Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
3,462 exploits
Metasploit300
Tomcat Application Manager Login Utility
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which all
60RISK
open
Metasploit300
MS15-034 HTTP Protocol Stack Request Handling Denial-of-Service
CVE-2015-1635CRITICALunder attack
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open
Metasploit300
TP-Link Wireless Lite N Access Point Directory Traversal Vulnerability
Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13
50RISK
open
Metasploit300
HTTP Cross-Site Tracing Detection
The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the
23RISK
open
Metasploit300
WANGKONGBAO CNS-1000 and 1100 UTM Directory Traversal
Multiple directory traversal vulnerabilities in src/acloglogin.php in Wangkongbao CNS-1000 and 1100 allow remote attacke
50RISK
open
Metasploit300
HTTP WebDAV Internal IP Scanner
IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (whic
30RISK
open
Metasploit300
WordPress XMLRPC GHOST Vulnerability Scanner
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RISK
open
Metasploit300
WordPress Brute Force and User Enumeration Utility
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the u
60RISK
open
Metasploit300
Wordpress Pingback Locator
The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct
23RISK
open
Metasploit300
Wordpress XML-RPC Username/Password Login Scanner
A Unix account has a default, null, blank, or missing password.
50RISK
open
Metasploit300
WordPress DukaPress Plugin File Read Vulnerability
Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2
50RISK
open
Metasploit300
WordPress GI-Media Library Plugin Directory Traversal Vulnerability
GI-Media Library < 3.0 - Directory Traversal
36RISK
open
Metasploit300
WordPress Mobile Pack Information Disclosure Vulnerability
The WordPress Mobile Pack plugin before 2.0.2 for WordPress does not properly restrict access to password protected post
23RISK
open
Metasploit300
WordPress Mobile Edition File Read Vulnerability
Directory traversal vulnerability in the mTheme-Unus theme before 2.3 for WordPress allows an attacker to read arbitrary
30RISK
open
Metasploit300
WordPress NextGEN Gallery Directory Read Vulnerability
The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.
23RISK
open
Metasploit300
FreeBSD Remote NFS RPC Request Denial of Service
nfsd in FreeBSD 6.0 kernel allows remote attackers to cause a denial of service via a crafted NFS mount request, as demo
50RISK
open
Metasploit300
ISC DHCP Zero Length ClientID Denial of Service Module
ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit)
60RISK
open
Metasploit300
WordPress Simple Backup File Read Vulnerability
Simple Backup <= 2.7.10 - Arbitrary File Download via Path Traversal
36RISK
open
Metasploit300
WordPress Subscribe Comments File Read Vulnerability
Subscribe to Comments <= 2.1.2 - Local File Includion
36RISK
open
Metasploit300
WebEx Remote Command Execution Utility
Cisco Webex Meetings Desktop App Update Service Command Injection Vulnerability
61RISK
open
Metasploit300
Samba Symlink Directory Traversal
The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable
50RISK
open
Metasploit300
TrendMicro ServerProtect File Access
SpntSvc.exe daemon in Trend Micro ServerProtect 5.58 for Windows, before Security Patch 4, exposes unspecified dangerous
30RISK
open
Metasploit300
Novell ZENworks Asset Management 7.5 Remote File Access
The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username o
30RISK
open
Metasploit300
Novell ZENworks Asset Management 7.5 Configuration Access
The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username o
30RISK
open
Metasploit300
Lotus Domino Password Hash Collector
IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.n
43RISK
open
Metasploit300
cups-browsed Information Disclosure
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open
Metasploit300
Dahua DVR Auth Bypass Scanner
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
60RISK
open
Metasploit300
Multiple DVR Manufacturers Configuration Disclosure
Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Wel
60RISK
open
Metasploit300
EasyCafe Server Remote File Access
EasyCafe Server 2.2.14 Remote File Disclosure via Opcode 0x43
36RISK
open
Metasploit300
TrendMicro OfficeScanNT Listener Traversal Arbitrary File Access
Directory traversal vulnerability in the UpdateAgent function in TmListen.exe in the OfficeScanNT Listener service in th
23RISK
open
previouspage 113 / 116next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.