Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,978GitHub PoC 13,282VulnCheck XDB 8,176Nuclei 4,202Metasploit 3,462✓ verified onlyrecentpopularrisk
4,202 exploits
Nucleicritical
Inspur ClusterEngine 4.0 - Remote Code Execution
A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. A remote attacker can send a maliciou
30RISK
open ↗Nucleimedium
Jenkin Audit Trail <=3.2 - Cross-Site Scripting
Jenkins Audit Trail Plugin 3.2 and earlier does not escape the error message for the URL Patterns field form validation,
40RISK
open ↗Nucleimedium
HomeAutomation 3.3.2 - Open Redirect
In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified befor
18RISK
open ↗Nucleihigh
PHPGurukul Hospital Management System 4.0 - SQL Injection
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unaut
18RISK
open ↗Nucleicritical
74cms - ajax_street.php 'x' SQL Injection
SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.
18RISK
open ↗Nucleicritical
74cms - ajax_common.php SQL Injection
SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php.
18RISK
open ↗Nucleicritical
74cms - ajax_officebuilding.php SQL Injection
SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.
18RISK
open ↗Nucleicritical
74cms - ajax_street.php 'key' SQL Injection
SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.
18RISK
open ↗Nucleimedium
b2evolution CMS <6.11.6 - Open Redirect
Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redi
23RISK
open ↗Nucleimedium
OPNsense <=20.1.5 - Open Redirect
An open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not fil
18RISK
open ↗Nucleimedium
Aryanic HighMail (High CMS) - Cross-Site Scripting
Cross Site Scripting (XSS) vulnerability in Aryanic HighMail (High CMS) versions 2020 and before allows remote attackers
18RISK
open ↗Nucleihigh
Kyocera Printer d-COPIA253MF - Directory Traversal
A directory traversal vulnerability exists in Kyocera Printer d-COPIA253MF plus. Successful exploitation of this vulnera
30RISK
open ↗Nucleimedium
Monstra CMS 3.0.4 - Cross-Site Scripting
Cross Site Scripting vulnerabilty in Monstra CMS 3.0.4 via the page feature in admin/index.php.
18RISK
open ↗Nucleimedium
XXL-JOB v2.2.0 — Stored Cross Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in xxl-job v2.2.0 allow remote attackers to inject arbitrary web scr
18RISK
open ↗Nucleihigh
Joomla! Component GMapFP 3.5 - Arbitrary File Upload
In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating
50RISK
open ↗Nucleicritical
Import XML & RSS Feeds WordPress Plugin <= 2.0.1 Server-Side Request Forgery
Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the
23RISK
open ↗Nucleicritical
WordPress wpDiscuz <=7.0.4 - Remote Code Execution
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RISK
open ↗Nucleimedium
Mara CMS 7.5 - Cross-Site Scripting
Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters.
43RISK
open ↗Nucleihigh
INTELBRAS TELEFONE IP TIP200 60.61.75.22 - Local File Inclusion
INTELBRAS TELEFONE IP TIP200 version 60.61.75.22 allows an attacker to obtain sensitive information through /cgi-bin/cgi
18RISK
open ↗Nucleihigh
WordPress Plugin File Manager (wp-file-manager) Backup Disclosure
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htacce
23RISK
open ↗Nucleicritical
Mongo-Express - Remote Code Execution
mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this m
40RISK
open ↗Nucleimedium
EpiServer Find <13.2.7 - Open Redirect
An Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted website
18RISK
open ↗Nucleicritical
Wordpress Quiz and Survey Master <7.0.1 - Arbitrary File Deletion
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbit
65RISK
open ↗Nucleimedium
Rukovoditel <= 2.7.2 - Cross Site Scripting
A stored cross site scripting (XSS) vulnerability in the 'Users Alerts' feature of Rukovoditel 2.7.2 allows authenticate
18RISK
open ↗Nucleimedium
Rukovoditel <= 2.7.2 - Cross Site Scripting
A stored cross site scripting (XSS) vulnerability in the 'Global Lists" feature of Rukovoditel 2.7.2 allows authenticate
18RISK
open ↗Nucleimedium
Rukovoditel <= 2.7.2 - Cross Site Scripting
A stored cross site scripting (XSS) vulnerability in the 'Users Access Groups' feature of Rukovoditel 2.7.2 allows authe
18RISK
open ↗Nucleimedium
Rukovoditel <= 2.7.2 - Cross-Site Scripting
A stored cross site scripting (XSS) vulnerability in the 'Entities List' feature of Rukovoditel 2.7.2 allows authenticat
18RISK
open ↗Nucleicritical
CSE Bookstore 1.0 - SQL Injection
CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pub
23RISK
open ↗Nucleicritical
Ultimate Member < 2.1.12 - Unauthenticated Privilege Escalation via User Meta
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalat
43RISK
open ↗Nucleimedium
Jira Server and Data Center - Information Disclosure
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Infor
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.