Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,760cataloged exploits
32,083CVEs with public exploitation
1,932lab-tested
4,193 exploits
Nucleicritical
Cisco HyperFlex HX Data Platform - Remote Command Execution
CVE-2021-1498CRITICALunder attack
Cisco HyperFlex HX Command Injection Vulnerabilities
100RISK
open
Nucleimedium
Cisco HyperFlex HX Data Platform - Arbitrary File Upload
Cisco HyperFlex HX Data Platform File Upload Vulnerability
50RISK
open
Nucleicritical
SonicWall Email Security <= 10.0.9.x - Unauthenticated Admin Account Creation
CVE-2021-20021CRITICALunder attackransomware
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account
100RISK
open
Nucleimedium
SonicWall SonicOS 7.0 - Open Redirect
A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management
43RISK
open
Nucleicritical
SonicWall SMA100 Stack - Buffer Overflow/Remote Code Execution
CVE-2021-20038CRITICALunder attackransomware
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows
100RISK
open
Nucleihigh
Odoo Apps - Cross-Site Scripting via Prototype Pollution
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-bbq 1.2.1 allows a m
18RISK
open
Nucleicritical
Buffalo WSR-2533DHPL2 - Path Traversal
CVE-2021-20090CRITICALunder attack
A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3
95RISK
open
Nucleihigh
Buffalo WSR-2533DHPL2 - Configuration File Injection
The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not pr
18RISK
open
Nucleihigh
Buffalo WSR-2533DHPL2 - Improper Access Control
The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not pr
18RISK
open
Nucleihigh
TCExam <= 14.8.1 - Sensitive Information Exposure
When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the
18RISK
open
Nucleihigh
Draytek VigorConnect 1.6.0-B - Local File Inclusion
CVE-2021-20123HIGHunder attack
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the D
88RISK
open
Nucleihigh
Draytek VigorConnect 6.0-B3 - Local File Inclusion
CVE-2021-20124HIGHunder attack
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the W
78RISK
open
Nucleimedium
Gryphon Tower - Cross-Site Scripting
A reflected cross-site scripting vulnerability exists in the url parameter of the /cgi-bin/luci/site_access/ page on the
18RISK
open
Nucleimedium
Trendnet AC2600 TEW-827DRU - Credentials Disclosure
Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses information via redirection from the setup wizard. Authe
30RISK
open
Nucleicritical
Trendnet AC2600 TEW-827DRU 2.08B01 - Admin Password Change
Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauth
23RISK
open
Nucleihigh
Netgear RAX43 1.0.3.96 - Command Injection/Authentication Bypass Buffer Overrun
Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable
18RISK
open
Nucleimedium
Keycloak 10.0.0 - 18.0.0 - Cross-Site Scripting
A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.
30RISK
open
Nucleicritical
Acmailer - Improper Access Control to OS Command Injection
Improper access control vulnerability in acmailer ver. 4.0.1 and earlier, and acmailer DB ver. 1.1.3 and earlier allows
18RISK
open
Nucleimedium
WordPress Quiz and Survey Master <7.1.14 - Cross-Site Scripting
Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject
18RISK
open
Nucleicritical
MovableType - Remote Command Injection
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISK
open
Nucleimedium
Adobe ColdFusion - Cross-Site Scripting
ColdFusion Improper neutralization of web input during page generation could lead to arbitrary JavaScript execution in the browser
40RISK
open
Nucleihigh
Spring Boot Actuator Logview Directory Traversal
Directory Traversal
61RISK
open
Nucleihigh
OneDev < 4.0.3 - User Access Token Leak
Pre-Auth Access token leak
48RISK
open
Nucleihigh
MinIO Browser API - Server-Side Request Forgery
Server-Side Request Forgery in MinIO Browser API
41RISK
open
Nucleicritical
Lucee Admin - Remote Code Execution
Remote Code Exploit in Lucee Admin
78RISK
open
Nucleihigh
Adminer <4.7.9 - Server-Side Request Forgery
CVE-2021-21311HIGHunder attack
SSRF in adminer
100RISK
open
Nucleihigh
Node.JS System Information Library <5.3.1 - Remote Command Injection
CVE-2021-21315HIGHunder attack
Command Injection Vulnerability
100RISK
open
Nucleimedium
WordPress Mediumish Theme <=1.0.47 - Cross-Site Scripting
Mediumish <= 1.0.47 - Unauthenticated Reflected Cross-Site Scripting (XSS)
18RISK
open
Nucleimedium
WordPress Bello Directory & Listing Theme <1.6.0 - Cross-Site Scripting
Bello < 1.6.0 - Unauthenticated Reflected XSS & XFS
23RISK
open
Nucleimedium
WordPress Car Repair Services & Auto Mechanic Theme <4.0 - Cross-Site Scripting
Car Repair Services < 4.0 - Unauthenticated Reflected XSS & XFS
18RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.