Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,104GitHub PoC 15,075VulnCheck XDB 8,883Nuclei 4,365Metasploit 3,493✓ verified onlyrecentpopularrisk
79,305 exploits
Exploit-DB
Cups Easy 1.0 - Cross Site Request Forgery (Password Reset)
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php.
23RISK
open ↗Exploit-DB
Cups Easy 1.0 - Cross Site Request Forgery (Password Reset)
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php
23RISK
open ↗GitHub PoC★ 1
Python CVE-2019-19781 exploit
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open ↗GitHub PoC★ 73
PoC script that shows RCE vulnerability over Intellian Satellite controller
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to th
60RISK
open ↗GitHub PoC★ 20
PoC for CVE-2020-0601 - CryptoAPI exploit
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open ↗Exploit-DB✓ VexDay Proof
Adive Framework 2.0.8 - Cross-Site Request Forgery (Change Admin Password)
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
23RISK
open ↗GitHub PoC★ 1
*CVE-2014-6271* Unix Arbitrary Code Execution Exploit commonly know as Shell Shock. Examples, Docs, Incident Response and Vulnerability/Risk Assessment, and Additional Resources may be dumped here. Enjoy :) --- somhmxxghoul ---
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗VulnCheck XDB
client-side
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open ↗VulnCheck XDB
initial-access
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to th
60RISK
open ↗Exploit-DB
Octeth Oempro 4.8 - 'CampaignID' SQL Injection
Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable.
23RISK
open ↗Metasploit600
OpenSMTPD MAIL FROM Remote Code Execution
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open ↗Exploit-DB
Microsoft Windows Kernel - Information Disclosure
Windows Kernel Information Disclosure Vulnerability
33RISK
open ↗Metasploit600
Centreon Poller Authenticated Remote Command Execution
There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers mi
23RISK
open ↗GitHub PoC★ 41
This repository contains the sources and documentation for the SWAPGS attack PoC (CVE-2019-1125)
Windows Kernel Information Disclosure Vulnerability
33RISK
open ↗GitHub PoC
PoC for "CurveBall" CVE-2020-0601
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open ↗VulnCheck XDB
initial-access
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open ↗GitHub PoC★ 2
Archi73ct/CVE-2020-0609
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RISK
open ↗GitHub PoC
Citrix ADC (NetScaler) Honeypot. Supports detection for CVE-2019-19781 and login attempts
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open ↗GitHub PoC★ 68
A proof-of-concept scanner to check an RDG Gateway Server for vulnerabilities CVE-2020-0609 & CVE-2020-0610.
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RISK
open ↗Exploit-DB
TP-Link TP-SG105E 1.0.0 - Unauthenticated Remote Reboot
The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the
35RISK
open ↗GitHub PoC★ 78
PoC for the Remote Desktop Gateway vulnerability - CVE-2020-0609 & CVE-2020-0610
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RISK
open ↗Exploit-DB
Genexis Platinum-4410 2.1 - Authentication Bypass
An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cl
23RISK
open ↗Exploit-DB
qdPM 9.1 - Remote Code Execution
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISK
open ↗Exploit-DB
Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC)
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
35RISK
open ↗GitHub PoC★ 1
CVE-2020-0601: Windows CryptoAPI Vulnerability. (CurveBall/ChainOfFools)
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open ↗Exploit-DB
Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC)
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RISK
open ↗GitHub PoC
:microscope: Jupyter notebook to help automate some of the forensic analysis related to Citrix Netscalers compromised via CVE-2019-19781
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open ↗Exploit-DB
Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC)
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RISK
open ↗GitHub PoC
a script to look for CVE-2019-19781 Vulnerability within a domain and it's subdomains
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open ↗GitHub PoC★ 249
PoC (DoS + scanner) for CVE-2020-0609 & CVE-2020-0610 - RD Gateway RCE
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.