Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,910GitHub PoC 14,997VulnCheck XDB 8,843Nuclei 4,358Metasploit 3,489✓ verified onlyrecentpopularrisk
4,357 exploits
Nucleicritical
PHPGurukul Dairy Farm Shop Management System 1.0 - SQL Injection
PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username paramet
23RISK
open ↗Nucleimedium
Spring Cloud Config - Local File Inclusion
Directory Traversal with spring-cloud-config-server
30RISK
open ↗Nucleihigh
Spring Cloud Config Server - Local File Inclusion
Directory Traversal with spring-cloud-config-server
100RISK
open ↗Nucleimedium
Spring Cloud Netflix - Server-Side Request Forgery
Hystrix Dashboard Proxy In spring-cloud-netflix-hystrix-dashboard
23RISK
open ↗Nucleicritical
Grandstream UCM6200 - SQL Injection
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafte
100RISK
open ↗Nucleihigh
SRS Simple Hits Counter 1.0.3-1.0.4 - Unauthenticated Blind SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SRS Simple Hits Counter Plugin f
18RISK
open ↗Nucleimedium
Canvas LMS v2020-07-29 - Blind Server-Side Request Forgery
Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas appli
18RISK
open ↗Nucleihigh
MAGMI - Cross-Site Request Forgery
Currently, all versions of MAGMI are vulnerable to CSRF due to the lack of CSRF tokens. RCE (via phpcli command) is poss
23RISK
open ↗Nucleicritical
Magento Mass Importer <0.7.24 - Remote Auth Bypass
MAGMI versions prior to 0.7.24 are vulnerable to a remote authentication bypass due to allowing default credentials in t
23RISK
open ↗Nucleicritical
UnRaid <=6.80 - Remote Code Execution
Unraid through 6.8.0 allows Remote Code Execution.
100RISK
open ↗Nucleicritical
F5 BIG-IP TMUI - Remote Code Execution
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open ↗Nucleimedium
CLink Office 2.0 - Cross-Site Scripting
A cross-site scripting (XSS) vulnerability in the index page of the CLink Office 2.0 management console allows remote at
18RISK
open ↗Nucleicritical
SAP Solution Manager 7.2 - Remote Command Execution
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an
100RISK
open ↗Nucleicritical
SAP NetWeaver AS JAVA 7.30-7.50 - Remote Admin Addition
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISK
open ↗Nucleimedium
SAP BusinessObjects Business Intelligence Platform - Blind Server-Side Request Forgery
SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated at
60RISK
open ↗Nucleicritical
OpenSIS 7.3 - SQL Injection
openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.
23RISK
open ↗Nucleimedium
Eclipse Mojarra - Local File Read
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or c
23RISK
open ↗Nucleimedium
WordPress Ultimate FAQ <1.8.30 - Cross-Site Scripting
The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.
18RISK
open ↗Nucleicritical
HPE Smart Update Manager < 8.5.6 - Remote Unauthorized Access
A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access
40RISK
open ↗Nucleicritical
LinuxKI Toolset <= 6.01 - Remote Command Execution
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
60RISK
open ↗Nucleimedium
McAfee ePolicy Orchestrator <5.10.9 Update 9 - Cross-Site Scripting
ePolicy Orchistrator (ePO) - Cross-Site Scripting vulnerability
28RISK
open ↗Nucleicritical
Zimbra Collaboration Suite < 8.8.15 Patch 7 - Server-Side Request Forgery
Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enab
95RISK
open ↗Nucleihigh
Puppet Server/PuppetDB - Sensitive Information Disclosure
Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For Pup
18RISK
open ↗Nucleicritical
Liferay Portal Unauthenticated < 7.2.1 CE GA2 - Remote Code Execution
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open ↗Nucleicritical
Satellian Intellian Aptus Web <= 1.24 - Remote Command Execution
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to th
60RISK
open ↗Nucleimedium
Revive Adserver <=5.0.3 - Cross-Site Scripting
A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver
18RISK
open ↗Nucleihigh
Ruby on Rails <5.0.1 - Remote Code Execution
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the
60RISK
open ↗Nucleimedium
Citrix ADC/Gateway - Cross-Site Scripting
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.1
23RISK
open ↗Nucleimedium
Citrix - Local File Inclusion
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14
100RISK
open ↗Nucleimedium
Citrix ADC and Citrix NetScaler Gateway - Remote Code Injection
Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.