Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,978GitHub PoC 13,282VulnCheck XDB 8,176Nuclei 4,202Metasploit 3,462✓ verified onlyrecentpopularrisk
4,202 exploits
Nucleilow
Mailcow < 2026-03b - Href Link Injection
mailcow-dockerized Login Page has Reflected Parameter Injection / Wrong-Context XSS Escaping
23RISK
open ↗Nucleicritical
Vendure Core - SQL Injection
@vendure/core has a SQL Injection vulnerability
43RISK
open ↗Nucleihigh
HT Mega < 3.0.7 - Sensitive Information Disclosure
HT Mega < 3.0.7 – Unauthenticated PII Disclosure
48RISK
open ↗Nucleicritical
Rclone RC - Broken Access Control
Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution
55RISK
open ↗Nucleicritical
RClone RC - Command Injection
RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
63RISK
open ↗Nucleicritical
Dgraph <= 25.3.2 - Admin Token Disclosure
Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars in Dgraph
43RISK
open ↗Nucleihigh
NocoBase - SQL Injection
NocoBase Vulnerable to SQL Injection via String Concatenation in Recursive Eager Loading
36RISK
open ↗Nucleihigh
NocoBase - SQL Injection
NocoBase Vulnerable to SQL Validation Bypass via `sqlCollection:update` Missing `checkSQL` Call
36RISK
open ↗Nucleicritical
cPanel & WHM - Authentication Bypass via Session-File CRLF Injection
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open ↗Nucleihigh
CKAN DataStore SQL Search - SQL Injection
CKAN: Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
36RISK
open ↗Nucleicritical
LiteLLM - SQL Injection
LiteLLM: SQL injection in Proxy API key verification
100RISK
open ↗Nucleicritical
LiteLLM - Command Injection
LiteLLM: Authenticated command execution via MCP stdio test endpoints
100RISK
open ↗Nucleicritical
MagicMirror <= 2.35.0 - Server-Side Request Forgery
MagicMirror²: Unauthenticated SSRF via /cors endpoint
43RISK
open ↗Nucleicritical
phpVMS < 7.0.6 - Legacy Importer Authorization Bypass
phpvms: /importer authorization bypass causing full database wipe
43RISK
open ↗Nucleicritical
WordPress Contact Form by Supsystic - Server-Side Template Injection
Contact Form by Supsystic <= 1.7.36 - Unauthenticated Server-Side Template Injection via Prefill Functionality
75RISK
open ↗Nucleicritical
Gotenberg - Command Injection
Gotenberg: Unauthenticated RCE via ExifTool Metadata Key Injection
63RISK
open ↗Nucleicritical
JoomSport <= 5.7.7 - SQL Injection
WordPress JoomSport plugin <= 5.7.7 - SQL Injection vulnerability
63RISK
open ↗Nucleicritical
Scramble Laravel - Remote Code Execution
Scramble: Remote code execution via evaluation of user-controlled input in validation rules
63RISK
open ↗Nucleicritical
Open WebUI 'LDAP Empty Password' - Authentication Bypass
Open WebUI: LDAP Empty Password Authentication Bypass
43RISK
open ↗Nucleihigh
Dozzle - Server Side Request Forgery
Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy)
36RISK
open ↗Nucleimedium
Open WebUI < 0.9.5 - Information Disclosure
Open WebUI: Unauthenticated RAG Configuration Disclosure
28RISK
open ↗Nucleicritical
Cockpit Web Console < 360 - Remote Code Execution
Cockpit: cockpit: unauthenticated remote code execution due to ssh command-line argument injection
68RISK
open ↗Nucleicritical
9Router <= 0.4.36 - Unauthenticated RCE
9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
43RISK
open ↗Nucleicritical
phpMyFAQ <= 4.1.1 - SQL Injection
phpMyFAQ - SQL Injection via User-Agent Header in BuiltinCaptcha
43RISK
open ↗Nucleihigh
SillyTavern - Server-Side Request Forgery
SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl
36RISK
open ↗Nucleicritical
Flowise < 3.1.2 - node-custom-function Unauthorized RCE
Flowise: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape
63RISK
open ↗Nucleicritical
TYPO3 ceselector Extension - Insecure Deserialization
Remote Code Execution in extension "Content Element Selector" (ceselector)
43RISK
open ↗Nucleicritical
Google ADK-Python - Unauthenticated Builder Endpoint
Remote Code Execution in Google Agent Development Kit (ADK)
43RISK
open ↗Nucleicritical
Adobe ColdFusion - RDS Arbitrary File Write
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
68RISK
open ↗Nucleihigh
ColdFusion - Path Traversal
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
43RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.