Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
3,462 exploits
Metasploit300
WordPress Simple Backup File Read Vulnerability
Simple Backup <= 2.7.10 - Arbitrary File Download via Path Traversal
36RISK
open
Metasploit300
WordPress NextGEN Gallery Directory Read Vulnerability
The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.
23RISK
open
Metasploit300
WordPress Mobile Edition File Read Vulnerability
Directory traversal vulnerability in the mTheme-Unus theme before 2.3 for WordPress allows an attacker to read arbitrary
30RISK
open
Metasploit300
WordPress Mobile Pack Information Disclosure Vulnerability
The WordPress Mobile Pack plugin before 2.0.2 for WordPress does not properly restrict access to password protected post
23RISK
open
Metasploit300
WordPress GI-Media Library Plugin Directory Traversal Vulnerability
GI-Media Library < 3.0 - Directory Traversal
36RISK
open
Metasploit300
WordPress DukaPress Plugin File Read Vulnerability
Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2
50RISK
open
Metasploit300
Wordpress XML-RPC Username/Password Login Scanner
A Unix account has a default, null, blank, or missing password.
50RISK
open
Metasploit300
Wordpress Pingback Locator
The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct
23RISK
open
Metasploit300
WordPress Brute Force and User Enumeration Utility
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the u
60RISK
open
Metasploit300
WordPress XMLRPC GHOST Vulnerability Scanner
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RISK
open
Metasploit300
HTTP WebDAV Internal IP Scanner
IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (whic
30RISK
open
Metasploit300
WANGKONGBAO CNS-1000 and 1100 UTM Directory Traversal
Multiple directory traversal vulnerabilities in src/acloglogin.php in Wangkongbao CNS-1000 and 1100 allow remote attacke
50RISK
open
Metasploit300
HTTP Cross-Site Tracing Detection
The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the
23RISK
open
Metasploit300
TP-Link Wireless Lite N Access Point Directory Traversal Vulnerability
Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13
50RISK
open
Metasploit300
Tomcat Application Manager Login Utility
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which all
60RISK
open
Metasploit300
Tomcat Application Manager Login Utility
HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to exe
60RISK
open
Metasploit300
Tomcat Application Manager Login Utility
HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers t
50RISK
open
Metasploit300
Tomcat Application Manager Login Utility
IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial
50RISK
open
Metasploit300
Tomcat Application Manager Login Utility
The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN acc
50RISK
open
Metasploit300
Tomcat Application Manager Login Utility
A Unix account has a default, null, blank, or missing password.
50RISK
open
Metasploit300
Tomcat Application Manager Login Utility
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a
60RISK
open
Metasploit300
Apache Tomcat User Enumeration
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, al
60RISK
open
Metasploit300
RIPS Scanner Directory Traversal
RIPS Scanner v0.54 Path Traversal
36RISK
open
Metasploit300
Apache Reverse Proxy Bypass Vulnerability Scanner
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does
60RISK
open
Metasploit300
Ruby on Rails XML Processor YAML Deserialization Scanner
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RISK
open
Metasploit300
Ruby on Rails JSON Processor YAML Deserialization Scanner
lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly
60RISK
open
Metasploit300
HTTP Options Detection
The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the
23RISK
open
Metasploit300
HTTP Options Detection
IBM WebSphere Application Server 5.0.x before 5.02.15, 5.1.x before 5.1.1.8, and 6.x before fixpack V6.0.2.5, when sessi
23RISK
open
Metasploit300
Novell Zenworks Mobile Device Management Admin Credentials
Directory traversal vulnerability in MDM.php in Novell ZENworks Mobile Management (ZMM) 2.6.1 and 2.7.0 allows remote at
50RISK
open
Metasploit300
Nginx Source Code Disclosure/Download
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or
60RISK
open
previouspage 112 / 116next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.