Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
4,217 exploits
Nucleicritical
rConfig 3.9.2 - Remote Code Execution
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RISK
open
Nucleicritical
vBulletin 5.0.0-5.5.4 - Remote Command Execution
CVE-2019-16759CRITICALunder attack
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISK
open
Nucleicritical
D-Link Routers - Remote Code Execution
CVE-2019-16920CRITICALunder attack
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The i
100RISK
open
Nucleimedium
WordPress Visualizer <3.3.1 - Cross-Site Scripting
A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute ar
18RISK
open
Nucleicritical
Visualizer <3.3.1 - Blind Server-Side Request Forgery
A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-d
30RISK
open
Nucleihigh
Metinfo 7.0.0 beta - SQL Injection
In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/product/admin/product_admin.class.php via the admin/?
23RISK
open
Nucleihigh
Metinfo 7.0.0 beta - SQL Injection
In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/language/admin/language_general.class.php via the adm
30RISK
open
Nucleimedium
Motors Car Dealer & Classified Ads <= 1.4.0 - Unauthenticated settings import/export
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin
18RISK
open
Nucleimedium
WordPress OneTone theme <= 3.0.6 – Unauthenticated Options Changes
includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress allows unauthenticated options changes.
18RISK
open
Nucleimedium
WordPress OneTone theme <= 3.0.6 – Unauthenticated Stored XSS
includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress has multiple stored XSS issues.
18RISK
open
Nucleihigh
WordPress Ultimate FAQs <= 1.8.24 – Unauthenticated Options Import and Export
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options im
18RISK
open
Nucleimedium
WordPress Ultimate FAQs <= 1.8.24 – Unauthenticated HTML Content Injection
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.
18RISK
open
Nucleicritical
Yachtcontrol Webapplication 1.0 - Remote Command Injection
Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user vi
30RISK
open
Nucleicritical
Zabbix <=4.4 - Authentication Bypass
An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass
30RISK
open
Nucleihigh
MetInfo 7.0.0 beta - SQL Injection
An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=language&c=language_general&a=doSearchPa
30RISK
open
Nucleicritical
Jfrog Artifactory <6.17.0 - Default Admin Password
JFrog Artifactory does not enforce default admin password change
55RISK
open
Nucleimedium
Kirona Dynamic Resource Scheduler - Information Disclosure
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REG
50RISK
open
Nucleicritical
D-Link DIR-868L/817LW - Information Disclosure
There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 route
30RISK
open
Nucleihigh
Jiangnan Online Judge 0.8.0 - Local File Inclusion
Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file reading via the web/polygon/problem/viewfile?id=
23RISK
open
Nucleimedium
Oracle Fusion Middleware WebCenter Sites 12.2.1.3.0 - SQL Injection
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The suppo
18RISK
open
Nucleimedium
Oracle Business Intelligence - Path Traversal
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publi
50RISK
open
Nucleihigh
Oracle Business Intelligence/XML Publisher - XML External Entity Injection
CVE-2019-2616HIGHunder attack
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publi
100RISK
open
Nucleicritical
Oracle WebLogic Server - Remote Command Execution
CVE-2019-2725HIGHunder attackransomware
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
Nucleicritical
Oracle WebLogic Server Administration Console - Remote Code Execution
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
85RISK
open
Nucleihigh
Oracle Business Intelligence Publisher - XML External Entity Injection
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publi
18RISK
open
Nucleicritical
Atlassian Confluence Server - Path Traversal
CVE-2019-3396CRITICALunder attackransomware
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
Nucleihigh
Atlassian Confluence Download Attachments - Remote Code Execution
CVE-2019-3398HIGHunder attack
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
100RISK
open
Nucleimedium
Atlassian Jira <7.13.3/8.0.0-8.1.1 - Incorrect Authorization
The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote
23RISK
open
Nucleimedium
Jira < 8.1.1 - Cross-Site Scripting
The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows
18RISK
open
Nucleimedium
Jira - Incorrect Authorization
The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and fr
30RISK
open
previouspage 123 / 141next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.