Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,051GitHub PoC 15,051VulnCheck XDB 8,883Nuclei 4,361Metasploit 3,493✓ verified onlyrecentpopularrisk
79,305 exploits
GitHub PoC
exploit for DNS 4.3
Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before
28RISK
open ↗GitHub PoC★ 2
An Python Exploit for Sudo vulnerability CVE-2019-18634
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISK
open ↗Exploit-DB✓ VexDay Proof
HP System Event Utility - Local Privilege Escalation
A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version
23RISK
open ↗VulnCheck XDB
remote-with-credentials
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open ↗GitHub PoC
PoC for CVE-2020-0601 vulnerability (Code Signing)
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open ↗GitHub PoC★ 3
PostgreSQL Remote Code Executuon
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open ↗GitHub PoC
N0b1e6/CVE-2018-1335-Python3
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISK
open ↗Metasploit600
Exchange Control Panel ViewState Deserialization
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open ↗Metasploit600
SQL Server Reporting Services (SSRS) ViewState Deserialization
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RISK
open ↗Exploit-DB✓ VexDay Proof
OpenSMTPD 6.4.0 < 6.6.1 - Local Privilege Escalation + Remote Code Execution
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open ↗Metasploit600
Service Tracing Privilege Elevation Vulnerability
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Window
23RISK
open ↗Exploit-DB
Vanilla Forums 2.6.3 - Persistent Cross-Site Scripting
index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.
23RISK
open ↗GitHub PoC★ 336
CVE-2020-0683 - Windows MSI “Installer service” Elevation of Privilege
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'W
71RISK
open ↗VulnCheck XDB
initial-access
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISK
open ↗Exploit-DB
CHIYU BF430 TCP IP Converter - Stored Cross-Site Scripting
Stored XSS was discovered on CHIYU BF-430 232/485 TCP/IP Converter devices before 1.16.00, as demonstrated by the /if.cg
23RISK
open ↗VulnCheck XDB
local
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'W
71RISK
open ↗GitHub PoC
https://github.com/awakened1712/CVE-2019-11932
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open ↗Exploit-DB
Dota 2 7.23f - Denial of Service (PoC)
schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ricoh Driver - Privilege Escalation (Metasploit)
An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attacker
38RISK
open ↗Metasploit600
Unraid 6.8.0 Auth Bypass PHP Code Execution
Unraid 6.8.0 allows authentication bypass.
100RISK
open ↗Exploit-DB
Forcepoint WebSecurity 8.5 - Reflective Cross-Site Scripting
It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host heade
23RISK
open ↗Exploit-DB✓ VexDay Proof
OpenSMTPD - MAIL FROM Remote Code Execution (Metasploit)
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open ↗Metasploit600
Unraid 6.8.0 Auth Bypass PHP Code Execution
Unraid through 6.8.0 allows Remote Code Execution.
100RISK
open ↗Exploit-DB✓ VexDay Proof
iOS/macOS - Out-of-Bounds Timestamp Write in IOAccelCommandQueue2::processSegmentKernelCommand()
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3
76RISK
open ↗GitHub PoC★ 3
VanillaForum 2.6.3 allows stored XSS.
index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.
23RISK
open ↗Exploit-DB✓ VexDay Proof
D-Link Devices - Unauthenticated Remote Command Execution in ssdpcgi (Metasploit)
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the
60RISK
open ↗Exploit-DB
WordPress Plugin LearnDash LMS 3.1.2 - Reflective Cross-Site Scripting
The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field.
23RISK
open ↗GitHub PoC★ 7
Containerized and deployable use of the CVE-2019-14287 vuln. View README.md for more.
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open ↗GitHub PoC★ 1
Exhaust WordPress <V5.0.1 resources using long passwords (CVE-2014-9016)
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x
60RISK
open ↗Exploit-DB✓ VexDay Proof
Windscribe - WindscribeService Named Pipe Privilege Escalation (Metasploit)
The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe s
38RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.