Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
4,357 exploits
Nucleihigh
Zimbra Collaboration Suite - SSRF
CVE-2019-9621HIGHunder attack
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x b
100RISK
open
Nucleihigh
ESAFENET CDG - Arbitrary File Download
ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because t
30RISK
open
Nucleicritical
Synacor Zimbra Collaboration <8.7.11p10 - XML External Entity Injection
CVE-2019-9670CRITICALunder attack
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RISK
open
Nucleihigh
Homematic CCU3 - Local File Inclusion
Directory Traversal / Arbitrary File Read in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to read
23RISK
open
Nucleicritical
JFrog Artifactory 6.7.3 - Admin Login Bypass
An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password o
30RISK
open
Nucleihigh
LabKey Server 19.1.0 - XML External Entity (XXE)
An issue was discovered in LabKey Server 19.1.0. Sending an SVG containing an XXE payload to the endpoint visualization-
30RISK
open
Nucleicritical
PHPSHE 1.7 - SQL Injection
A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnera
18RISK
open
Nucleicritical
Sitecore Experience Platform - Deserialization of Untrusted Data
CVE-2019-9874CRITICALunder attack
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 an
95RISK
open
Nucleicritical
WPGraphQL 0.2.3 - User Creation
The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever
50RISK
open
Nucleicritical
WPEngine WPGraphQL 0.2.3 - Unauthenticated User Information Disclosure
An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible,
50RISK
open
Nucleimedium
WPEngine WPGraphQL 0.2.3 - Unauthenticated Comment Posting
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on
43RISK
open
Nucleimedium
WP Google Maps < 7.10.43 - Cross-Site Scripting
The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO.
18RISK
open
Nucleimedium
GetSimple CMS 3.3.13 - Open Redirect
GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.
18RISK
open
Nucleihigh
Joomla! Harmis Messenger 1.2.2 - Local File Inclusion
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Directory Traversal allows read access t
33RISK
open
Nucleimedium
Zyxel - Cross-Site Scripting
On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, U
43RISK
open
Nucleimedium
WordPress Social Warfare <3.5.3 - Cross-Site Scripting
CVE-2019-9978MEDIUMunder attack
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
Nucleihigh
Microsoft SQL Server Reporting Services - Remote Code Execution
CVE-2020-0618CRITICALunder attackransomware
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RISK
open
Nucleicritical
SolarWinds Orion API - Auth Bypass
CVE-2020-10148CRITICALunder attack
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
100RISK
open
Nucleicritical
ManageEngine Desktop Central Java Deserialization
CVE-2020-10189CRITICALunder attack
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted d
100RISK
open
Nucleihigh
Sonatype Nexus Repository Manager 3 - Remote Code Execution
CVE-2020-10199HIGHunder attack
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open
Nucleihigh
Sonatype Nexus Repository Manager 3 - Remote Code Execution
Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.
30RISK
open
Nucleicritical
rConfig 3.9 - SQL Injection
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RISK
open
Nucleihigh
rConfig <= 3.9.4 - Authenticated OS Command Injection
CVE-2020-10221HIGHunder attack
lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands vi
100RISK
open
Nucleicritical
ThemeREX Addons - Remote Code Execution
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST
43RISK
open
Nucleicritical
WatchGuard Fireware AD Helper Component - Credentials Disclosure
The AD Helper component in WatchGuard Fireware before 5.8.5.10317 allows remote attackers to discover cleartext password
18RISK
open
Nucleicritical
rConfig 3.9.4 - SQL Injection
rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, n
40RISK
open
Nucleicritical
rConfig 3.9.4 - SQL Injection
rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by defa
30RISK
open
Nucleicritical
rConfig 3.9.4 - SQL Injection
rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passw
30RISK
open
Nucleicritical
rConfig <=3.9.4 - SQL Injection
rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' pass
30RISK
open
Nucleimedium
Keycloak <= 12.0.1 - request_uri Blind Server-Side Request Forgery (SSRF)
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using
50RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.