Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,900cataloged exploits
36,847CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,475Referência 23,360GitHub PoC 15,228VulnCheck XDB 8,946Nuclei 4,390Metasploit 3,501✓ verified onlyrecentpopularrisk
24,475 exploits
Exploit-DB
WUZHI CMS 4.1.0 - 'form[qq_10]' Cross-Site Scripting
WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 2003 SP2 - 'RRAS' SMB Remote Code Execution
Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold,
35RISK
open ↗Exploit-DB
Open-AudIT Community 2.2.0 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Open-AudIT Community 2.2.0 allows remote attackers to inject arbitrary web s
23RISK
open ↗Exploit-DB
2345 Security Guard 3.7 - '2345BdPcSafe.sys' Denial of Service
In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of serv
23RISK
open ↗Exploit-DB
Open-AudIT Professional - 2.1.1 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary we
23RISK
open ↗Exploit-DB
EMC RecoverPoint 4.3 - 'Admin CLI' Command Injection
An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0
23RISK
open ↗Exploit-DB
MyBB Latest Posts on Profile Plugin 1.1 - Cross-Site Scripting
The "Latest Posts on Profile" plugin 1.1 for MyBB has XSS because there is an added section in a user profile that displ
23RISK
open ↗Exploit-DB
Dell Touchpad - 'ApMsgFwd.exe' Denial of Service
An issue was discovered in Alps Pointing-device Driver 10.1.101.207. ApMsgFwd.exe allows the current user to map and wri
23RISK
open ↗Exploit-DB
ModbusPal 1.6b - XML External Entity Injection
ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations c
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mantis Bug Tracker 1.1.3 - 'manage_proj_page' PHP Code Execution (Metasploit)
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RISK
open ↗Exploit-DB
Fastweb FASTGate 0.00.47 - Cross-Site Request Forgery
Fastweb FASTgate 0.00.47 devices are vulnerable to CSRF, with impacts including Wi-Fi password changing, Guest Wi-Fi act
23RISK
open ↗Exploit-DB✓ VexDay Proof
PlaySMS 1.4 - 'sendfromfile.php?Filename' (Authenticated) 'Code Execution (Metasploit)
PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile
50RISK
open ↗Exploit-DB✓ VexDay Proof
FTPShell Client 6.7 - Buffer Overflow
An issue was discovered in FTPShell Client 6.7. A remote FTP server can send 400 characters of 'F' in conjunction with t
50RISK
open ↗Exploit-DB
2345 Security Guard 3.7 - '2345NetFirewall.sys' Denial of Service
In 2345 Security Guard 3.7, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD)
23RISK
open ↗Exploit-DB✓ VexDay Proof
PlaySMS - 'import.php' (Authenticated) CSV File Upload Code Execution (Metasploit)
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RISK
open ↗Exploit-DB✓ VexDay Proof
Palo Alto Networks - 'readSessionVarsFromFile()' Session Corruption (Metasploit)
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RISK
open ↗Exploit-DB
CSP MySQL User Manager 2.3.1 - Authentication Bypass
CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a
23RISK
open ↗Exploit-DB
DeviceLock Plug and Play Auditor 5.72 - Unicode Buffer Overflow (SEH)
DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH).
28RISK
open ↗Exploit-DB
GNU wget - Cookie Injection
GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequen
28RISK
open ↗Exploit-DB
IceWarp Mail Server < 11.1.1 - Directory Traversal
Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary
50RISK
open ↗Exploit-DB
WordPress Plugin WF Cookie Consent 1.1.3 - Cross-Site Scripting
An issue was discovered in the wunderfarm WF Cookie Consent plugin 1.1.3 for WordPress. A persistent cross-site scriptin
23RISK
open ↗Exploit-DB✓ VexDay Proof
Google Chrome V8 - Object Allocation Size Integer Overflow
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch
83RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows WMI - Recieve Notification Exploit (Metasploit)
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to g
91RISK
open ↗Exploit-DB
GPON Routers - Authentication Bypass / Command Injection
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RISK
open ↗Exploit-DB
JasperReports - (Authenticated) File Read
TIBCO JasperReports Server Information Disclosure Vulnerability
83RISK
open ↗Exploit-DB
GPON Routers - Authentication Bypass / Command Injection
An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images
100RISK
open ↗Exploit-DB
TBK DVR4104 / DVR4216 - Credentials Leak
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open ↗Exploit-DB
LibreOffice/Open Office - '.odt' Information Disclosure
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically p
60RISK
open ↗Exploit-DB
Norton Core Secure WiFi Router - 'BLE' Command Injection (PoC)
The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in whic
28RISK
open ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::jsElementScrollHeightGetter' Use-After-Free
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.