Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,459Referência 22,721GitHub PoC 14,946VulnCheck XDB 8,829Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
24,695 exploits
Exploit-DB✓ VexDay Proof
October CMS - Upload Protection Bypass Code Execution (Metasploit)
October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise
50RISK
open ↗Exploit-DB✓ VexDay Proof
AwindInc SNMP Service - Command Injection (Metasploit)
Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote
60RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco UCS Director - default scpuser password (Metasploit)
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data SCP User Default Credentials Vulnerability
85RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco Data Center Network Manager - Unauthenticated Remote Code Execution (Metasploit)
Cisco Data Center Network Manager Authentication Bypass Vulnerability
85RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco RV110W/RV130(W)/RV215W Routers Management Interface - Remote Command Execution (Metasploit)
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco Data Center Network Manager - Unauthenticated Remote Code Execution (Metasploit)
Cisco Data Center Network Manager Information Disclosure Vulnerability
70RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco Data Center Network Manager - Unauthenticated Remote Code Execution (Metasploit)
Cisco Data Center Network Manager Arbitrary File Upload and Remote Code Execution Vulnerability
85RISK
open ↗Exploit-DB✓ VexDay Proof
ktsuss 1.4 - suid Privilege Escalation (Metasploit)
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified com
60RISK
open ↗Exploit-DB✓ VexDay Proof
Webkit JSC: JIT - Uninitialized Variable Access in ArgumentsEliminationPhase::transform
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS M
28RISK
open ↗Exploit-DB✓ VexDay Proof
Tableau - XML External Entity
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to informat
46RISK
open ↗Exploit-DB✓ VexDay Proof
Exim 4.87 / 4.91 - Local Privilege Escalation (Metasploit)
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 10 - SET_REPARSE_POINT_EX Mount Point Security Feature Bypass
Windows NTFS Elevation of Privilege Vulnerability
41RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Font Subsetting - DLL Heap Corruption in ReadAllocFormat12CharGlyphMapList
Microsoft Graphics Remote Code Execution Vulnerability
46RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Memory Corruption due to Malformed TTF Font
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Font Subsetting - DLL Heap-Based Out-of-Bounds read in WriteTableFromStructure
Microsoft Graphics Remote Code Execution Vulnerability
46RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat CoolType (AFDKO) - Memory Corruption in the Handling of Type 1 Font load/store Operators
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Font Subsetting - DLL Returning a Dangling Pointer via MergeFontPackage
Microsoft Graphics Remote Code Execution Vulnerability
46RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Font Subsetting - DLL Double Free in MergeFormat12Cmap / MakeFormat12MergedGlyphList
Microsoft Graphics Remote Code Execution Vulnerability
46RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Font Subsetting - DLL Heap Corruption in ReadTableIntoStructure
Microsoft Graphics Remote Code Execution Vulnerability
46RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader DC for Windows - Static Buffer Overflow due to Malformed Font Stream
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Font Subsetting - DLL Heap-Based Out-of-Bounds read in FixSbitSubTableFormat1
Microsoft Graphics Component Information Disclosure Vulnerability
33RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Font Subsetting - DLL Heap Corruption in MakeFormat12MergedGlyphList
Microsoft Graphics Remote Code Execution Vulnerability
46RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader DC for Windows - Double Free due to Malformed JP2 Stream
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISK
open ↗Exploit-DB✓ VexDay Proof
NSKeyedUnarchiver - Info Leak in Decoding SGBigUTF8String
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6. A remote attacker
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Font Subsetting - DLL Heap Corruption in FixSbitSubTables
Microsoft Graphics Remote Code Execution Vulnerability
46RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow While Processing Malformed PDF
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
35RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader DC for Windows - free() of Uninitialized Pointer due to Malformed JBIG2Globals Stream
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Font Subsetting - DLL Heap-Based Out-of-Bounds read in GetGlyphIdx
Microsoft Graphics Component Information Disclosure Vulnerability
33RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow due to Malformed Font Stream
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat CoolType (AFDKO) - Call from Uninitialized Memory due to Empty FDArray in Type 1 Fonts
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.