Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
4,217 exploits
Nucleihigh
BOA Web Server 0.94.14 - Arbitrary File Access
/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read
50RISK
open
Nucleicritical
PHPUnit - Remote Code Execution
CVE-2017-9841CRITICALunder attack
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
Nucleimedium
Schneider Electric Pelco VideoXpert Enterprise 2.0 - Path Traversal
An exposure of sensitive information vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2
18RISK
open
Nucleicritical
Cisco RV132W/RV134W Router - Information Disclosure
A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VP
40RISK
open
Nucleihigh
Cisco ASA - Local File Inclusion
CVE-2018-0296HIGHunder attack
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RISK
open
Nucleimedium
Jolokia 1.3.7 - Cross-Site Scripting
An XSS vulnerability exists in the Jolokia agent version 1.3.7 in the HTTP servlet that allows an attacker to execute ma
23RISK
open
Nucleihigh
Jolokia Agent - JNDI Code Injection
A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to
40RISK
open
Nucleicritical
Cobbler - Authentication Bypass
Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibl
23RISK
open
Nucleicritical
GitList < 0.6.0 Remote Code Execution
klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in
40RISK
open
Nucleihigh
Jenkins GitHub Plugin <=1.29.1 - Server-Side Request Forgery
A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCrede
40RISK
open
Nucleimedium
Sympa version =>6.2.16 - Cross-Site Scripting
sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in
18RISK
open
Nucleimedium
DomainMOD 4.11.01 - Cross-Site Scripting
DomainMOD version 4.09.03 and above. Also verified in the latest version 4.11.01 contains a Cross Site Scripting (XSS) v
18RISK
open
Nucleicritical
Jenkins - Remote Command Injection
CVE-2018-1000861CRITICALunder attack
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea
100RISK
open
Nucleicritical
XiongMai uc-httpd 1.0.0 - Buffer Overflow
Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE
50RISK
open
Nucleihigh
AudioCodes 420HD - Remote Code Execution
AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution.
50RISK
open
Nucleimedium
Dolibarr <7.0.2 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Dolibarr before 7.0.2 allows remote attackers to inject arbitrary web script
40RISK
open
Nucleimedium
Palo Alto Networks PAN-OS GlobalProtect <8.1.4 - Cross-Site Scripting
GlobalProtect Portal Login page in Palo Alto Networks PAN-OS before 8.1.4 allows an unauthenticated attacker to inject a
18RISK
open
Nucleihigh
Webgrind <= 1.5 - Local File Inclusion
Webgrind 1.5 relies on user input to display a file, which lets anyone view files from the local filesystem (that the we
23RISK
open
Nucleimedium
Zoho manageengine - Cross-Site Scripting
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network
40RISK
open
Nucleimedium
TOTOLINK A3002RU 1.0.8 - Information Disclosure
Password disclosure in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to obtain the plaintext password
18RISK
open
Nucleihigh
Apache Tika < 1.1.8 - Header Command Injection
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISK
open
Nucleicritical
Fortinet FortiOS - Credentials Disclosure
CVE-2018-13379CRITICALunder attackransomware
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open
Nucleimedium
Fortinet FortiOS - Cross-Site Scripting
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 to 5.4.12, 5.2 and
40RISK
open
Nucleimedium
Zeta Producer Desktop CMS <14.2.1 - Local File Inclusion
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclos
38RISK
open
Nucleimedium
Synacor Zimbra Collaboration Suite Collaboration <8.8.11 - Cross-Site Scripting
Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients.
18RISK
open
Nucleicritical
VelotiSmart Wifi - Directory Traversal
The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../..
50RISK
open
Nucleimedium
Orange Forum 1.4.0 - Open Redirect
views/auth.go in Orange Forum 1.4.0 allows Open Redirection via the next parameter to /login or /signup.
18RISK
open
Nucleimedium
Django - Open Redirect
django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.
23RISK
open
Nucleicritical
Responsive filemanager 9.13.1 Server-Side Request Forgery
upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.
60RISK
open
Nucleihigh
cgit < 1.2.1 - Directory Traversal
cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned
60RISK
open
previouspage 100 / 141next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.