Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,023GitHub PoC 13,334VulnCheck XDB 8,195Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
4,217 exploits
Nucleilow
Pure-FTPd ≤ 1.0.22 - Directory Traversal
Directory traversal vulnerability in pure-FTPd 1.0.22 and possibly other versions, when running on SUSE Linux Enterprise
18RISK
open ↗Nucleimedium
Titan FTP Server < 10.40 Move Function - Directory Traversal
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke
38RISK
open ↗Nucleimedium
Titan FTP Server Search Function < 10.40 - User Enumeration
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke
38RISK
open ↗Nucleimedium
Titan FTP Server < 10.40 - User Properties Traversal
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke
38RISK
open ↗Nucleimedium
vsftpd <= 3.0.2 - Access Restriction Bypass
Unspecified vulnerability in vsftpd 3.0.2 and earlier allows remote attackers to bypass access restrictions via unknown
18RISK
open ↗Nucleicritical
ProFTPd - Remote Code Execution
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISK
open ↗Nucleicritical
HP Data Protector - Arbitrary Command Execution
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary cod
60RISK
open ↗Nucleicritical
Oracle WebLogic Server Java Object Deserialization - Remote Code Execution
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12
40RISK
open ↗Nucleicritical
Cisco IOS 12.2(55)SE11 - Remote Code Execution
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RISK
open ↗Nucleicritical
Apache Log4j Server - Deserialization Command Execution
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events
40RISK
open ↗Nucleicritical
Oracle WebLogic Server Deserialization - Remote Code Execution
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open ↗Nucleicritical
Oracle WebLogic Server - Remote Code Execution
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
60RISK
open ↗Nucleihigh
ProFTPD < 1.3.6b - Remote Unauthenticated DoS
ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handl
23RISK
open ↗Nucleihigh
Pure-FTPd < 1.0.50 - DoS via Resource Exhaustion
In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c.
18RISK
open ↗Nucleicritical
SolarWinds Serv-U FTP - Remote Code Execution
Serv-U Remote Memory Escape Vulnerability
100RISK
open ↗Nucleicritical
RealTek AP Router SDK - Arbitrary Command Injection
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as
95RISK
open ↗Nucleihigh
PowerDNS Authoritative Server - Denial of Service
PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE
30RISK
open ↗Nucleihigh
Oracle WebLogic Server - Unauthorized Access
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISK
open ↗Nucleicritical
VMWare Aria Operations - Remote Code Execution
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key g
75RISK
open ↗Nucleicritical
Acronis Cyber Infrastructure - Default Password
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastruct
85RISK
open ↗Nucleicritical
Apache ActiveMQ - Remote Code Execution
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open ↗Nucleimedium
OpenSSH Terrapin Attack - Detection
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remot
50RISK
open ↗Nucleihigh
Jenkins < 2.441 - Arbitrary File Read
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open ↗Nucleicritical
Zimbra Collaboration Suite < 9.0.0 - Remote Code Execution
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISK
open ↗Nucleihigh
CUPS - Remote Code Execution
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open ↗Nucleimedium
Citrix NetScaler ADC & Gateway - Reflected XSS / Open Redirect
Cross-Site Scripting (XSS)
33RISK
open ↗Nucleihigh
MongoDB Server - Information Disclosure (MongoBleed)
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗Nucleicritical
Redis < 8.2.1 lua script - Integer Overflow
Lua library commands may lead to integer overflow and potential RCE
36RISK
open ↗Nucleihigh
Redis Lua Sandbox < 8.2.2 - Cross-User Escape
Redis: Authenticated users can execute LUA scripts as a different user
28RISK
open ↗Nucleihigh
Redis < 8.2.1 Lua Long-String Delimiter - Out-of-Bounds Read
Redis is vulnerable to DoS via specially crafted LUA scripts
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.