Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
24,460 exploits
Exploit-DB
CMSUno 1.6.2 - 'lang' Remote Code Execution (Authenticated)
CVE-2020-25538webappsphp28 Jan 2021
An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and r
23RISK
open
Exploit-DB
Metasploit Framework 6.0.11 - msfvenom APK template command injection
CVE-2020-7384HIGHlocalmultiple28 Jan 2021
Client-Side Command Injection in Rapid7 Metasploit
68RISK
open
Exploit-DB
Fuel CMS 1.4.1 - Remote Code Execution (2)
CVE-2018-16763webappsphp28 Jan 2021
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
Exploit-DB
Tenda AC5 AC1200 Wireless - 'WiFi Name & Password' Stored Cross Site Scripting
CVE-2021-3186webappshardware26 Jan 2021
A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_m
23RISK
open
Exploit-DB
Oracle WebLogic Server 12.2.1.0 - RCE (Unauthenticated)
CVE-2020-14882CRITICALunder attackwebappsjava26 Jan 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
Exploit-DBVexDay Proof
Klog Server 2.4.1 - Unauthenticated Command Injection (Metasploit)
CVE-2020-35729webappsphp25 Jan 2021
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
60RISK
open
Exploit-DB
Atlassian Confluence Widget Connector Macro - SSTI
CVE-2019-3396CRITICALunder attackransomwarewebappsmultiple22 Jan 2021
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
Exploit-DB
Oracle WebLogic Server 14.1.1.0 - RCE (Authenticated)
CVE-2021-2109HIGHwebappsjava22 Jan 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
63RISK
open
Exploit-DB
Anchor CMS 0.12.7 - CSRF (Delete user)
CVE-2020-23342webappsmultiple21 Jan 2021
A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.
28RISK
open
Exploit-DBVexDay Proof
Wordpress Plugin Simple Job Board 2.9.3 - Authenticated File Read (Metasploit)
CVE-2020-35749webappsphp21 Jan 2021
Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2
50RISK
open
Exploit-DB
osTicket 1.14.2 - SSRF
CVE-2020-24881webappsphp19 Jan 2021
SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
60RISK
open
Exploit-DB
Laravel 8.4.2 debug mode - Remote code execution
CVE-2021-3129CRITICALunder attackransomwarewebappsphp14 Jan 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
Exploit-DB
Nagios XI 5.7.X - Remote Code Execution RCE (Authenticated)
CVE-2020-35578webappsphp14 Jan 2021
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature
60RISK
open
Exploit-DBVexDay Proof
Apache Flink 1.11.0 - Unauthenticated Arbitrary File Read (Metasploit)
CVE-2020-17519CRITICALunder attackwebappsjava08 Jan 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
Exploit-DBVexDay Proof
Gitea 1.7.5 - Remote Code Execution
CVE-2019-11229webappsmultiple06 Jan 2021
models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to rem
35RISK
open
Exploit-DBVexDay Proof
Sonatype Nexus 3.21.1 - Remote Code Execution (Authenticated)
CVE-2020-10199HIGHunder attackwebappsjava06 Jan 2021
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open
Exploit-DB
IPeakCMS 3.5 - Boolean-based blind SQLi
CVE-2021-3018webappsmultiple06 Jan 2021
ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the
43RISK
open
Exploit-DBVexDay Proof
PaperStream IP (TWAIN) 1.42.0.5685 - Local Privilege Escalation
CVE-2018-16156localwindows06 Jan 2021
In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes u
23RISK
open
Exploit-DBVexDay Proof
Klog Server 2.4.1 - Command Injection (Unauthenticated)
CVE-2020-35729webappsphp05 Jan 2021
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
60RISK
open
Exploit-DB
IncomCMS 2.0 - Insecure File Upload
CVE-2020-29597webappsmultiple05 Jan 2021
IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows un
60RISK
open
Exploit-DB
Fluentd TD-agent plugin 4.0.1 - Insecure Folder Permission
CVE-2020-28169localwindows05 Jan 2021
The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory
23RISK
open
Exploit-DB
Advanced Comment System 1.0 - 'ACS_path' Path Traversal
CVE-2020-35598webappsphp04 Jan 2021
ACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=.
43RISK
open
Exploit-DB
Subrion CMS 4.2.1 - 'avatar[path]' XSS
CVE-2020-35437webappsphp04 Jan 2021
Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the
23RISK
open
Exploit-DB
Mantis Bug Tracker 2.24.3 - 'access' SQL Injection
CVE-2020-28413MEDIUMwebappsphp04 Jan 2021
In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the A
33RISK
open
Exploit-DB
Wordpress Core 5.2.2 - 'post previews' XSS
CVE-2019-16223webappsphp04 Jan 2021
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
23RISK
open
Exploit-DB
GitLab 11.4.7 - RCE (Authenticated) (2)
CVE-2018-19571webappsruby24 Dec 2020
GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an
28RISK
open
Exploit-DB
GitLab 11.4.7 - RCE (Authenticated) (2)
CVE-2018-19585webappsruby24 Dec 2020
GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection
28RISK
open
Exploit-DB
Flexmonster Pivot Table & Charts 2.7.17 - 'To OLAP' Reflected XSS
CVE-2020-20141webappsmultiple21 Dec 2020
Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Tab
23RISK
open
Exploit-DB
Flexmonster Pivot Table & Charts 2.7.17 - 'Remote Report' Reflected XSS
CVE-2020-20140webappsmultiple21 Dec 2020
Cross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Cha
23RISK
open
Exploit-DB
Flexmonster Pivot Table & Charts 2.7.17 - 'Remote JSON' Reflected XSS
CVE-2020-20139webappsmultiple21 Dec 2020
Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.