Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
4,202 exploits
Nucleimedium
Pure-FTPd 1.0.24 - Security Vulnerability
An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function i
18RISK
open
Nucleihigh
Veritas Backup Exec - Broken Authentication
CVE-2021-27877HIGHunder attackransomware
An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authenticat
98RISK
open
Nucleihigh
vsftpd < 3.0.3 - DoS
VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.
18RISK
open
Nucleicritical
NCR Command Center Agent 16.3 - Remote Command Execution
CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (wit
40RISK
open
Nucleihigh
CUPS - Remote Code Execution
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open
Nucleimedium
Citrix NetScaler ADC & Gateway - Reflected XSS / Open Redirect
Cross-Site Scripting (XSS)
33RISK
open
Nucleihigh
MongoDB Server - Information Disclosure (MongoBleed)
CVE-2025-14847HIGHunder attack
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
Nucleicritical
Redis < 8.2.1 lua script - Integer Overflow
Lua library commands may lead to integer overflow and potential RCE
36RISK
open
Nucleihigh
Redis Lua Sandbox < 8.2.2 - Cross-User Escape
Redis: Authenticated users can execute LUA scripts as a different user
28RISK
open
Nucleihigh
Redis < 8.2.1 Lua Long-String Delimiter - Out-of-Bounds Read
Redis is vulnerable to DoS via specially crafted LUA scripts
28RISK
open
Nucleicritical
Redis Lua Parser < 8.2.2 - Use After Free
Redis Lua Use-After-Free may lead to remote code execution
85RISK
open
Nucleicritical
Palo Alto Networks PAN-OS - Authentication Bypass
CVE-2026-0257HIGHunder attackransomware
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
100RISK
open
Nucleicritical
SonicWall SMA1000 - Server-Side Request Forgery
CVE-2026-15409CRITICALunder attack
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
98RISK
open
Nucleicritical
BeyondTrust Remote Support - Unauthenticated WebSocket RCE
CVE-2026-1731CRITICALunder attackransomware
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
100RISK
open
Nucleicritical
Apache Camel camel-coap - Remote Code Execution
Apache Camel: CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code Execution
63RISK
open
Nucleihigh
Vite Dev Server - Arbitrary File Read
Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket
36RISK
open
Nucleicritical
Marimo <= 0.20.4 - Pre-Auth Terminal WebSocket RCE
CVE-2026-39987CRITICALunder attack
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISK
open
Nucleihigh
Next.js WebSocket Upgrade Handler - SSRF
Next.js: Server-side request forgery in applications using WebSocket upgrades
68RISK
open
Nucleicritical
Samba Printing Subsystem - Remote Code Execution
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISK
open
Nucleicritical
WordPress Fusion Builder <3.6.2 - Server-Side Request Forgery
Fusion Builder < 3.6.2 - Unauthenticated SSRF
60RISK
open
Nucleicritical
F5 BIG-IP iControl - REST Auth Bypass RCE
CVE-2022-1388CRITICALunder attackransomware
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
Nucleicritical
WordPress Admin Word Count Column 2.2 - Local File Inclusion
Admin Word Count Column <= 2.2 - Unauthenticated Arbitrary File Read
23RISK
open
Nucleicritical
WordPress Cab fare calculator < 1.0.4 - Local File Inclusion
Cab fare calculator < 1.0.4 - Unauthenticated LFI
23RISK
open
Nucleihigh
WordPress Videos sync PDF <=1.7.4 - Local File Inclusion
Videos sync PDF <= 1.7.4 - Unauthenticated LFI
23RISK
open
Nucleimedium
External Media without Import <=1.1.2 - Authenticated Blind Server-Side Request Forgery
External Media without Import <= 1.1.2 - Subscriber+ Blind SSRF
18RISK
open
Nucleimedium
Microweber <1.2.15 - Cross-Site Scripting
Reflected XSS on demo.microweber.org/demo/module/ in microweber/microweber
28RISK
open
Nucleihigh
WordPress Metform <=2.1.3 - Information Disclosure
Metform Elementor Contact Form Builder <= 2.1.3 - Sensitive Information Disclosure
36RISK
open
Nucleicritical
RSVPMaker <= 9.2.5 - SQL Injection
RSVPMaker <= 9.2.5 - Unauthenticated SQL Injection
43RISK
open
Nucleicritical
WordPress HTML2WP <=1.0.0 - Arbitrary File Upload
HTML2WP <= 1.0.0 - Unauthenticated Arbitrary File Upload
23RISK
open
Nucleimedium
Site Offline WP Plugin < 1.5.3 - Authorization Bypass
Site Offline < 1.5.3 - Access Bypass
18RISK
open
previouspage 108 / 141next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.