Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,003GitHub PoC 13,307VulnCheck XDB 8,182Nuclei 4,217Metasploit 3,462✓ verified onlyrecentpopularrisk
4,202 exploits
Nucleihigh
Netgear RAX43 1.0.3.96 - Command Injection/Authentication Bypass Buffer Overrun
Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable
18RISK
open ↗Nucleimedium
Keycloak 10.0.0 - 18.0.0 - Cross-Site Scripting
A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.
30RISK
open ↗Nucleicritical
Acmailer - Improper Access Control to OS Command Injection
Improper access control vulnerability in acmailer ver. 4.0.1 and earlier, and acmailer DB ver. 1.1.3 and earlier allows
18RISK
open ↗Nucleimedium
WordPress Quiz and Survey Master <7.1.14 - Cross-Site Scripting
Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject
18RISK
open ↗Nucleicritical
MovableType - Remote Command Injection
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISK
open ↗Nucleimedium
Adobe ColdFusion - Cross-Site Scripting
ColdFusion Improper neutralization of web input during page generation could lead to arbitrary JavaScript execution in the browser
40RISK
open ↗Nucleihigh
MinIO Browser API - Server-Side Request Forgery
Server-Side Request Forgery in MinIO Browser API
41RISK
open ↗Nucleihigh
Node.JS System Information Library <5.3.1 - Remote Command Injection
Command Injection Vulnerability
100RISK
open ↗Nucleihigh
WordPress Modern Events Calendar Lite <5.16.5 - Authenticated Arbitrary File Upload
Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE
60RISK
open ↗Nucleihigh
WordPress Modern Events Calendar Lite <5.16.5 - Sensitive Information Disclosure
Modern Events Calendar Lite < 5.16.5 - Unauthenticated Events Export
50RISK
open ↗Nucleihigh
WordPress Like Button Rating <2.6.32 - Server-Side Request Forgery
Like Button Rating < 2.6.32 - Unauthenticated Full-Read SSRF
18RISK
open ↗Nucleihigh
WordPress BackupGuard <1.6.0 - Authenticated Arbitrary File Upload
Backup Guard < 1.6.0 - Authenticated Arbitrary File Upload
60RISK
open ↗Nucleimedium
WordPress Ninja Forms <3.4.34 - Open Redirect
Ninja Forms < 3.4.34 - Administrator Open Redirect
18RISK
open ↗Nucleimedium
WordPress Advanced Order Export For WooCommerce <3.1.8 - Authenticated Cross-Site Scripting
Advanced Order Export For WooCommerce < 3.1.8 - Reflected Cross-Site Scripting (XSS)
43RISK
open ↗Nucleihigh
User Profile Picture < 2.5.0 - Sensitive Information Disclosure
User Profile Picture < 2.5.0 - Sensitive Information Disclosure
18RISK
open ↗Nucleicritical
The Plus Addons for Elementor Page Builder < 4.1.7 - Authentication Bypass
The Plus Addons for Elementor Page Builder < 4.1.7 - Authentication Bypass
23RISK
open ↗Nucleimedium
WordPress JH 404 Logger <=1.1 - Cross-Site Scripting
JH 404 Logger <= 1.1 - Unauthenticated Stored Cross-Site Scripting (XSS)
18RISK
open ↗Nucleimedium
WordPress PhastPress <1.111 - Open Redirect
PhastPress < 1.111 - Open Redirect
18RISK
open ↗Nucleicritical
WooCommerce Help Scout - Arbitrary File Upload
WooCommerce Help Scout < 2.9.1 - Unauthenticated Arbitrary File Upload leading to RCE
18RISK
open ↗Nucleimedium
GiveWP <= 2.9.7 - Cross-Site Scripting
GiveWP < 2.10.0 - Reflected Cross Site Scripting (XSS)
18RISK
open ↗Nucleimedium
WordPress OpenID Connect Generic Client 3.8.0-3.8.1 - Cross-Site Scripting
OpenID Connect Generic Client 3.8.0-3.8.1 - Reflected Cross Site Scripting (XSS) via Login Error
18RISK
open ↗Nucleicritical
Controlled Admin Access WordPress Plugin <= 1.4.0 - Improper Access Control & Privilege Escalation
Controlled Admin Access < 1.5.2 - Improper Access Control & Privilege Escalation
18RISK
open ↗Nucleimedium
All Thrive Themes and Plugins - Unauthenticated Option Update
All Thrive Themes and Plugins - Unauthenticated Option Update
18RISK
open ↗Nucleicritical
Multiple Thrive Themes < 2.0.0 - Arbitrary File Upload
All Thrive Themes Legacy Themes < 2.0.0 - Unauthenticated Arbitrary File Upload and Option Deletion
18RISK
open ↗Nucleihigh
AccessAlly <3.5.7 - Sensitive Information Leakage
AccessAlly < 3.5.7 - $_SERVER Superglobal Leakage
18RISK
open ↗Nucleihigh
Patreon WordPress <1.7.0 - Unauthenticated Local File Inclusion
Patreon WordPress < 1.7.0 - Unauthenticated Local File Disclosure
18RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.