Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,760cataloged exploits
32,083CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,934GitHub PoC 13,235VulnCheck XDB 8,150Nuclei 4,193Metasploit 3,462✓ verified onlyrecentpopularrisk
22,786 exploits
Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RISK
open ↗Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RISK
open ↗Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RISK
open ↗Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require ad
23RISK
open ↗Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RISK
open ↗Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RISK
open ↗Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:4
23RISK
open ↗Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in integration-contact
23RISK
open ↗Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RISK
open ↗Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RISK
open ↗Exploit-DB
Solaris - libnspr NSPR_LOG_FILE Privilege Escalation (Metasploit)
The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment v
38RISK
open ↗Exploit-DB
CA Release Automation NiMi 6.5 - Remote Command Execution
Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows atta
28RISK
open ↗Exploit-DB
Joomla! Component JCK Editor 6.4.4 - 'parent' SQL Injection
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
60RISK
open ↗Exploit-DB
Watchguard AP100 AP102 AP200 1.2.9.15 - Remote Code Execution (Metasploit)
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Improper authentica
23RISK
open ↗Exploit-DB
Watchguard AP100 AP102 AP200 1.2.9.15 - Remote Code Execution (Metasploit)
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices w
23RISK
open ↗Exploit-DB
Watchguard AP100 AP102 AP200 1.2.9.15 - Remote Code Execution (Metasploit)
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentia
23RISK
open ↗Exploit-DB
Apache Syncope 2.0.7 - Remote Code Execution
An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupporte
28RISK
open ↗Exploit-DB
Apache Portals Pluto 3.0.0 - Remote Code Execution
The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote a
35RISK
open ↗Exploit-DB
Apache Syncope 2.0.7 - Remote Code Execution
An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and un
28RISK
open ↗Exploit-DB
CirCarLife SCADA 4.3.0 - Credential Disclosure
CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/lo
50RISK
open ↗Exploit-DB
MyBB 1.8.17 - Cross-Site Scripting
An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can gener
23RISK
open ↗Exploit-DB
LG Smart IP Camera 1508190 - Backup File Download
LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /u
23RISK
open ↗Exploit-DB
Rubedo CMS 3.4.0 - Directory Traversal
Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attac
50RISK
open ↗Exploit-DB
IBM Identity Governance and Intelligence 5.2.3.2 / 5.2.4 - SQL Injection
IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 is vulnerable to SQL injection. A remote attacker co
46RISK
open ↗Exploit-DB
SynaMan 4.0 build 1488 - (Authenticated) Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Synametrics SynaMan 4.0 build 1488 via the (1) Main heading or (2
23RISK
open ↗Exploit-DB
Apple macOS 10.13.4 - Denial of Service (PoC)
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
23RISK
open ↗Exploit-DB
SynaMan 4.0 build 1488 - SMTP Credential Disclosure
Synametrics SynaMan 4.0 build 1488 uses cleartext password storage for SMTP credentials.
23RISK
open ↗Exploit-DB
Apache Struts 2 - Namespace Redirect OGNL Injection (Metasploit)
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open ↗Exploit-DB
Ghostscript - Failed Restore Command Execution (Metasploit)
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RISK
open ↗Exploit-DB
QNAP Photo Station 5.7.0 - Cross-Site Scripting
Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inje
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.