Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
4,202 exploits
Nucleihigh
Netgear RAX43 1.0.3.96 - Command Injection/Authentication Bypass Buffer Overrun
Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable
18RISK
open
Nucleimedium
Keycloak 10.0.0 - 18.0.0 - Cross-Site Scripting
A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.
30RISK
open
Nucleicritical
Acmailer - Improper Access Control to OS Command Injection
Improper access control vulnerability in acmailer ver. 4.0.1 and earlier, and acmailer DB ver. 1.1.3 and earlier allows
18RISK
open
Nucleimedium
WordPress Quiz and Survey Master <7.1.14 - Cross-Site Scripting
Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject
18RISK
open
Nucleicritical
MovableType - Remote Command Injection
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISK
open
Nucleimedium
Adobe ColdFusion - Cross-Site Scripting
ColdFusion Improper neutralization of web input during page generation could lead to arbitrary JavaScript execution in the browser
40RISK
open
Nucleihigh
Spring Boot Actuator Logview Directory Traversal
Directory Traversal
61RISK
open
Nucleihigh
OneDev < 4.0.3 - User Access Token Leak
Pre-Auth Access token leak
48RISK
open
Nucleihigh
MinIO Browser API - Server-Side Request Forgery
Server-Side Request Forgery in MinIO Browser API
41RISK
open
Nucleicritical
Lucee Admin - Remote Code Execution
Remote Code Exploit in Lucee Admin
78RISK
open
Nucleihigh
Adminer <4.7.9 - Server-Side Request Forgery
CVE-2021-21311HIGHunder attack
SSRF in adminer
100RISK
open
Nucleihigh
Node.JS System Information Library <5.3.1 - Remote Command Injection
CVE-2021-21315HIGHunder attack
Command Injection Vulnerability
100RISK
open
Nucleihigh
WordPress Modern Events Calendar Lite <5.16.5 - Authenticated Arbitrary File Upload
Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE
60RISK
open
Nucleihigh
WordPress Modern Events Calendar Lite <5.16.5 - Sensitive Information Disclosure
Modern Events Calendar Lite < 5.16.5 - Unauthenticated Events Export
50RISK
open
Nucleihigh
WordPress Like Button Rating <2.6.32 - Server-Side Request Forgery
Like Button Rating < 2.6.32 - Unauthenticated Full-Read SSRF
18RISK
open
Nucleihigh
WordPress BackupGuard <1.6.0 - Authenticated Arbitrary File Upload
Backup Guard < 1.6.0 - Authenticated Arbitrary File Upload
60RISK
open
Nucleimedium
WordPress Ninja Forms <3.4.34 - Open Redirect
Ninja Forms < 3.4.34 - Administrator Open Redirect
18RISK
open
Nucleimedium
WordPress Advanced Order Export For WooCommerce <3.1.8 - Authenticated Cross-Site Scripting
Advanced Order Export For WooCommerce < 3.1.8 - Reflected Cross-Site Scripting (XSS)
43RISK
open
Nucleihigh
User Profile Picture < 2.5.0 - Sensitive Information Disclosure
User Profile Picture < 2.5.0 - Sensitive Information Disclosure
18RISK
open
Nucleicritical
The Plus Addons for Elementor Page Builder < 4.1.7 - Authentication Bypass
The Plus Addons for Elementor Page Builder < 4.1.7 - Authentication Bypass
23RISK
open
Nucleimedium
WordPress JH 404 Logger <=1.1 - Cross-Site Scripting
JH 404 Logger <= 1.1 - Unauthenticated Stored Cross-Site Scripting (XSS)
18RISK
open
Nucleimedium
WordPress PhastPress <1.111 - Open Redirect
PhastPress < 1.111 - Open Redirect
18RISK
open
Nucleicritical
WooCommerce Help Scout - Arbitrary File Upload
WooCommerce Help Scout < 2.9.1 - Unauthenticated Arbitrary File Upload leading to RCE
18RISK
open
Nucleimedium
GiveWP <= 2.9.7 - Cross-Site Scripting
GiveWP < 2.10.0 - Reflected Cross Site Scripting (XSS)
18RISK
open
Nucleimedium
WordPress OpenID Connect Generic Client 3.8.0-3.8.1 - Cross-Site Scripting
OpenID Connect Generic Client 3.8.0-3.8.1 - Reflected Cross Site Scripting (XSS) via Login Error
18RISK
open
Nucleicritical
Controlled Admin Access WordPress Plugin <= 1.4.0 - Improper Access Control & Privilege Escalation
Controlled Admin Access < 1.5.2 - Improper Access Control & Privilege Escalation
18RISK
open
Nucleimedium
All Thrive Themes and Plugins - Unauthenticated Option Update
All Thrive Themes and Plugins - Unauthenticated Option Update
18RISK
open
Nucleicritical
Multiple Thrive Themes < 2.0.0 - Arbitrary File Upload
All Thrive Themes Legacy Themes < 2.0.0 - Unauthenticated Arbitrary File Upload and Option Deletion
18RISK
open
Nucleihigh
AccessAlly <3.5.7 - Sensitive Information Leakage
AccessAlly < 3.5.7 - $_SERVER Superglobal Leakage
18RISK
open
Nucleihigh
Patreon WordPress <1.7.0 - Unauthenticated Local File Inclusion
Patreon WordPress < 1.7.0 - Unauthenticated Local File Disclosure
18RISK
open
previouspage 119 / 141next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.