Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
4,201 exploits
Nucleimedium
OPNsense - Cross-Site Scripting
A cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense Community Edition
18RISK
open
Nucleicritical
OPNsense - Cross-Site Scripting to RCE
/ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 al
18RISK
open
Nucleihigh
FileMage Gateway - Directory Traversal
Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker t
43RISK
open
Nucleihigh
rConfig 3.9.4 - Server-Side Request Forgery
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_b parameter in the doDiff Fun
18RISK
open
Nucleihigh
rConfig 3.9.4 - Server-Side Request Forgery
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_a parameter in the doDiff Fun
18RISK
open
Nucleihigh
rConfig 3.9.4 - Server-Side Request Forgery
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPa
18RISK
open
Nucleihigh
Emlog 2.1.9 - SQL Injection
emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.
18RISK
open
Nucleihigh
Aria2 WebUI - Path traversal
webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.
18RISK
open
Nucleicritical
PaperCut < 22.1.3 - Path Traversal
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete
85RISK
open
Nucleimedium
Blog2Social < 7.2.1 - Cross-Site Scripting
Blog2Social < 7.2.1 - Reflected XSS
28RISK
open
Nucleicritical
Cacti 1.2.24 - SQL Injection
Unauthenticated SQL Injection in graph_view.php in Cacti
85RISK
open
Nucleicritical
ECTouch v2 - SQL Injection
ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\inse
18RISK
open
Nucleimedium
IceWarp Email Client - Cross Site Scripting
Cross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 allows a remote attacker to execute arbitra
18RISK
open
Nucleimedium
EyouCms v1.6.2 - Cross-Site Scripting
EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/t
18RISK
open
Nucleimedium
JFinalCMS v5.0.0 - Directory Traversal
An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traver
23RISK
open
Nucleimedium
Emlog Pro v2.1.14 - Cross-Site Scripting
A Cross Site Scripting (XSS) vulnerability was discovered in Emlog Pro v2.1.14 via the component /admin/store.php.
18RISK
open
Nucleimedium
RealGimm by GruppoSCAI v1.1.37p38 - Cross-Site Scripting
Multiple reflected cross-site scripting (XSS) vulnerabilities in the ErroreNonGestito.aspx component of GruppoSCAI RealG
18RISK
open
Nucleihigh
Adlisting Classified Ads 2.14.0 - Information Disclosure
Templatecookie Adlisting Redirect ad-list information disclosure
60RISK
open
Nucleihigh
Ruijie RG-EW1200G Router - Password Reset
Ruijie RG-EW1200G Administrator Password set_passwd access control
40RISK
open
Nucleimedium
mooSocial 3.1.8 - Reflected XSS
mooSocial mooStore index cross site scripting
43RISK
open
Nucleimedium
mooSocial 3.1.6 - Reflected Cross Site Scripting
mooSocial mooStore cross site scripting
43RISK
open
Nucleimedium
Skype for Business 2019 (SfB) - Blind Server-side Request Forgery
CVE-2023-41763MEDIUMunder attack
Skype for Business Elevation of Privilege Vulnerability
80RISK
open
Nucleicritical
CraftCMS < 4.4.15 - Unauthenticated Remote Code Execution
Craft CMS Remote Code Execution vulnerability
85RISK
open
Nucleihigh
ProfilePress <= 4.13.1 — Unauthenticated Privilege Escalation
WordPress ProfilePress plugin <= 4.13.1 - Unauthenticated Limited Privilege Escalation vulnerability
36RISK
open
Nucleimedium
Chamilo LMS <= 1.11.24 - Remote Code Execution
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
Nucleimedium
OpenCMS - Cross-Site Scripting
A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type.
28RISK
open
Nucleihigh
OpenCMS - XML external entity (XXE)
Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/
56RISK
open
Nucleimedium
JumpServer > 3.6.4 - Information Disclosure
JumpServer session replays download without authentication
48RISK
open
Nucleicritical
JetBrains TeamCity < 2023.05.4 - Remote Code Execution
CVE-2023-42793CRITICALunder attackransomware
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
Nucleihigh
WordPress Post Timeline Plugin < 2.2.6 - Cross-Site Scripting
Post Timeline < 2.2.6 - Reflected XSS
18RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.