Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,457cataloged exploits
36,589CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,152GitHub PoC 15,098VulnCheck XDB 8,883Nuclei 4,365Metasploit 3,493✓ verified onlyrecentpopularrisk
79,305 exploits
Metasploit600
Liferay Portal Java Unmarshalling via JSONWS RCE
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open ↗Metasploit300
QNAP QTS and Photo Station Local File Inclusion
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fi
100RISK
open ↗Metasploit300
QNAP QTS and Photo Station Local File Inclusion
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fi
100RISK
open ↗VulnCheck XDB
denial-of-service
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RISK
open ↗VulnCheck XDB
local
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open ↗VulnCheck XDB
initial-access
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open ↗VulnCheck XDB
client-side
Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploi
90RISK
open ↗GitHub PoC
crispy-peppers/Libssh-server-CVE-2018-10933
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open ↗GitHub PoC
crispy-peppers/Goahead-CVE-2017-17562
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RISK
open ↗VulnCheck XDB
initial-access
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RISK
open ↗GitHub PoC★ 7
timwr/CVE-2019-5825
Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploi
90RISK
open ↗Exploit-DB✓ VexDay Proof
Internet Explorer - Use-After-Free in JScript Arguments During toJSON Callback
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RISK
open ↗GitHub PoC★ 8
A quick python exploit for the Nostromo 1.9.6 remote code execution vulnerability. Simply takes a host and port that the web server is running on.
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open ↗VulnCheck XDB
initial-access
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open ↗GitHub PoC★ 1
ulisesrc/-2-CVE-2019-0708
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open ↗VulnCheck XDB
initial-access
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open ↗GitHub PoC★ 193
CVE-2019-1388 UAC提权 (nt authority\system)
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user
71RISK
open ↗GitHub PoC
am6539/CVE-2019-3396
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open ↗GitHub PoC
jaychouzzk/CVE-2019-1388
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user
71RISK
open ↗GitHub PoC★ 20
CVE-2019-0232-Remote Code Execution on Apache Tomcat 7.0.42
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open ↗VulnCheck XDB
initial-access
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open ↗Exploit-DB
GNU Mailutils 3.7 - Privilege Escalation
maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ubuntu 19.10 - Refcount Underflow and Type Confusion in shiftfs
Mishandling of file-system uid/gid with namespaces in shiftfs
33RISK
open ↗Exploit-DB✓ VexDay Proof
Ubuntu 19.10 - Refcount Underflow and Type Confusion in shiftfs
Reference count underflow in shiftfs
41RISK
open ↗Exploit-DB✓ VexDay Proof
Ubuntu 19.10 - ubuntu-aufs-modified mmap_region() Breaks Refcounting in overlayfs/shiftfs Error Path
Reference counting error in overlayfs/shiftfs error path when used in conjuction with aufs
41RISK
open ↗Exploit-DB✓ VexDay Proof
Bludit - Directory Traversal Image File Upload (Metasploit)
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISK
open ↗Exploit-DB✓ VexDay Proof
Ubuntu 19.10 - Refcount Underflow and Type Confusion in shiftfs
Type confusion in shiftfs
41RISK
open ↗GitHub PoC★ 1
l-iberty/cve-2012-1889
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attacker
100RISK
open ↗Exploit-DB✓ VexDay Proof
Xorg X11 Server - Local Privilege Escalation (Metasploit)
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RISK
open ↗Exploit-DB✓ VexDay Proof
Pulse Secure VPN - Arbitrary Command Execution (Metasploit)
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.