Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
4,202 exploits
Nucleihigh
SAS/Internet 9.4 1520 - Local File Inclusion
SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the app
18RISK
open
Nucleihigh
PuneethReddyHC action.php SQL Injection
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId
23RISK
open
Nucleicritical
PuneethReddyHC Online Shopping System homeaction.php SQL Injection
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php c
30RISK
open
Nucleicritical
TP-Link - OS Command Injection
The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to r
60RISK
open
Nucleihigh
openSIS Student Information System 8.0 SQL Injection
A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TR
43RISK
open
Nucleicritical
CraftCMS SEOmatic - Server-Side Template Injection
In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Si
23RISK
open
Nucleihigh
D-Link DAP-1620 - Local File Inclusion
Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd]
50RISK
open
Nucleimedium
Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site Scripting
ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads t
43RISK
open
Nucleihigh
Franklin Fueling Systems Colibri Controller Module 1.8.19.8580 - Local File Inclusion
Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privilege
50RISK
open
Nucleihigh
Telesquare TLR-2855KS6 - Arbitrary File Creation
An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.
43RISK
open
Nucleicritical
Telesquare TLR-2855KS6 - Arbitrary File Deletion
An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system fil
60RISK
open
Nucleicritical
SDT-CW3B1 1.1.0 - OS Command Injection
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RISK
open
Nucleicritical
Telesquare TLR-2005KSH 1.0.0 - Arbitrary File Delete
Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to de
50RISK
open
Nucleicritical
GenieACS => 1.2.8 - OS Command Injection
In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping
23RISK
open
Nucleimedium
Keystone 6 Login Page - Open Redirect and Cross-Site Scripting
Cross-site Scripting (XSS) - Reflected in keystonejs/keystone
36RISK
open
Nucleimedium
WordPress Visual Form Builder <3.0.8 - Information Disclosure
Visual Form Builder < 3.0.6 - Unauthenticated Information Disclosure
18RISK
open
Nucleimedium
WordPress Cookie Information/Free GDPR Consent Solution <2.0.8 - Cross-Site Scripting
Cookie Information < 2.0.8 - Reflected Cross-Site Scripting
18RISK
open
Nucleimedium
WordPress All-in-one Floating Contact Form <2.0.4 - Cross-Site Scripting
All-in-one Floating Contact Form < 2.0.4 - Authenticated Reflected Cross-Site Scripting (XSS)
18RISK
open
Nucleimedium
WooCommerce Stored Exporter WordPress Plugin < 2.7.1 - Cross-Site Scripting
WooCommerce – Store Exporter < 2.7.1 - Reflected Cross-Site Scripting (XSS)
18RISK
open
Nucleimedium
WordPress Accessibility Helper <0.6.0.7 - Cross-Site Scripting
WP Accessibility Helper (WAH) < 0.6.0.7 - Reflected Cross-Site Scripting (XSS)
18RISK
open
Nucleimedium
WordPress Page Builder KingComposer <=2.9.6 - Open Redirect
Page Builder KingComposer <= 2.9.6 - Open Redirect
18RISK
open
Nucleicritical
Photo Gallery by 10Web < 1.6.0 - SQL Injection
Photo Gallery by 10Web < 1.6.0 - Unauthenticated SQL Injection
60RISK
open
Nucleimedium
CMP WordPress < 4.0.19 - Broken Access Control
Coming Soon & Maintenance Plugin by NiteoThemes < 4.0.19 - Unauthenticated Arbitrary CSS Update
18RISK
open
Nucleimedium
WordPress RSS Aggregator < 4.20 - Authenticated Cross-Site Scripting
WP RSS Aggregator < 4.20 - Reflected Cross-Site Scripting (XSS)
18RISK
open
Nucleimedium
WordPress Permalink Manager <2.2.15 - Cross-Site Scripting
Permalink Manager < 2.2.15 - Reflected Cross-Site Scripting
18RISK
open
Nucleimedium
WordPress NewStatPress <1.3.6 - Cross-Site Scripting
NewStatPress < 1.3.6 - Reflected Cross-Site Scripting
18RISK
open
Nucleimedium
WordPress Plugin MapPress <2.73.4 - Cross-Site Scripting
MapPress Maps for WordPress < 2.73.4 - Reflected Cross-Site scripting
18RISK
open
Nucleimedium
WordPress Spider Calendar <=1.5.65 - Cross-Site Scripting
SpiderCalendar <= 1.5.65 - Reflected Cross-Site Scripting
18RISK
open
Nucleimedium
HTML Email Template Designer < 3.1 - Missing Authorization on Rest Route
WP HTML Mail <= 3.0.9 Missing Authorization on REST-API Route
58RISK
open
Nucleimedium
WordPress GDPR & CCPA <1.9.27 - Cross-Site Scripting
WordPress GDPR & CCPA < 1.9.27 - Unauthenticated Reflected Cross-Site Scripting
18RISK
open
previouspage 102 / 141next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.