Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
4,202 exploits
Nucleimedium
Parallels H-Sphere 3.6.1713 - Cross-Site Scripting
Parallels H-Sphere 3.6.1713 allows XSS via the index_en.php from parameter.
18RISK
open
Nucleihigh
Prestashop Blockwishlist 2.1.0 SQL Injection
SQL Injection in prestashop/blockwishlist
61RISK
open
Nucleicritical
Roxy-WI - Remote Code Execution
Unauthenticated Remote Code Execution in Roxy-wi
75RISK
open
Nucleicritical
Roxy-WI < 6.1.1.0 - Remote Code Execution
Unauthenticated Remote Code Execution in Roxy-WI
85RISK
open
Nucleicritical
Roxy-WI - Remote Code Execution
Roxy-WI Vulnerable to Unauthenticated Remote Code Execution via ssl_cert Upload
68RISK
open
Nucleicritical
PrestaShop - SQL Injection to Eval Injection
Remote code execution in prestashop
63RISK
open
Nucleimedium
Frontend File Manager < 21.3 - Unauthenticated File Renaming
Frontend File Manager < 21.3 - Unauthenticated File Renaming
18RISK
open
Nucleimedium
ResourceSpace - Metadata Export
In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collectio
18RISK
open
Nucleihigh
Gitblit 1.9.3 - Local File Inclusion
A Path Traversal vulnerability in Gitblit 1.9.3 can lead to reading website files via /resources//../ (e.g., followed by
23RISK
open
Nucleihigh
Linear eMerge E3-Series - Information Disclosure
Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to o
18RISK
open
Nucleimedium
Haraj 3.7 - Cross-Site Scripting
Haraj v3.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the User Upgrade Form.
18RISK
open
Nucleimedium
SolarView Compact 6.00 - Cross-Site Scripting
SolarView Compact v6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Solar_AiCo
18RISK
open
Nucleihigh
NEX-Forms Plugin < 7.9.7 - SQL Injection
NEX-Forms < 7.9.7 - Authenticated SQLi
43RISK
open
Nucleimedium
Axigen WebMail - Cross-Site Scripting
An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12
50RISK
open
Nucleihigh
BackupBuddy - Local File Inclusion
WordPress BackupBuddy Plugin 8.5.8.0-8.7.4.1 is vulnerable to Directory Traversal
48RISK
open
Nucleicritical
Nortek Linear eMerge E3-Series <0.32-08f - Remote Command Injection
Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via Reade
30RISK
open
Nucleicritical
VMware - Local File Inclusion
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability aff
23RISK
open
Nucleicritical
VMWare Cloud Foundation NSX-V - XML External Entity (XXE)
VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V dep
43RISK
open
Nucleicritical
VMware vRealize Log Insight - Improper Access Control to RCE
The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely
85RISK
open
Nucleicritical
VMware vRealize Log Insight - Path Traversal
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject fi
85RISK
open
Nucleimedium
VMware vRealize Log Insight < v8.10.2 - Information Disclosure
VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sen
53RISK
open
Nucleimedium
Nortek Linear eMerge E3-Series - Cross-Site Scripting
Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation
18RISK
open
Nucleicritical
pfSense pfBlockerNG <=2.1..4_26 - OS Command Injection
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISK
open
Nucleihigh
WAVLINK WN535 G3 - Information Disclosure
A vulnerability in live_check.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router
18RISK
open
Nucleihigh
WAVLINK WN535 G3 - Information Disclosure
A vulnerability in live_mfg.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router in
18RISK
open
Nucleihigh
WAVLINK WN579 X3 M79X3.V5030.180719 - Information Disclosure
A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN579 X3 M79X3.V5030.180719 allows attackers to obtain sensi
18RISK
open
Nucleihigh
Codoforum 5.1 - Arbitrary File Upload
Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin
50RISK
open
Nucleihigh
Online Fire Reporting System v1.0 - SQL injection
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=reports&date=.
18RISK
open
Nucleihigh
Online Fire Reporting System v1.0 - SQL injection
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=user/manage_user&id=.
18RISK
open
Nucleicritical
Online Fire Reporting System v1.0 - SQL injection
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_request.
18RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.