Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,967GitHub PoC 13,264VulnCheck XDB 8,156Nuclei 4,201Metasploit 3,462✓ verified onlyrecentpopularrisk
22,786 exploits
Exploit-DB
FTPShell Client 6.7 - Buffer Overflow
An issue was discovered in FTPShell Client 6.7. A remote FTP server can send 400 characters of 'F' in conjunction with t
50RISK
open ↗Exploit-DB
PlaySMS - 'import.php' (Authenticated) CSV File Upload Code Execution (Metasploit)
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RISK
open ↗Exploit-DB
2345 Security Guard 3.7 - '2345NetFirewall.sys' Denial of Service
In 2345 Security Guard 3.7, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD)
23RISK
open ↗Exploit-DB
Palo Alto Networks - 'readSessionVarsFromFile()' Session Corruption (Metasploit)
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RISK
open ↗Exploit-DB
GNU wget - Cookie Injection
GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequen
28RISK
open ↗Exploit-DB
CSP MySQL User Manager 2.3.1 - Authentication Bypass
CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a
23RISK
open ↗Exploit-DB
DeviceLock Plug and Play Auditor 5.72 - Unicode Buffer Overflow (SEH)
DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH).
28RISK
open ↗Exploit-DB
IceWarp Mail Server < 11.1.1 - Directory Traversal
Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary
50RISK
open ↗Exploit-DB
WordPress Plugin WF Cookie Consent 1.1.3 - Cross-Site Scripting
An issue was discovered in the wunderfarm WF Cookie Consent plugin 1.1.3 for WordPress. A persistent cross-site scriptin
23RISK
open ↗Exploit-DB
Google Chrome V8 - Object Allocation Size Integer Overflow
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch
83RISK
open ↗Exploit-DB
Microsoft Windows WMI - Recieve Notification Exploit (Metasploit)
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to g
91RISK
open ↗Exploit-DB
GPON Routers - Authentication Bypass / Command Injection
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RISK
open ↗Exploit-DB
GPON Routers - Authentication Bypass / Command Injection
An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images
100RISK
open ↗Exploit-DB
JasperReports - (Authenticated) File Read
TIBCO JasperReports Server Information Disclosure Vulnerability
83RISK
open ↗Exploit-DB
Cockpit CMS 0.4.4 < 0.5.5 - Server-Side Request Forgery
SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to r
23RISK
open ↗Exploit-DB
Exim < 4.90.1 - 'base64d' Remote Code Execution
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISK
open ↗Exploit-DB
LibreOffice/Open Office - '.odt' Information Disclosure
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically p
60RISK
open ↗Exploit-DB
TBK DVR4104 / DVR4216 - Credentials Leak
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open ↗Exploit-DB
Norton Core Secure WiFi Router - 'BLE' Command Injection (PoC)
The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in whic
28RISK
open ↗Exploit-DB
WebKit - 'WebCore::jsElementScrollHeightGetter' Use-After-Free
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud
23RISK
open ↗Exploit-DB
WordPress Plugin Responsive Cookie Consent 1.7 / 1.6 / 1.5 - (Authenticated) Persistent Cross-Site Scripting
The Responsive Cookie Consent plugin before 1.8 for WordPress mishandles number fields, leading to XSS.
23RISK
open ↗Exploit-DB
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an
43RISK
open ↗Exploit-DB
Apple macOS/iOS - ReportCrash mach port Replacement due to Failure to Respect MIG Ownership Rules
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2
23RISK
open ↗Exploit-DB
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execut
50RISK
open ↗Exploit-DB
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RC
50RISK
open ↗Exploit-DB
Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code (Metasploit)
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RISK
open ↗Exploit-DB
WordPress Plugin Form Maker 1.12.20 - CSV Injection
The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.
23RISK
open ↗Exploit-DB
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker
50RISK
open ↗Exploit-DB
Apple macOS 10.13.2 - Double mach_port_deallocate in kextd due to Failure to Comply with MIG Ownership Rules
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "kext tools"
23RISK
open ↗Exploit-DB
SickRage < v2018.03.09 - Clear-Text Credentials HTTP Response
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
60RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.