Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
4,201 exploits
Nucleicritical
Intelbras NPLUG 1.0.0.14 - Authentication Bypass
Intelbras NPLUG 1.0.0.14 wireless repeater devices have a critical vulnerability that allows an attacker to authenticate
18RISK
open
Nucleihigh
PhpMyAdmin <4.8.2 - Local File Inclusion
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open
Nucleicritical
CirCarLife Scada <4.3 - System Log Exposure
CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/lo
50RISK
open
Nucleimedium
SV3C HD Camera L Series - Open Redirect
The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) does not perform origin
18RISK
open
Nucleimedium
Spring MVC Framework - Local File Inclusion
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow app
30RISK
open
Nucleicritical
Spring Data Commons - Remote Code Execution
CVE-2018-1273CRITICALunder attackransomware
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RISK
open
Nucleihigh
Webgrind <= 1.5 - Local File Inclusion
Webgrind 1.5 relies on user input to display a file, which lets anyone view files from the local filesystem (that the we
23RISK
open
Nucleimedium
Zoho manageengine - Cross-Site Scripting
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network
40RISK
open
Nucleimedium
TOTOLINK A3002RU 1.0.8 - Information Disclosure
Password disclosure in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to obtain the plaintext password
18RISK
open
Nucleihigh
Apache Tika < 1.1.8 - Header Command Injection
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISK
open
Nucleicritical
Fortinet FortiOS - Credentials Disclosure
CVE-2018-13379CRITICALunder attackransomware
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open
Nucleimedium
Fortinet FortiOS - Cross-Site Scripting
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 to 5.4.12, 5.2 and
40RISK
open
Nucleimedium
Zeta Producer Desktop CMS <14.2.1 - Local File Inclusion
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclos
38RISK
open
Nucleimedium
Synacor Zimbra Collaboration Suite Collaboration <8.8.11 - Cross-Site Scripting
Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients.
18RISK
open
Nucleicritical
VelotiSmart Wifi - Directory Traversal
The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../..
50RISK
open
Nucleimedium
Orange Forum 1.4.0 - Open Redirect
views/auth.go in Orange Forum 1.4.0 allows Open Redirection via the next parameter to /login or /signup.
18RISK
open
Nucleimedium
Django - Open Redirect
django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.
23RISK
open
Nucleicritical
Responsive filemanager 9.13.1 Server-Side Request Forgery
upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.
60RISK
open
Nucleihigh
cgit < 1.2.1 - Directory Traversal
cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned
60RISK
open
Nucleicritical
WordPress Payeezy Pay <=2.97 - Local File Inclusion
The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay
18RISK
open
Nucleihigh
SAP Internet Graphics Server (IGS) - XML External Entity Injection
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML Exter
50RISK
open
Nucleicritical
osCommerce 2.3.4.1 - Remote Code Execution
osCommerce 2.3.4.1 Installer Unauthenticated Configuration File Injection PHP Code Execution
63RISK
open
Nucleihigh
Oracle Fusion Middleware WebCenter Sites - Cross-Site Scripting
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported
50RISK
open
Nucleicritical
Oracle WebLogic Server - Remote Code Execution
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Su
50RISK
open
Nucleimedium
Oracle E-Business Suite - Blind SSRF
Vulnerability in the Application Management Pack for Oracle E-Business Suite component of Oracle E-Business Suite (subco
23RISK
open
Nucleimedium
Oracle Fusion Middleware WebCenter Sites 11.1.1.8.0 - Cross-Site Scripting
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The suppo
18RISK
open
Nucleimedium
node-srv - Local File Inclusion
node-srv node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malici
18RISK
open
Nucleihigh
Ruby On Rails - Local File Inclusion
There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12
43RISK
open
Nucleicritical
Oturia WordPress Smart Google Code Inserter <3.5 - Authentication Bypass
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RISK
open
Nucleimedium
Atlassian Jira Confluence - Cross-Site Scripting
The issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0
30RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.