Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,978GitHub PoC 13,282VulnCheck XDB 8,176Nuclei 4,202Metasploit 3,462✓ verified onlyrecentpopularrisk
4,202 exploits
Nucleicritical
Apache Struts 2.0.0-2.5.25 - Remote Code Execution
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open ↗Nucleimedium
Z-Blog <=1.5.2 - Open Redirect
Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect"
18RISK
open ↗Nucleimedium
Memos 0.13.2 - Server-Side Request Forgery
memos vulnerable to an SSRF in /api/resource
28RISK
open ↗Nucleihigh
.NET Framework - Leaking ObjRefs via HTTP .NET Remoting
.NET Framework Information Disclosure Vulnerability
100RISK
open ↗Nucleihigh
WordPress Tourfic Plugin <= 2.11.7 - Cross-Site Scripting
WordPress Tourfic plugin <= 2.11.7 - Reflected Cross Site Scripting (XSS) vulnerability
36RISK
open ↗Nucleimedium
WordPress Restrict User Access <= 2.5 - Cross-Site Scripting
WordPress Restrict User Access plugin <= 2.5 - Reflected Cross Site Scripting (XSS) vulnerability
36RISK
open ↗Nucleihigh
GeoServer Demo Request Endpoint - Server Side Request Forgery
GeoServer Vulnerable to Unauthenticated SSRF via TestWfsPost
36RISK
open ↗Nucleicritical
Telesquare TLR-2005KSH - Remote Command Execution
An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the
56RISK
open ↗Nucleimedium
VvvebJs < 1.7.5 - Arbitrary File Upload
Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute
28RISK
open ↗Nucleihigh
MLflow < 2.11.3 - Path Traversal
Local File Inclusion (LFI) via URI Fragment Parsing in mlflow/mlflow
41RISK
open ↗Nucleimedium
Unlimited Elements for Elementor <= 1.5.93 - Cross Site Scripting
WordPress Unlimited Elements for Elementor plugin <= 1.5.93 - Reflected Cross Site Scripting (XSS) vulnerability
36RISK
open ↗Nucleicritical
Ivanti EPM - Remote Code Execution
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att
100RISK
open ↗Nucleicritical
Apache StreamPipes <= 0.93.0 - Use of Cryptographically Weak PRNG in Recovery Token Generation
Apache StreamPipes, Apache StreamPipes: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Recovery Token Generation
63RISK
open ↗Nucleihigh
GLPI 10.0.10-10.0.14 - SQL Injection
GLPI contains an SQL injection through the saved searches
48RISK
open ↗Nucleicritical
Cacti cmd_realtime.php - Command Injection
Cacti command injection in cmd_realtime.php
85RISK
open ↗Nucleimedium
WP Go Maps <= 9.0.29 - Cross-Site Scripting
WordPress WP Go Maps plugin <= 9.0.29 - Reflected Cross Site Scripting (XSS) vulnerability
36RISK
open ↗Nucleicritical
Zyxel NAS326 Firmware < V5.21(AAZF.17)C0 - NsaRescueAngel Backdoor Account
** UNSUPPORTED WHEN ASSIGNED **
The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326
85RISK
open ↗Nucleicritical
Zyxel NAS326 Firmware < V5.21(AAZF.17)C0 - Command Injection
** UNSUPPORTED WHEN ASSIGNED **
The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RISK
open ↗Nucleicritical
IPS Community Suite - Unauthenticated SQL Injection
Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\
43RISK
open ↗Nucleihigh
Apache DolphinScheduler >= 3.1.0, < 3.2.2 Resource File Read And Write
Apache DolphinScheduler: Resource File Read And Write Vulnerability
36RISK
open ↗Nucleimedium
Sunshine Photo Cart <= 3.1.1 - Reflected Cross-Site Scripting
WordPress Sunshine Photo Cart plugin <= 3.1.1 - Reflected Cross Site Scripting (XSS) vulnerability
36RISK
open ↗Nucleimedium
DataEase <= 2.4.1 - Sensitive Information Exposure
DataEase has database configuration information exposure vulnerability
53RISK
open ↗Nucleimedium
WordPress Themify Builder < 7.5.8 - Open Redirect
Themify Builder < 7.5.8 - Open Redirect
28RISK
open ↗Nucleimedium
WPZOOM Social Icons Widget <= 4.2.15 - Missing Authorization
WordPress Social Icons Widget & Block by WPZOOM plugin <= 4.2.15 - Broken Access Control vulnerability
28RISK
open ↗Nucleicritical
ProfileGrid <= 5.7.8 - SQL Injection
WordPress ProfileGrid plugin <= 5.7.8 - SQL Injection vulnerability
43RISK
open ↗Nucleicritical
CRM Perks Forms <= 1.1.4 - SQL Injection
WordPress CRM Perks Forms plugin <= 1.1.4 - Unauthenticated SQL Injection vulnerability
43RISK
open ↗Nucleicritical
WP Travel Engine <= 5.7.9 - SQL Injection
WordPress WP Travel Engine plugin <= 5.7.9 - Unauth. Blind SQL Injection vulnerability
43RISK
open ↗Nucleicritical
Netgear R6850 V1.1.0.88 - Command Injection
Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter.
55RISK
open ↗Nucleihigh
Netgear R6850 - Information Disclosure
An information leak in currentsetting.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information wi
36RISK
open ↗Nucleimedium
Netgear R6850 - Information Disclosure
An information leak in debuginfo.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.