Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
3,462 exploits
Metasploit300
Ruby On Rails File Content Disclosure ('doubletap')
CVE-2019-5418HIGHunder attack
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
Metasploit300
Sielco Sistemi Winlog Remote File Access
Multiple directory traversal vulnerabilities in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA bef
43RISK
open
Metasploit300
Microsoft Windows Authenticated Logged In Users Enumeration
A Windows NT local user or administrator account has a default, null, blank, or missing password.
50RISK
open
Metasploit300
SMB Group Policy Preference Saved Passwords Enumeration
CVE-2014-1812HIGHunder attackransomware
The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windo
98RISK
open
Metasploit300
SMB Login Check Scanner
A Windows NT domain user or administrator account has a default, null, blank, or missing password.
23RISK
open
Metasploit300
Peplink Balance routers SQLi
SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw
50RISK
open
Metasploit300
MS17-010 SMB RCE Detection
CVE-2017-0148HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Metasploit300
Ulterius Server File Download Vulnerability
The Process function in RemoteTaskServer/WebServer/HttpServer.cs in Ulterius before 1.9.5.0 allows HTTP server directory
60RISK
open
Metasploit300
NETGEAR Administrator Password Disclosure
CVE-2017-5521HIGHunder attack
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R
100RISK
open
Metasploit300
MS17-010 SMB RCE Detection
CVE-2017-0143HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Metasploit300
TYPO3 sa-2010-020 Remote File Disclosure
The jumpUrl (aka access tracking) implementation in tslib/class.tslib_fe.php in TYPO3 4.2.x before 4.2.15, 4.3.x before
43RISK
open
Metasploit300
MS17-010 SMB RCE Detection
CVE-2017-0144HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Metasploit300
ManageEngine DataSecurity Plus Xnode Enumeration
Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode
40RISK
open
Metasploit300
ManageEngine ADAudit Plus Xnode Enumeration
Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode
40RISK
open
Metasploit300
RPC DoS targeting *nix rpcbind/libtirpc
rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider t
60RISK
open
Metasploit300
MS17-010 SMB RCE Detection
CVE-2017-0145HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Metasploit300
Samba lsa_io_privilege_set Heap Overflow
Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers
60RISK
open
Metasploit300
MS17-010 SMB RCE Detection
CVE-2017-0147HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Metasploit300
FortiOS Path Traversal Credential Gatherer
CVE-2018-13379CRITICALunder attackransomware
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open
Metasploit300
Firefox PDF.js Browser File Theft
CVE-2015-4495HIGHunder attack
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote
100RISK
open
Metasploit300
DNS Record Scanner and Enumerator
A DNS server allows zone transfers.
30RISK
open
Metasploit300
GlassFish Brute Force Utility
Unspecified vulnerability in Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, and 3.0.1, and Sun Java System Applicati
50RISK
open
Metasploit300
Samba lsa_io_trans_names Heap Overflow
Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers
60RISK
open
Metasploit300
MS17-010 SMB RCE Detection
CVE-2017-0146HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Metasploit300
Samba _netr_ServerPasswordSet Uninitialized Credential State
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1
60RISK
open
Metasploit300
SMTP User Enumeration Utility
15RISK
open
Metasploit300
SMTP Open Relay Detection
A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.
23RISK
open
Metasploit300
Arris DG950A Cable Modem Wifi Enumeration
The Arris Touchstone DG950A cable modem with software 7.10.131 has an SNMP community of public, which allows remote atta
23RISK
open
Metasploit300
Cambium cnPilot r200/r201 SNMP Enumeration
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the SNMP read-only (RO) community string has access
18RISK
open
Metasploit300
Binom3 Web Management Login Scanner, Config and Password File Dump
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Lack of authentication for rem
23RISK
open
previouspage 111 / 116next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.