Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,863cataloged exploits
32,152CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,978GitHub PoC 13,279VulnCheck XDB 8,156Nuclei 4,202Metasploit 3,462✓ verified onlyrecentpopularrisk
3,462 exploits
Metasploit300
Telnet Login Check Scanner
A Unix account has a default, null, blank, or missing password.
50RISK
open ↗Metasploit300
RuggedCom Telnet Password Generator
RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Ad
50RISK
open ↗Metasploit300
UDP Amplification Scanner
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISK
open ↗Metasploit300
SSDP ssdp:all M-SEARCH Amplification Scanner
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISK
open ↗Metasploit300
UPnP SSDP M-SEARCH Information Discovery
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RISK
open ↗Metasploit300
WinRM Login Utility
A Unix account has a default, null, blank, or missing password.
50RISK
open ↗Metasploit300
VNC Authentication None Detection
RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers t
60RISK
open ↗Metasploit300
UPnP SSDP M-SEARCH Information Discovery
Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP
50RISK
open ↗Metasploit300
UPnP SSDP M-SEARCH Information Discovery
The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attacke
60RISK
open ↗Metasploit300
MS12-020 Microsoft Remote Desktop Checker
The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows V
60RISK
open ↗Metasploit300
PostgreSQL Login Utility
A Unix account has a default, null, blank, or missing password.
50RISK
open ↗Metasploit300
PostgreSQL Database Name Command Line Flag Injection
Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows re
30RISK
open ↗Metasploit300
Portmapper Amplification Scanner
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISK
open ↗Metasploit300
PcAnywhere Login Scanner
A Unix account has a default, null, blank, or missing password.
50RISK
open ↗Metasploit300
UPnP SSDP M-SEARCH Information Discovery
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RISK
open ↗Metasploit300
Varnish Cache CLI File Read
The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy serve
50RISK
open ↗Metasploit300
Varnish Cache CLI Login Utility
The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy serve
50RISK
open ↗Metasploit300
VMware Authentication Daemon Login Scanner
A Unix account has a default, null, blank, or missing password.
50RISK
open ↗Metasploit300
Oracle RDBMS Login Utility
A Unix account has a default, null, blank, or missing password.
50RISK
open ↗Metasploit300
NTP Clock Variables Disclosure
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISK
open ↗Metasploit300
NTP "NAK to the Future"
Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authen
40RISK
open ↗Metasploit300
NTP Monitor List Scanner
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISK
open ↗Metasploit300
VMware Web Login Scanner
A Unix account has a default, null, blank, or missing password.
50RISK
open ↗Metasploit300
NNTP Login Utility
A Unix account has a default, null, blank, or missing password.
50RISK
open ↗Metasploit300
NFS Mount Scanner
Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list.
23RISK
open ↗Metasploit300
NFS Mount Scanner
NFS exports system-critical data to the world, e.g. / or a password file.
23RISK
open ↗Metasploit300
MySQL Login Utility
A Unix account has a default, null, blank, or missing password.
50RISK
open ↗Metasploit300
VMware Server Directory Traversal Vulnerability
Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on L
60RISK
open ↗Metasploit300
Apple Remote Desktop Root Vulnerability
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The is
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.