Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,596cataloged exploits
36,656CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,475Referência 23,212GitHub PoC 15,164VulnCheck XDB 8,883Nuclei 4,369Metasploit 3,493✓ verified onlyrecentpopularrisk
79,305 exploits
VulnCheck XDB
initial-access
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RISK
open ↗VulnCheck XDB
initial-access
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open ↗GitHub PoC
leonardo1101/cve-2017-11176
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RISK
open ↗GitHub PoC
ictnamanh/CVE-2017-9248
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RISK
open ↗Exploit-DB
Rocket.Chat 2.1.0 - Cross-Site Scripting
Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line.
23RISK
open ↗GitHub PoC★ 1
CVE-2019-16278 Python3 Exploit Code
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open ↗Exploit-DB
Moxa EDR-810 - Command Injection / Information Disclosure
Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from
23RISK
open ↗Exploit-DB
Moxa EDR-810 - Command Injection / Information Disclosure
Moxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature to execute unauthor
28RISK
open ↗VulnCheck XDB
local
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open ↗Exploit-DB✓ VexDay Proof
Total.js CMS 12 - Widget JavaScript Code Injection (Metasploit)
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote
60RISK
open ↗GitHub PoC★ 9
脏牛Linux本地提权漏洞复现(CVE-2016-5195)
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow due to Malformed JP2 Stream (2)
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RISK
open ↗GitHub PoC★ 167
exploit CVE-2019-7609(kibana RCE) on right way by python2 scripts
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open ↗GitHub PoC★ 56
RCE on Kibana versions before 5.6.15 and 6.6.0 in the Timelion visualizer
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open ↗Exploit-DB
Solaris 11.4 - xscreensaver Privilege Escalation
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is a
91RISK
open ↗Exploit-DB✓ VexDay Proof
Trend Micro Anti-Threat Toolkit 1.62.0.1218 - Remote Code Execution
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to
28RISK
open ↗GitHub PoC★ 5
Instructions for installing a vulnerable version of Exim and its expluatation
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open ↗VulnCheck XDB
initial-access
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before
60RISK
open ↗VulnCheck XDB
local
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open ↗VulnCheck XDB
local
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open ↗VulnCheck XDB
initial-access
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open ↗VulnCheck XDB
remote-with-credentials
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open ↗VulnCheck XDB
infoleak
There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12
43RISK
open ↗GitHub PoC★ 5
RCE Exploit For CVE-2019-17424 (nipper-ng 0.11.10)
A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows re
28RISK
open ↗Metasploit400
Nostromo Directory Traversal Remote Command Execution
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open ↗VulnCheck XDB
initial-access
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.