Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,003GitHub PoC 13,307VulnCheck XDB 8,182Nuclei 4,217Metasploit 3,462✓ verified onlyrecentpopularrisk
4,202 exploits
Nucleihigh
CyberPower < v2.8.3 - SQL Injection
CyberPower PowerPanel Enterprise SQL Injection
36RISK
open ↗Nucleimedium
D-LINK DNS-320L,DNS-320LW and DNS-327L - Information Disclosure
D-Link DNS-320L/DNS-320LW/DNS-327L HTTP GET Request info.cgi information disclosure
40RISK
open ↗Nucleimedium
Simply Static - Information Disclosure
WordPress Simply Static plugin <= 3.1.3 - Sensitive Data Exposure via Log File vulnerability
36RISK
open ↗Nucleimedium
iTop Hub Connector - Information Disclosure
iTop hub connector Information disclosure
28RISK
open ↗Nucleicritical
Lobe Chat <= v0.150.5 - Server-Side Request Forgery
lobe-chat `/api/proxy` endpoint Server-Side Request Forgery vulnerability
55RISK
open ↗Nucleicritical
Delmia Apriso - Pre-Authentication Unsafe .NET Object Deserialization
Pre-authentication Unsafe .NET object deserialization vulnerability affecting DELMIA Apriso Release 2019 through Release 2024
43RISK
open ↗Nucleimedium
D-LINK DIR-845L bsc_sms_inbox.php file - Information Disclosure
D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.
28RISK
open ↗Nucleihigh
Prison Management System - SQL Injection Authentication Bypass
Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the
56RISK
open ↗Nucleimedium
LumisXP - Cross-site Scripting
A cross-site scripting (XSS) vulnerability in the component XsltResultControllerHtml.jsp of Lumisxp v15.0.x to v16.1.x a
28RISK
open ↗Nucleimedium
User Meta WP Plugin < 3.1 - Sensitive Information Exposure
WordPress User Meta plugin <= 3.0 - Sensitive Data Exposure vulnerability
28RISK
open ↗Nucleihigh
Sharp Multifunction Printers - Directory Listing
Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for th
36RISK
open ↗Nucleimedium
Sharp Multifunction Printers - Cookie Exposure
"sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides log
55RISK
open ↗Nucleimedium
SOPlanning 1.52.00 Cross Site Scripting
SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.
48RISK
open ↗Nucleimedium
iboss Secure Web Gateway - Stored Cross-Site Scripting
iboss Secure Web Gateway Login Portal login cross site scripting
33RISK
open ↗Nucleimedium
OneNav v0.9.35-20240318 - Server-Side Request Forgery (SSRF)
OneNav v0.9.35-20240318 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /index.php?c=ap
28RISK
open ↗Nucleimedium
Masteriyo LMS <= 1.7.3 - Insecure Direct Object Reference
WordPress LMS by Masteriyo plugin <= 1.7.3 - Broken Authentication vulnerability
28RISK
open ↗Nucleicritical
GlobalProtect - OS Command Injection
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open ↗Nucleimedium
Changedetection.io <=v0.45.21 - Cross-Site Scripting
Reflected cross site scripting in changedetection.io
28RISK
open ↗Nucleicritical
D-Tale 3.10.0 - 3.15.1 - Authentication Bypass & Remote Code Execution
Authentication Bypass and RCE in man-group/dtale
85RISK
open ↗Nucleicritical
Adobe Commerce & Magento - CosmicSting
XXE can expose crypt key and other secrets granting full admin access
100RISK
open ↗Nucleihigh
TOTOLINK EX1800T TOTOLINK EX1800T - Command Injection
TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized e
43RISK
open ↗Nucleihigh
Next.js - Server Side Request Forgery (SSRF)
Next.js Server-Side Request Forgery in Server Actions
36RISK
open ↗Nucleihigh
HSC Mailinspector 5.2.17-3 through 5.2.18 - Local File Inclusion
An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability
36RISK
open ↗Nucleimedium
GP Premium <= 2.4.0 - Cross-Site Scripting
GP Premium <= 2.4.0 - Reflected Cross-Site Scripting
28RISK
open ↗Nucleicritical
Wordpress Country State City Dropdown <=2.7.2 - SQL Injection
Country State City Dropdown CF7 <= 2.7.2 - Unauthenticated SQL Injection
68RISK
open ↗Nucleihigh
LyLme-Spage - Arbitary File Upload
An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to exec
43RISK
open ↗Nucleihigh
OpenAPI Generator <= 7.5.0 - Arbitrary File Read/Delete
OpenAPI Generator Online - Arbitrary File Read/Delete
36RISK
open ↗Nucleicritical
Mitel MiCollab <= 9.8.0.33 - SQL Injection
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to cond
75RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.