Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,852cataloged exploits
32,148CVEs with public exploitation
1,932lab-tested
3,462 exploits
Metasploit300
Cisco IOS HTTP GET /%% Request Denial of Service
CVE-2000-038026 Apr 2000
The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a deni
50RISK
open
Metasploit300
OpenSSL DTLS ChangeCipherSpec Remote DoS
CVE-2009-138626 Apr 2000
ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and
60RISK
open
Metasploit400
UoW IMAP Server LSUB Buffer Overflow
CVE-2000-028416 Apr 2000
Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via
50RISK
open
Metasploit600
RedHat Piranha Virtual Server Package passwd.php3 Arbitrary Command Execution
CVE-2000-024804 Apr 2000
The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password tha
60RISK
open
Metasploit600
RedHat Piranha Virtual Server Package passwd.php3 Arbitrary Command Execution
CVE-2000-032204 Apr 2000
The passwd.php3 CGI script in the Red Hat Piranha Virtual Server Package allows local users to execute arbitrary command
50RISK
open
Metasploit300
ARP Spoof
CVE-1999-066722 Dec 1999
The ARP protocol allows any host to spoof ARP replies and poison the ARP cache to conduct IP address spoofing or a denia
23RISK
open
Metasploit600
Matt Wright guestbook.pl Arbitrary Command Execution
CVE-1999-105305 Nov 1999
guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remo
60RISK
open
Metasploit0
SSH User Code Execution
CVE-1999-050201 Jan 1999
A Unix account has a default, null, blank, or missing password.
50RISK
open
Metasploit0
Microsoft Windows Authenticated User Code Execution
CVE-1999-050401 Jan 1999
A Windows NT local user or administrator account has a default, null, blank, or missing password.
50RISK
open
Metasploit600
Powershell Remoting Remote Command Execution
CVE-1999-050401 Jan 1999
A Windows NT local user or administrator account has a default, null, blank, or missing password.
50RISK
open
Metasploit600
PsExec via Current User Token
CVE-1999-050401 Jan 1999
A Windows NT local user or administrator account has a default, null, blank, or missing password.
50RISK
open
Metasploit600
Windows Management Instrumentation (WMI) Remote Command Execution
CVE-1999-050401 Jan 1999
A Windows NT local user or administrator account has a default, null, blank, or missing password.
50RISK
open
Metasploit600
MS99-025 Microsoft IIS MDAC msadcs.dll RDS Arbitrary Remote Command Execution
CVE-1999-101117 Jul 1998
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x expose
60RISK
open
Metasploit200
War-FTPD 1.65 Password Overflow
CVE-1999-025619 Mar 1998
Buffer overflow in War FTP allows remote execution of commands.
60RISK
open
Metasploit200
War-FTPD 1.65 Username Overflow
CVE-1999-025619 Mar 1998
Buffer overflow in War FTP allows remote execution of commands.
60RISK
open
Metasploit300
X11 Keylogger
CVE-1999-052601 Jul 1997
An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.
23RISK
open
Metasploit300
Chargen Probe Utility
CVE-1999-010308 Feb 1996
Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or U
23RISK
open
Metasploit600
Solaris ypupdated Command Execution
CVE-1999-020912 Dec 1994
The SunView (SunTools) selection_svc facility allows remote users to read files.
50RISK
open
Metasploit300
NTP "NAK to the Future"
Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authen
40RISK
open
Metasploit300
Tomcat Application Manager Login Utility
IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial
50RISK
open
Metasploit300
Tomcat Application Manager Login Utility
HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers t
50RISK
open
Metasploit300
Tomcat Application Manager Login Utility
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a
60RISK
open
Metasploit300
FreeBSD Remote NFS RPC Request Denial of Service
nfsd in FreeBSD 6.0 kernel allows remote attackers to cause a denial of service via a crafted NFS mount request, as demo
50RISK
open
Metasploit300
ISC DHCP Zero Length ClientID Denial of Service Module
ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit)
60RISK
open
Metasploit300
WebEx Remote Command Execution Utility
Cisco Webex Meetings Desktop App Update Service Command Injection Vulnerability
61RISK
open
Metasploit300
Samba Symlink Directory Traversal
The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable
50RISK
open
Metasploit300
TrendMicro ServerProtect File Access
SpntSvc.exe daemon in Trend Micro ServerProtect 5.58 for Windows, before Security Patch 4, exposes unspecified dangerous
30RISK
open
Metasploit300
Tomcat Application Manager Login Utility
HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to exe
60RISK
open
Metasploit300
Viproy CUCDM IP Phone XML Services - Speed Dial Attack Tool
The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application
23RISK
open
Metasploit300
Viproy CUCDM IP Phone XML Services - Call Forwarding Tool
The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application
23RISK
open
previouspage 107 / 116next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.