Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
3,462 exploits
Metasploit300
Carlo Gavazzi Energy Meters - Login Brute Force, Extract Info and Dump Plant Database
An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Vers
18RISK
open
Metasploit300
GlassFish Brute Force Utility
Unspecified vulnerability in Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, and 3.0.1, and Sun Java System Applicati
50RISK
open
Metasploit300
Embedthis GoAhead Embedded Web Server Directory Traversal
EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remot
23RISK
open
Metasploit300
ws - Denial of Service
ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date
18RISK
open
Metasploit300
WordPress Traversal Directory DoS
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.
43RISK
open
Metasploit300
Novell Groupwise Agents HTTP Directory Traversal
Directory traversal vulnerability in the agent HTTP interfaces in Novell GroupWise 8.0 before Support Pack 3 and 2012 be
30RISK
open
Metasploit300
ua-parser-js npm module ReDoS
ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial o
18RISK
open
Metasploit300
Tautulli v2.1.9 - Shutdown Denial of Service
In Tautulli 2.1.9, CSRF in the /shutdown URI allows an attacker to shut down the remote media server. (Also, anonymous a
23RISK
open
Metasploit300
HTTP Host Header Injection Detection
The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the emai
60RISK
open
Metasploit300
HP Intelligent Management BIMS DownloadServlet Directory Traversal
Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Soft
30RISK
open
Metasploit300
HP Intelligent Management FaultDownloadServlet Directory Traversal
Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Netw
23RISK
open
Metasploit300
HP Intelligent Management IctDownloadServlet Directory Traversal
Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Netw
23RISK
open
Metasploit300
HP Intelligent Management ReportImgServlt Directory Traversal
Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Netw
23RISK
open
Metasploit300
HP Intelligent Management SOM FileDownloadServlet Arbitrary Download
Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Mod
30RISK
open
Metasploit300
HTTP Login Utility
A Unix account has a default, null, blank, or missing password.
50RISK
open
Metasploit300
Httpdasm Directory Traversal
httpdASM 0.92 Path Traversal
36RISK
open
Metasploit300
Microsoft IIS HTTP Internal IP Disclosure
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page w
60RISK
open
Metasploit300
Microsoft IIS HTTP Internal IP Disclosure
IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (whic
30RISK
open
Metasploit300
JBoss Status Servlet Information Gathering
JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remot
30RISK
open
Metasploit300
JBoss Status Servlet Information Gathering
Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 a
30RISK
open
Metasploit300
JBoss Vulnerability Scanner
JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remot
30RISK
open
Metasploit300
JBoss Vulnerability Scanner
CVE-2017-12149CRITICALunder attackransomware
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISK
open
Metasploit300
JBoss Vulnerability Scanner
Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 a
30RISK
open
Metasploit300
JBoss Vulnerability Scanner
CVE-2010-1428HIGHunder attackransomware
The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4
78RISK
open
Metasploit300
JBoss Vulnerability Scanner
CVE-2010-0738MEDIUMunder attackransomware
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RISK
open
Metasploit300
MS15-034 HTTP Protocol Stack Request Handling Denial-of-Service
CVE-2015-1635CRITICALunder attack
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open
Metasploit300
Jenkins-CI Unauthenticated Script-Console Scanner
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary co
60RISK
open
Metasploit300
Joomla Bruteforce Login Utility
A Unix account has a default, null, blank, or missing password.
50RISK
open
Metasploit300
Linknat Vos Manager Traversal
Linknat VOS Manager Path Traversal File Disclosure
36RISK
open
Metasploit300
Linksys E1500 Directory Traversal Vulnerability
Linksys Routers apply.cgi Path Traversal
28RISK
open
previouspage 110 / 116next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.