Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,978GitHub PoC 13,282VulnCheck XDB 8,176Nuclei 4,202Metasploit 3,462✓ verified onlyrecentpopularrisk
3,462 exploits
Metasploit300
Linux DoS Xen 4.2.0 2012-5525
The get_page_from_gfn hypercall function in Xen 4.2 allows local PV guest OS administrators to cause a denial of service
18RISK
open ↗Metasploit300
Tomcat Application Manager Login Utility
HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers t
50RISK
open ↗Metasploit300
Haserl Arbitrary File Reader
Lack of verification in haserl, a component of Alpine Linux Configuration Framework, before 0.9.36 allows local users to
18RISK
open ↗Metasploit300
Tomcat Application Manager Login Utility
IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial
50RISK
open ↗Metasploit300
Tomcat Application Manager Login Utility
The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN acc
50RISK
open ↗Metasploit300
Tomcat Application Manager Login Utility
A Unix account has a default, null, blank, or missing password.
50RISK
open ↗Metasploit300
SNMP Community Login Scanner
An SNMP community name is the default (e.g. public), null, or missing.
33RISK
open ↗Metasploit300
Tomcat Application Manager Login Utility
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a
60RISK
open ↗Metasploit300
MS17-010 SMB RCE Detection
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open ↗Metasploit300
MS17-010 SMB RCE Detection
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open ↗Metasploit300
SSH Username Enumeration
OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations
50RISK
open ↗Metasploit300
MS17-010 SMB RCE Detection
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open ↗Metasploit300
SMB Login Check Scanner
A Windows NT domain user or administrator account has a default, null, blank, or missing password.
23RISK
open ↗Metasploit300
SMB Group Policy Preference Saved Passwords Enumeration
The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windo
98RISK
open ↗Metasploit300
SSH Username Enumeration
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open ↗Metasploit300
MS17-010 SMB RCE Detection
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open ↗Metasploit300
Microsoft Windows Authenticated Logged In Users Enumeration
A Windows NT local user or administrator account has a default, null, blank, or missing password.
50RISK
open ↗Metasploit300
SNMP Community Login Scanner
An account on a router, firewall, or other network device has a default, null, blank, or missing password.
18RISK
open ↗Metasploit300
Sielco Sistemi Winlog Remote File Access
Multiple directory traversal vulnerabilities in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA bef
43RISK
open ↗Metasploit300
Moxa UDP Device Discovery
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 52
48RISK
open ↗Metasploit300
WordPress GI-Media Library Plugin Directory Traversal Vulnerability
GI-Media Library < 3.0 - Directory Traversal
36RISK
open ↗Metasploit300
WordPress DukaPress Plugin File Read Vulnerability
Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2
50RISK
open ↗Metasploit300
Wordpress XML-RPC Username/Password Login Scanner
A Unix account has a default, null, blank, or missing password.
50RISK
open ↗Metasploit300
Wordpress Pingback Locator
The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct
23RISK
open ↗Metasploit300
SSH Username Enumeration
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISK
open ↗Metasploit300
WordPress Brute Force and User Enumeration Utility
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the u
60RISK
open ↗Metasploit300
MS17-010 SMB RCE Detection
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open ↗Metasploit300
VMware Server Directory Traversal Vulnerability
Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on L
60RISK
open ↗Metasploit300
Oracle RDBMS Login Utility
A Unix account has a default, null, blank, or missing password.
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.