Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,832GitHub PoC 14,991VulnCheck XDB 8,829Nuclei 4,357Metasploit 3,489✓ verified onlyrecentpopularrisk
4,357 exploits
Nucleihigh
Zimbra Collaboration Suite - SSRF
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x b
100RISK
open ↗Nucleihigh
ESAFENET CDG - Arbitrary File Download
ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because t
30RISK
open ↗Nucleicritical
Synacor Zimbra Collaboration <8.7.11p10 - XML External Entity Injection
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RISK
open ↗Nucleihigh
Homematic CCU3 - Local File Inclusion
Directory Traversal / Arbitrary File Read in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to read
23RISK
open ↗Nucleicritical
JFrog Artifactory 6.7.3 - Admin Login Bypass
An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password o
30RISK
open ↗Nucleihigh
LabKey Server 19.1.0 - XML External Entity (XXE)
An issue was discovered in LabKey Server 19.1.0. Sending an SVG containing an XXE payload to the endpoint visualization-
30RISK
open ↗Nucleicritical
PHPSHE 1.7 - SQL Injection
A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnera
18RISK
open ↗Nucleicritical
Sitecore Experience Platform - Deserialization of Untrusted Data
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 an
95RISK
open ↗Nucleicritical
WPGraphQL 0.2.3 - User Creation
The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever
50RISK
open ↗Nucleicritical
WPEngine WPGraphQL 0.2.3 - Unauthenticated User Information Disclosure
An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible,
50RISK
open ↗Nucleimedium
WPEngine WPGraphQL 0.2.3 - Unauthenticated Comment Posting
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on
43RISK
open ↗Nucleimedium
WP Google Maps < 7.10.43 - Cross-Site Scripting
The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO.
18RISK
open ↗Nucleimedium
GetSimple CMS 3.3.13 - Open Redirect
GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.
18RISK
open ↗Nucleihigh
Joomla! Harmis Messenger 1.2.2 - Local File Inclusion
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Directory Traversal allows read access t
33RISK
open ↗Nucleimedium
Zyxel - Cross-Site Scripting
On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, U
43RISK
open ↗Nucleimedium
WordPress Social Warfare <3.5.3 - Cross-Site Scripting
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open ↗Nucleihigh
Microsoft SQL Server Reporting Services - Remote Code Execution
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RISK
open ↗Nucleicritical
SolarWinds Orion API - Auth Bypass
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
100RISK
open ↗Nucleicritical
ManageEngine Desktop Central Java Deserialization
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted d
100RISK
open ↗Nucleihigh
Sonatype Nexus Repository Manager 3 - Remote Code Execution
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open ↗Nucleihigh
Sonatype Nexus Repository Manager 3 - Remote Code Execution
Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.
30RISK
open ↗Nucleicritical
rConfig 3.9 - SQL Injection
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RISK
open ↗Nucleihigh
rConfig <= 3.9.4 - Authenticated OS Command Injection
lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands vi
100RISK
open ↗Nucleicritical
ThemeREX Addons - Remote Code Execution
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST
43RISK
open ↗Nucleicritical
WatchGuard Fireware AD Helper Component - Credentials Disclosure
The AD Helper component in WatchGuard Fireware before 5.8.5.10317 allows remote attackers to discover cleartext password
18RISK
open ↗Nucleicritical
rConfig 3.9.4 - SQL Injection
rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, n
40RISK
open ↗Nucleicritical
rConfig 3.9.4 - SQL Injection
rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by defa
30RISK
open ↗Nucleicritical
rConfig 3.9.4 - SQL Injection
rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passw
30RISK
open ↗Nucleicritical
rConfig <=3.9.4 - SQL Injection
rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' pass
30RISK
open ↗Nucleimedium
Keycloak <= 12.0.1 - request_uri Blind Server-Side Request Forgery (SSRF)
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.