Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
4,217 exploits
Nucleilow
Pure-FTPd ≤ 1.0.22 - Directory Traversal
Directory traversal vulnerability in pure-FTPd 1.0.22 and possibly other versions, when running on SUSE Linux Enterprise
18RISK
open
Nucleimedium
Titan FTP Server < 10.40 Move Function - Directory Traversal
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke
38RISK
open
Nucleimedium
Titan FTP Server Search Function < 10.40 - User Enumeration
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke
38RISK
open
Nucleimedium
Titan FTP Server < 10.40 - User Properties Traversal
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke
38RISK
open
Nucleimedium
vsftpd <= 3.0.2 - Access Restriction Bypass
Unspecified vulnerability in vsftpd 3.0.2 and earlier allows remote attackers to bypass access restrictions via unknown
18RISK
open
Nucleicritical
ProFTPd - Remote Code Execution
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISK
open
Nucleicritical
HP Data Protector - Arbitrary Command Execution
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary cod
60RISK
open
Nucleicritical
Oracle WebLogic Server Java Object Deserialization - Remote Code Execution
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12
40RISK
open
Nucleicritical
Cisco IOS 12.2(55)SE11 - Remote Code Execution
CVE-2017-3881CRITICALunder attack
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RISK
open
Nucleicritical
Apache Log4j Server - Deserialization Command Execution
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events
40RISK
open
Nucleicritical
Oracle WebLogic Server Deserialization - Remote Code Execution
CVE-2018-2628CRITICALunder attack
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
Nucleicritical
Oracle WebLogic Server - Remote Code Execution
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
60RISK
open
Nucleihigh
ProFTPD < 1.3.6b - Remote Unauthenticated DoS
ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handl
23RISK
open
Nucleihigh
Pure-FTPd < 1.0.50 - DoS via Resource Exhaustion
In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c.
18RISK
open
Nucleicritical
SolarWinds Serv-U FTP - Remote Code Execution
CVE-2021-35211CRITICALunder attackransomware
Serv-U Remote Memory Escape Vulnerability
100RISK
open
Nucleicritical
RealTek AP Router SDK - Arbitrary Command Injection
CVE-2021-35394CRITICALunder attack
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as
95RISK
open
Nucleihigh
PowerDNS Authoritative Server - Denial of Service
PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE
30RISK
open
Nucleihigh
Oracle WebLogic Server - Unauthorized Access
CVE-2023-21839HIGHunder attack
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISK
open
Nucleicritical
VMWare Aria Operations - Remote Code Execution
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key g
75RISK
open
Nucleicritical
Acronis Cyber Infrastructure - Default Password
CVE-2023-45249CRITICALunder attack
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastruct
85RISK
open
Nucleicritical
Apache ActiveMQ - Remote Code Execution
CVE-2023-46604CRITICALunder attackransomware
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
Nucleimedium
OpenSSH Terrapin Attack - Detection
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remot
50RISK
open
Nucleihigh
Jenkins < 2.441 - Arbitrary File Read
CVE-2024-23897CRITICALunder attackransomware
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
Nucleicritical
Zimbra Collaboration Suite < 9.0.0 - Remote Code Execution
CVE-2024-45519CRITICALunder attack
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISK
open
Nucleihigh
CUPS - Remote Code Execution
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open
Nucleimedium
Citrix NetScaler ADC & Gateway - Reflected XSS / Open Redirect
Cross-Site Scripting (XSS)
33RISK
open
Nucleihigh
MongoDB Server - Information Disclosure (MongoBleed)
CVE-2025-14847HIGHunder attack
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
Nucleicritical
Redis < 8.2.1 lua script - Integer Overflow
Lua library commands may lead to integer overflow and potential RCE
36RISK
open
Nucleihigh
Redis Lua Sandbox < 8.2.2 - Cross-User Escape
Redis: Authenticated users can execute LUA scripts as a different user
28RISK
open
Nucleihigh
Redis < 8.2.1 Lua Long-String Delimiter - Out-of-Bounds Read
Redis is vulnerable to DoS via specially crafted LUA scripts
28RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.