Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,852cataloged exploits
32,148CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,978GitHub PoC 13,268VulnCheck XDB 8,156Nuclei 4,202Metasploit 3,462✓ verified onlyrecentpopularrisk
3,462 exploits
Metasploit300
Cisco IOS HTTP GET /%% Request Denial of Service
The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a deni
50RISK
open ↗Metasploit300
OpenSSL DTLS ChangeCipherSpec Remote DoS
ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and
60RISK
open ↗Metasploit400
UoW IMAP Server LSUB Buffer Overflow
Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via
50RISK
open ↗Metasploit600
RedHat Piranha Virtual Server Package passwd.php3 Arbitrary Command Execution
The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password tha
60RISK
open ↗Metasploit600
RedHat Piranha Virtual Server Package passwd.php3 Arbitrary Command Execution
The passwd.php3 CGI script in the Red Hat Piranha Virtual Server Package allows local users to execute arbitrary command
50RISK
open ↗Metasploit300
ARP Spoof
The ARP protocol allows any host to spoof ARP replies and poison the ARP cache to conduct IP address spoofing or a denia
23RISK
open ↗Metasploit600
Matt Wright guestbook.pl Arbitrary Command Execution
guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remo
60RISK
open ↗Metasploit0
SSH User Code Execution
A Unix account has a default, null, blank, or missing password.
50RISK
open ↗Metasploit0
Microsoft Windows Authenticated User Code Execution
A Windows NT local user or administrator account has a default, null, blank, or missing password.
50RISK
open ↗Metasploit600
Powershell Remoting Remote Command Execution
A Windows NT local user or administrator account has a default, null, blank, or missing password.
50RISK
open ↗Metasploit600
PsExec via Current User Token
A Windows NT local user or administrator account has a default, null, blank, or missing password.
50RISK
open ↗Metasploit600
Windows Management Instrumentation (WMI) Remote Command Execution
A Windows NT local user or administrator account has a default, null, blank, or missing password.
50RISK
open ↗Metasploit600
MS99-025 Microsoft IIS MDAC msadcs.dll RDS Arbitrary Remote Command Execution
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x expose
60RISK
open ↗Metasploit200
War-FTPD 1.65 Password Overflow
Buffer overflow in War FTP allows remote execution of commands.
60RISK
open ↗Metasploit200
War-FTPD 1.65 Username Overflow
Buffer overflow in War FTP allows remote execution of commands.
60RISK
open ↗Metasploit300
X11 Keylogger
An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.
23RISK
open ↗Metasploit300
Chargen Probe Utility
Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or U
23RISK
open ↗Metasploit600
Solaris ypupdated Command Execution
The SunView (SunTools) selection_svc facility allows remote users to read files.
50RISK
open ↗Metasploit300
NTP "NAK to the Future"
Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authen
40RISK
open ↗Metasploit300
Tomcat Application Manager Login Utility
IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial
50RISK
open ↗Metasploit300
Tomcat Application Manager Login Utility
HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers t
50RISK
open ↗Metasploit300
Tomcat Application Manager Login Utility
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a
60RISK
open ↗Metasploit300
FreeBSD Remote NFS RPC Request Denial of Service
nfsd in FreeBSD 6.0 kernel allows remote attackers to cause a denial of service via a crafted NFS mount request, as demo
50RISK
open ↗Metasploit300
ISC DHCP Zero Length ClientID Denial of Service Module
ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit)
60RISK
open ↗Metasploit300
WebEx Remote Command Execution Utility
Cisco Webex Meetings Desktop App Update Service Command Injection Vulnerability
61RISK
open ↗Metasploit300
Samba Symlink Directory Traversal
The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable
50RISK
open ↗Metasploit300
TrendMicro ServerProtect File Access
SpntSvc.exe daemon in Trend Micro ServerProtect 5.58 for Windows, before Security Patch 4, exposes unspecified dangerous
30RISK
open ↗Metasploit300
Tomcat Application Manager Login Utility
HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to exe
60RISK
open ↗Metasploit300
Viproy CUCDM IP Phone XML Services - Speed Dial Attack Tool
The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application
23RISK
open ↗Metasploit300
Viproy CUCDM IP Phone XML Services - Call Forwarding Tool
The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.