Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,432cataloged exploits
34,424CVEs with public exploitation
24,695lab-tested
4,217 exploits
Nucleimedium
Cloudron 6.2 Cross-Site Scripting
In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.
38RISK
open
Nucleicritical
Aviatrix Controller 6.x before 6.5-1804.1922 - Remote Command Execution
CVE-2021-40870CRITICALunder attack
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous
100RISK
open
Nucleihigh
Gurock TestRail Application files.md5 Exposure
Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat ac
50RISK
open
Nucleicritical
Galera WebTemplate 1.0 Directory Traversal
Galera WebTemplate 1.0 is affected by a directory traversal vulnerability that could reveal information from /etc/passwd
18RISK
open
Nucleimedium
Spotweb <= 1.5.1 - Cross Site Scripting
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote
18RISK
open
Nucleimedium
Spotweb <= 1.5.1 - Cross Site Scripting (Reflected)
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote
18RISK
open
Nucleimedium
Spotweb <= 1.5.1 - Cross Site Scripting
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote
18RISK
open
Nucleimedium
Spotweb <= 1.5.1 - Cross Site Scripting
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote
18RISK
open
Nucleimedium
Spotweb <= 1.5.1 - Cross Site Scripting
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote
18RISK
open
Nucleimedium
Spotweb <= 1.5.1 - Cross Site Scripting
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote
18RISK
open
Nucleihigh
MKdocs 1.2.2 - Directory Traversal
The mkdocs 1.2.2 built-in dev-server allows directory traversal using the port 8000, enabling remote exploitation to obt
23RISK
open
Nucleihigh
Aurelia-Path < 1.1.7 - Prototype Pollution
Prototype pollution in aurelia-path
43RISK
open
Nucleimedium
Grafana 8.0.0 <= v.8.2.2 - Angularjs Rendering Cross-Site Scripting
XSS vulnerability allowing arbitrary JavaScript execution
50RISK
open
Nucleimedium
Redash Setup Configuration - Default Secrets Disclosure
Insecure default configuration
36RISK
open
Nucleicritical
MinIO Operator Console Authentication Bypass
Authentication bypass issue in the Operator Console
48RISK
open
Nucleihigh
Metabase - Local File Inclusion
CVE-2021-41277CRITICALunder attack
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RISK
open
Nucleihigh
pfSense - Arbitrary File Write
diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data abo
40RISK
open
Nucleihigh
ECOA Building Automation System - Directory Traversal Content Disclosure
ECOA BAS controller - Path Traversal-1
58RISK
open
Nucleihigh
ECOA Building Automation System - Arbitrary File Retrieval
ECOA BAS controller - Path Traversal-3
41RISK
open
Nucleimedium
Microsoft Exchange Server Pre-Auth POST Based Cross-Site Scripting
Microsoft Exchange Server Spoofing Vulnerability
70RISK
open
Nucleihigh
Payara Micro Community 5.2021.6 Directory Traversal
Payara Micro Community 5.2021.6 and below allows Directory Traversal.
50RISK
open
Nucleicritical
QVIS NVR/DVR - Remote Code Execution
QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization.
18RISK
open
Nucleimedium
FlatPress 1.2.1 - Stored Cross-Site Scripting
A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaS
18RISK
open
Nucleihigh
ECShop 4.1.0 - SQL Injection
ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.
18RISK
open
Nucleimedium
JustWriting - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in application/controllers/dropbox.php in JustWriting 1.0.0 and below allow rem
18RISK
open
Nucleihigh
SAS/Internet 9.4 1520 - Local File Inclusion
SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the app
18RISK
open
Nucleihigh
PuneethReddyHC action.php SQL Injection
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId
23RISK
open
Nucleicritical
PuneethReddyHC Online Shopping System homeaction.php SQL Injection
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php c
30RISK
open
Nucleicritical
TP-Link - OS Command Injection
The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to r
60RISK
open
Nucleihigh
openSIS Student Information System 8.0 SQL Injection
A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TR
43RISK
open
previouspage 121 / 141next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.