Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
3,462 exploits
Metasploit300
SSH Username Enumeration
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISK
open
Metasploit300
SSH Username Enumeration
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
Metasploit300
SSH Username Enumeration
OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations
50RISK
open
Metasploit300
SNMP Community Login Scanner
An SNMP community name is the default (e.g. public), null, or missing.
33RISK
open
Metasploit300
SNMP Community Login Scanner
An account on a router, firewall, or other network device has a default, null, blank, or missing password.
18RISK
open
Metasploit300
SNMP Community Login Scanner
An SNMP community name is guessable.
23RISK
open
Metasploit300
SNMP Enumeration Module
An SNMP community name is the default (e.g. public), null, or missing.
33RISK
open
Metasploit300
SNMP Enumeration Module
An account on a router, firewall, or other network device has a default, null, blank, or missing password.
18RISK
open
Metasploit300
SNMP Enumeration Module
An SNMP community name is guessable.
23RISK
open
Metasploit300
Cambium ePMP 1000 SNMP Enumeration
An Improper Privilege Management issue was discovered in Cambium Networks ePMP. The privileges for SNMP community string
18RISK
open
Metasploit300
Cambium ePMP 1000 SNMP Enumeration
An Improper Access Control issue was discovered in Cambium Networks ePMP. After a valid user has used SNMP configuration
18RISK
open
Metasploit300
Cambium cnPilot r200/r201 SNMP Enumeration
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the SNMP read-only (RO) community string has access
18RISK
open
Metasploit300
Arris DG950A Cable Modem Wifi Enumeration
The Arris Touchstone DG950A cable modem with software 7.10.131 has an SNMP community of public, which allows remote atta
23RISK
open
Metasploit300
TrendMicro OfficeScanNT Listener Traversal Arbitrary File Access
Directory traversal vulnerability in the UpdateAgent function in TmListen.exe in the OfficeScanNT Listener service in th
23RISK
open
Metasploit300
SMTP Open Relay Detection
A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.
23RISK
open
Metasploit300
Cisco Secure ACS Unauthorized Password Change
The web-based management interface in Cisco Secure Access Control System (ACS) 5.1 before 5.1.0.44.6 and 5.2 before 5.2.
23RISK
open
Metasploit300
Cisco ASA Authentication Bypass (EXTRABACON)
CVE-2016-6366HIGHunder attack
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Service
100RISK
open
Metasploit300
SMTP User Enumeration Utility
15RISK
open
Metasploit300
Samba _netr_ServerPasswordSet Uninitialized Credential State
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1
60RISK
open
Metasploit300
MS17-010 SMB RCE Detection
CVE-2017-0146HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Metasploit300
MS17-010 SMB RCE Detection
CVE-2017-0147HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Metasploit300
MS17-010 SMB RCE Detection
CVE-2017-0145HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Metasploit300
MS17-010 SMB RCE Detection
CVE-2017-0144HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Metasploit300
MS17-010 SMB RCE Detection
CVE-2017-0143HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Metasploit300
Ulterius Server File Download Vulnerability
The Process function in RemoteTaskServer/WebServer/HttpServer.cs in Ulterius before 1.9.5.0 allows HTTP server directory
60RISK
open
Metasploit300
TYPO3 sa-2010-020 Remote File Disclosure
The jumpUrl (aka access tracking) implementation in tslib/class.tslib_fe.php in TYPO3 4.2.x before 4.2.15, 4.3.x before
43RISK
open
Metasploit300
MS17-010 SMB RCE Detection
CVE-2017-0148HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Metasploit300
SMB Login Check Scanner
A Windows NT domain user or administrator account has a default, null, blank, or missing password.
23RISK
open
Metasploit300
SMB Group Policy Preference Saved Passwords Enumeration
CVE-2014-1812HIGHunder attackransomware
The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windo
98RISK
open
Metasploit300
Microsoft Windows Authenticated Logged In Users Enumeration
A Windows NT local user or administrator account has a default, null, blank, or missing password.
50RISK
open
previouspage 109 / 116next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.