Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
3,462 exploits
Metasploit300
DNS Amplification Scanner
The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Serve
30RISK
open
Metasploit300
PetitPotam
CVE-2021-36942HIGHunder attackransomware
Windows LSA Spoofing Vulnerability
98RISK
open
Metasploit300
DB2 Authentication Brute Force Utility
A Unix account has a default, null, blank, or missing password.
50RISK
open
Metasploit300
CouchDB Enum Utility
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RISK
open
Metasploit300
Novell eDirectory eMBox Unauthenticated File Access
The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on clien
50RISK
open
Metasploit300
ManageEngine ADAudit Plus Xnode Enumeration
Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode
40RISK
open
Metasploit300
ManageEngine DataSecurity Plus Xnode Enumeration
Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode
40RISK
open
Metasploit300
Energizer DUO Trojan Scanner
UsbCharger.dll in the Energizer DUO USB battery charger software contains a backdoor that is implemented through the Aru
43RISK
open
Metasploit300
Novell eDirectory DHOST Predictable Session Cookie
The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote att
50RISK
open
Metasploit300
Apple Airport ACPP Authentication Scanner
The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fi
23RISK
open
Metasploit300
Xymon Daemon Gather Information
xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files
23RISK
open
Metasploit300
NETGEAR Administrator Password Disclosure
CVE-2017-5521HIGHunder attack
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R
100RISK
open
Metasploit300
Peplink Balance routers SQLi
SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw
50RISK
open
Metasploit300
Diagnostics Agent in Solution Manager, stores unencrypted credentials for Solution Manager server
Diagnostics Agent in Solution Manager, version 7.2, stores several credentials such as SLD user connection as well as So
18RISK
open
Metasploit300
Bypass the macOS TCC Framework
CVE-2020-9934MEDIUMunder attack
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue
78RISK
open
Metasploit300
Ruby On Rails File Content Disclosure ('doubletap')
CVE-2019-5418HIGHunder attack
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
Metasploit300
Active Directory Certificate Services (ADCS) privilege escalation (Certifried)
CVE-2022-26923HIGHunder attack
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISK
open
Metasploit300
Twonky Server Log Leak Authentication Bypass
Unauthenticated log access in Twonky Server
75RISK
open
Metasploit300
Windows Pulse Secure Connect Client Saved Password Extractor
Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settin
23RISK
open
Metasploit300
Windows Gather TeamViewer Passwords
CVE-2019-18988HIGHunder attack
TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for dif
86RISK
open
Metasploit300
Netlogon Weak Cryptographic Authentication
CVE-2020-1472MEDIUMunder attackransomware
Netlogon Elevation of Privilege Vulnerability
100RISK
open
Metasploit300
Twonky Server Log Leak Authentication Bypass
Hard-coded encryption keys in Twonky Server
36RISK
open
Metasploit300
Veritas Backup Exec Server Registry Access
VERITAS Backup Exec Server (beserver.exe) 9.0 through 10.0 for Windows allows remote unauthenticated attackers to modify
30RISK
open
Metasploit300
Veritas Backup Exec Windows Remote File Access
VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for
60RISK
open
Metasploit300
Android Browser RCE Through Google Play Store XFO
The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribu
23RISK
open
Metasploit300
Windows Gather Forensics Duqu Registry Check
CVE-2011-3402HIGHunder attack
Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Wind
88RISK
open
Metasploit300
Tomcat Application Manager Login Utility
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a
60RISK
open
Metasploit300
SolarWinds Serv-U Unauthenticated Arbitrary File Read
CVE-2024-28995HIGHunder attack
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISK
open
Metasploit300
Samba read_nttrans_ea_list Integer Overflow
Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.
50RISK
open
Metasploit300
Apache Tomcat User Enumeration
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, al
60RISK
open
previouspage 115 / 116next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.