Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,432cataloged exploits
34,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,493GitHub PoC 13,618VulnCheck XDB 8,198Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
4,217 exploits
Nucleihigh
Distccd v1 - Remote Code Execution
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote at
60RISK
open ↗Nucleimedium
FileZilla Server < 0.9.6 - DoS via MS-DOS Device Names
FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename cont
18RISK
open ↗Nucleicritical
Fortinet FortiSIEM - Unauthenticated Command Injection
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
85RISK
open ↗Nucleicritical
Apache RocketMQ - Remote Command Execution
Apache RocketMQ: Possible remote code execution when using the update configuration function
85RISK
open ↗Nucleicritical
Fortinet Forticlient Endpoint Management Server - SQL Injection
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS versio
100RISK
open ↗Nucleihigh
ProFTPD < 1.3.8a - DoS via Out-of-Bounds Read
make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandl
18RISK
open ↗Nucleicritical
Fortinet FortiSIEM - OS Command Injection
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
85RISK
open ↗Nucleihigh
Pure-FTPd < 1.0.52 - Buffer Overflow
pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the
36RISK
open ↗Nucleihigh
ProFTPD ≤ 1.3.8b - Privilege Escalation via mod_sql
In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of th
36RISK
open ↗Nucleicritical
Fortinet FortiSIEM - OS Command Injection
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in
75RISK
open ↗Nucleicritical
Güralp Systems FMUS Series - Unauthenticated Access
Güralp Systems FMUS Series and MIN Series Devices
43RISK
open ↗Nucleimedium
Mailpit < 1.28.2 - SMTP CRLF Injection
Mailpit has SMTP Header Injection via Regex Bypass
28RISK
open ↗Nucleihigh
ProFTPD mod_sql - Preauth User Backdoor
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where th
36RISK
open ↗Nucleicritical
ProFTPd-1.3.3c - Backdoor Command Execution
ProFTPD 1.3.3c Backdoor Command Execution
63RISK
open ↗Nucleimedium
MySQL - Authentication Bypass
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x befor
60RISK
open ↗Nucleihigh
Memcached Server SASL Authentication - Remote Code Execution
An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of
48RISK
open ↗Nucleicritical
Cisco Smart Install - Configuration Download
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthentica
100RISK
open ↗Nucleihigh
Apache HTTP Server - NULL Pointer Dereference
mod_md, DoS via Coredumps on specially crafted requests
30RISK
open ↗Nucleicritical
NTPsec > 1.1.3 - 'ctl_getitem' Out-of-Bounds Read
An issue was discovered in NTPsec before 1.1.3. Because of a bug in ctl_getitem, there is a stack-based buffer over-read
50RISK
open ↗Nucleihigh
PostgreSQL 9.3-12.3 Authenticated Remote Code Execution
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open ↗Nucleicritical
Oracle WebLogic Server - Remote Code Execution (Insecure Deserialization)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISK
open ↗Nucleicritical
Oracle WebLogic Server - Remote Code Execution
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RISK
open ↗Nucleicritical
IBM Data Risk Manager - Hardcoded Credentials
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrativ
65RISK
open ↗Nucleicritical
OpenSMTPD 6.4.0-6.6.1 - Remote Code Execution
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open ↗Nucleihigh
Veritas Backup Exec - Broken Authentication
An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authenticat
98RISK
open ↗Nucleicritical
SolarWinds Serv-U FTP - Remote Code Execution
Serv-U Remote Memory Escape Vulnerability
100RISK
open ↗Nucleicritical
RealTek AP Router SDK - Arbitrary Command Injection
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as
95RISK
open ↗Nucleihigh
PowerDNS Authoritative Server - Denial of Service
PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE
30RISK
open ↗Nucleihigh
Oracle WebLogic Server - Unauthorized Access
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISK
open ↗Nucleicritical
VMWare Aria Operations - Remote Code Execution
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key g
75RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.