalation
GOG Galaxy GalaxyClientService Privilege Escalation
36RISK
open ↗Metasploit600
TrixBox CE endpoint_devicemap.php Authenticated Command Execution
Fonality Trixbox CE Post-Authentication Command Injection
48RISK
open ↗Metasploit400
WordPress Simple File List Unauthenticated Remote Code Execution
Simple File List < 4.2.3 - Remote Code Execution
75RISK
open ↗Exploit-DB
Source Engine CS:GO BuildID: 4937372 - Arbitrary Code Execution
Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in
23RISK
open ↗GitHub PoC★ 102
Hikvision camera CVE-2017-7921-EXP
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open ↗GitHub PoC★ 1
wcxxxxx/CVE-2020-7961
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open ↗GitHub PoC
CVE-2018-15133 (Webased)
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open ↗VulnCheck XDB
initial-access
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open ↗VulnCheck XDB
client-side
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open ↗GitHub PoC
Sudo Vulnerability CVE-2019-14287
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open ↗GitHub PoC★ 2
WordPress CVE-2017-5487 Exploit in Python
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RISK
open ↗GitHub PoC★ 7
android-kernel-exploitation-ashfaq-CVE-2019-2215 docker setup for mac users
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open ↗GitHub PoC
JJSO12/Apache-Pluto-3.0.0--CVE-2018-1306
The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote a
35RISK
open ↗VulnCheck XDB
local
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open ↗GitHub PoC
section-c/CVE-2020-0796
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.