Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,900cataloged exploits
36,847CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,475Referência 23,360GitHub PoC 15,228VulnCheck XDB 8,946Nuclei 4,390Metasploit 3,501✓ verified onlyrecentpopularrisk
24,475 exploits
Exploit-DB✓ VexDay Proof
Linux Kernel - UDP Fragmentation Offset 'UFO' Privilege Escalation (Metasploit)
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE
43RISK
open ↗Exploit-DB
Universal Media Server 7.1.0 - SSDP Processing XML External Entity Injection
In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML Extern
28RISK
open ↗Exploit-DB
Sun Solaris 11.3 AVS Kernel - Local Privilege Escalation
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Availability Suite Service).
23RISK
open ↗Exploit-DB
WityCMS 0.6.2 - Cross-Site Request Forgery (Password Change)
CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an attacker to take over a user account, as dem
23RISK
open ↗Exploit-DB
Seq 4.2.476 - Authentication Bypass
Datalust Seq before 4.2.605 is vulnerable to Authentication Bypass (with the attacker obtaining admin access) via '"Name
35RISK
open ↗Exploit-DB
Craft CMS SEOmatic plugin 3.1.4 - Server-Side Template Injection
A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because reques
35RISK
open ↗Exploit-DB
Responsive Filemanager 9.13.1 - Server-Side Request Forgery
upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.
60RISK
open ↗Exploit-DB
H2 Database 1.4.197 - Information Disclosure
An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read
38RISK
open ↗Exploit-DB
Charles Proxy 4.2 - Local Privilege Escalation
Race condition in the Charles Proxy Settings suid binary in Charles Proxy before 4.2.1 allows local users to gain privil
23RISK
open ↗Exploit-DB✓ VexDay Proof
fusermount - user_allow_other Restriction Bypass and SELinux Label Control
In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is act
33RISK
open ↗Exploit-DB✓ VexDay Proof
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
60RISK
open ↗Exploit-DB✓ VexDay Proof
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
60RISK
open ↗Exploit-DB✓ VexDay Proof
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
60RISK
open ↗Exploit-DB✓ VexDay Proof
Skia - Heap Overflow in SkScan::FillPath due to Precision Error
A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds m
23RISK
open ↗Exploit-DB✓ VexDay Proof
SoftNAS Cloud < 4.0.3 - OS Command Injection
A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particul
45RISK
open ↗Exploit-DB
Online Trade 1 - Information Disclosure
Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensiti
28RISK
open ↗Exploit-DB
Trivum Multiroom Setup Tool 8.76 - Corss-Site Request Forgery (Admin Bypass)
MusicCenter / Trivum Multiroom Setup Tool V8.76 - SNR 8604.26 - C4 Professional before V9.34 build 13381 - 12.07.18, all
28RISK
open ↗Exploit-DB
GetGo Download Manager 6.2.1.3200 - Denial of Service (PoC)
A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to exec
28RISK
open ↗Exploit-DB
Nagios Core 4.4.1 - Denial of Service
qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to
23RISK
open ↗Exploit-DB
Micro Focus Secure Messaging Gateway (SMG) < 471 - Remote Code Execution (Metasploit)
Unauthenticated SQL injection in Micro Focus Secure Messaging Gateway
85RISK
open ↗Exploit-DB
Nagios Core 4.4.1 - Denial of Service
qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows atta
23RISK
open ↗Exploit-DB
Nagios Core 4.4.1 - Denial of Service
qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to
23RISK
open ↗Exploit-DB
Micro Focus Secure Messaging Gateway (SMG) < 471 - Remote Code Execution (Metasploit)
Remote Code Execution in Micro Focus Secure Messaging Gateway
85RISK
open ↗Exploit-DB
Tenda Wireless N150 Router 5.07.50 - Cross-Site Request Forgery (Reboot Router)
Cross-site request forgery (CSRF) vulnerability on Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 allo
23RISK
open ↗Exploit-DB
Davolink DVW 3200 Router - Password Disclosure
Davolink DVW-3200N all version prior to Version 1.00.06. The device generates a weak password hash that is easily cracke
28RISK
open ↗Exploit-DB
Inteno’s IOPSYS - (Authenticated) Local Privilege Escalation
read_tmp and write_tmp in Inteno IOPSYS allow attackers to gain privileges after writing to /tmp/etc/smb.conf because /v
23RISK
open ↗Exploit-DB
MSVOD 10 - 'cid' SQL Injection
In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.
23RISK
open ↗Exploit-DB
TP-Link TL-WR840N - Denial of Service
TP-Link WR840N devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets w
23RISK
open ↗Exploit-DB
Touchpad / Trivum WebTouch Setup 2.53 build 13163 - Authentication Bypass
Touchpad / Trivum WebTouch Setup V9 V2.53 build 13163 of Apr 6 2018 09:10:14 (FW 303) allow unauthorized remote attacker
35RISK
open ↗Exploit-DB
WordPress Plugin All In One Favicon 4.6 - (Authenticated) Cross-Site Scripting
Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plu
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.