Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,978GitHub PoC 13,282VulnCheck XDB 8,176Nuclei 4,202Metasploit 3,462✓ verified onlyrecentpopularrisk
4,202 exploits
Nucleicritical
PSW Front-end Login & Registration 1.13 - Weak Password Recovery
WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerability
68RISK
open ↗Nucleimedium
Label Studio < 1.18.0 - Reflected XSS
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
36RISK
open ↗Nucleicritical
Wing FTP Server <= 7.4.3 - Remote Code Execution
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open ↗Nucleimedium
Wing FTP Server <= 7.4.3 - Path Disclosure via Overlong UID Cookie
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a
70RISK
open ↗Nucleicritical
Invision Community <=5.0.6 Unauthenticated RCE via Template Injection
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The
85RISK
open ↗Nucleicritical
WordPress Formality Plugin <= 1.5.9 - Local File Inclusion
WordPress Formality <= 1.5.9 - Local File Inclusion Vulnerability
36RISK
open ↗Nucleicritical
MyStyle Custom Product Designer <= 3.21.1 - SQL Injection
WordPress MyStyle Custom Product Designer plugin <= 3.21.1 - SQL Injection Vulnerability
43RISK
open ↗Nucleicritical
CWP (Control Web Panel) < 0.9.8.1205 - Remote Code Execution
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
100RISK
open ↗Nucleicritical
vBulletin 5.0.0-6.0.3 - Authentication Bypass
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RISK
open ↗Nucleicritical
vBulletin replaceAdTemplate - Remote Code Execution
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the t
75RISK
open ↗Nucleihigh
Discourse OAuth Social Login - Cross-site Scripting
Discourse vulnerable to XSS via user-provided query parameter in oauth failure flow
36RISK
open ↗Nucleicritical
DataEase < 2.10.10 - JWT Authentication Bypass
Dataease Authentication Bypass Vulnerability
41RISK
open ↗Nucleihigh
DataEase - Remote Code Execution
Dataease H2 Database Remote Code Execution (RCE) Bypass Vulnerability
48RISK
open ↗Nucleihigh
WordPress Custom Login And Signup Widget Plugin <= 1.0 - Arbitrary Code Execution
WordPress Custom Login And Signup Widget plugin <= 1.0 - Arbitrary Code Execution vulnerability
63RISK
open ↗Nucleicritical
Roundcube Webmail - Remote Code Execution
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open ↗Nucleicritical
Pterodactyl Panel - Remote Code Execution
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open ↗Nucleicritical
Akamai CloudTest < 60 2025.06.02 - XML External Entity (XXE)
Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.
48RISK
open ↗Nucleicritical
Adobe Experience Manager Forms - Insecure Deserialization
Adobe Experience Manager (MS) | Deserialization of Untrusted Data (CWE-502)
55RISK
open ↗Nucleicritical
MCP Inspector < 0.14.0 UnauthenticatedRemote Code Execution
MCP Inspector proxy server lacks authentication between the Inspector client and proxy
75RISK
open ↗Nucleimedium
Microsoft SharePoint Server - Authentication Bypass
Microsoft SharePoint Server Spoofing Vulnerability
100RISK
open ↗Nucleicritical
Teleport - Authentication Bypass
Teleport allows remote authentication bypass
43RISK
open ↗Nucleimedium
Heimdall - Host Header Injection & Open Redirect
LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically
43RISK
open ↗Nucleicritical
Dassault Systèmes DELMIA Apriso (up to 2025) - Insecure Deserialization
Deserialization of Untrusted Data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025
95RISK
open ↗Nucleihigh
Letta Letta 0.7.12 - Remote Code Execution
Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows rem
56RISK
open ↗Nucleihigh
React Server Components - Denial of Service
A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 1
68RISK
open ↗Nucleicritical
ArgoCD Project API Token Repository Credentials Exposure
Argo CD: Project API Token Exposes Repository Credentials
43RISK
open ↗Nucleimedium
Astro - Unauthorized Third-Party Image Access
Unauthorized third-party images in Astro’s _image endpoint
28RISK
open ↗Nucleihigh
Agent-Zero 0.8.0 - 0.9.4 - Arbitrary File Download
An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to execute a directory tr
23RISK
open ↗Nucleihigh
XWiki Platform - Information Disclosure
XWiki Platform's configuration files can be accessed through the webjars API
43RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.