Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,967GitHub PoC 13,264VulnCheck XDB 8,156Nuclei 4,201Metasploit 3,462✓ verified onlyrecentpopularrisk
22,786 exploits
Exploit-DB
Ncomputing vSpace Pro 10/11 - Directory Traversal
An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11. It is possible t
50RISK
open ↗Exploit-DB
Monstra cms 3.0.4 - Persitent Cross-Site Scripting
Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload
23RISK
open ↗Exploit-DB
Drupal avatar_uploader v7.x-1.0-beta8 - Arbitrary File Disclosure
Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.
50RISK
open ↗Exploit-DB
PRTG Network Monitor < 18.1.39.1648 - Stack Overflow (Denial of Service)
Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.
23RISK
open ↗Exploit-DB
Oracle Weblogic Server 10.3.6.0 / 12.1.3.0 / 12.2.1.2 / 12.2.1.3 - Deserialization Remote Command Execution
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open ↗Exploit-DB
Cobub Razor 0.8.0 - Physical Path Leakage
Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, contro
50RISK
open ↗Exploit-DB
Cobub Razor 0.8.0 - Physical Path Leakage
Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via an invalid channel_name parameter to /index.php?/ma
28RISK
open ↗Exploit-DB
Geist WatchDog Console 3.2.2 - Multiple Vulnerabilities
XML external entity (XXE) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to re
23RISK
open ↗Exploit-DB
Match Clone Script 1.0.4 - Cross-Site Scripting
PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to searchbyid.php (aka the "View Search By Id" sc
23RISK
open ↗Exploit-DB
Kodi 17.6 - Persistent Cross-Site Scripting
A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/s
35RISK
open ↗Exploit-DB
Geist WatchDog Console 3.2.2 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to i
23RISK
open ↗Exploit-DB
WordPress Plugin Caldera Forms 1.5.9.1 - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow re
23RISK
open ↗Exploit-DB
Easy File Sharing Web Server 7.2 - Stack Buffer Overflow
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code
60RISK
open ↗Exploit-DB
Lutron Quantum 2.0 - 3.2.243 - Information Disclosure
Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) doesn't check for correct user authentication before showing th
28RISK
open ↗Exploit-DB
Brave Browser < 0.13.0 - 'window.close(self)' Denial of Service
Brave Browser before 0.13.0 allows a tab to close itself even if the tab was not opened by a script, resulting in denial
28RISK
open ↗Exploit-DB
Ultra MiniHTTPd 1.2 - 'GET' Remote Stack Buffer Overflow (PoC)
Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resour
50RISK
open ↗Exploit-DB
Joomla! Component jDownloads 3.2.58 - Cross Site Scripting
The jDownloads extension before 3.2.59 for Joomla! has XSS.
23RISK
open ↗Exploit-DB
Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (Metasploit)
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open ↗Exploit-DB
D-Link DIR-615 Wireless Router - Persistent Cross Site Scripting
D-Link DIR-615 T1 devices allow XSS via the Add User feature.
23RISK
open ↗Exploit-DB
Brave Browser < 0.13.0 - 'long alert() argument' Denial of Service
Brave Browser before 0.13.0 allows remote attackers to cause a denial of service (resource consumption) via a long alert
23RISK
open ↗Exploit-DB
CloudMe Sync 1.11.0 - Local Buffer Overflow
An issue was discovered in CloudMe 1.11.0. An unauthenticated local attacker that can connect to the "CloudMe Sync" clie
23RISK
open ↗Exploit-DB
Microsoft Windows - 'nt!NtQueryFullAttributesFile' Kernel Stack Memory Disclosure
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open ↗Exploit-DB
Microsoft Windows - 'CiSetFileCache' TOCTOU Incomplete Fix
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security F
23RISK
open ↗Exploit-DB
Microsoft Windows - 'nt!NtQueryVirtualMemory (MemoryImageInformation)' Kernel 64-bit Stack Memory Disclosure
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open ↗Exploit-DB
Microsoft Windows - 'nt!NtQueryVirtualMemory (Memory(Privileged)BasicInformation)' Kernel 64-bit Stack Memory Disclosure
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open ↗Exploit-DB
Microsoft Windows - 'nt!NtQueryInformationTransactionManager (TransactionManagerRecoveryInformation)' Kernel Pool Memory Disclosure
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open ↗Exploit-DB
Microsoft Windows - 'nt!NtQuerySystemInformation (SystemPageFileInformation(Ex))' Kernel 64-bit Stack Memory Disclosure
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open ↗Exploit-DB
Microsoft Windows - 'nt!NtQueryInformationProcess (ProcessImageFileName)' Kernel 64-bit Pool/Stack Memory Disclosure
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open ↗Exploit-DB
Cobub Razor 0.8.0 - SQL injection
A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a
28RISK
open ↗Exploit-DB
Microsoft Windows - 'nt!NtQueryAttributesFile' Kernel Stack Memory Disclosure
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.