Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
4,217 exploits
Nucleicritical
SPIP Saisies - Remote Code Execution
SPIP Saisies Plugin < 5.11.1 Remote Code Execution
63RISK
open
Nucleimedium
BMC FootPrints - Authentication Bypass
BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass
48RISK
open
Nucleihigh
BMC FootPrints 'searchWeb' - Server-Side Request Forgery
BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in searchWeb
33RISK
open
Nucleihigh
BMC FootPrints 'feedUrl' - Server-Side Request Forgery
BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in externalfeed/RSS
33RISK
open
Nucleicritical
Zoo Management System 1.0 - SQL Injection
PHPGurukul Zoo Management System index.php sql injection
28RISK
open
Nucleihigh
Ditty < 3.1.58 - Server-Side Request Forgery
Ditty < 3.1.58 - Unauthenticated SSRF
41RISK
open
Nucleihigh
Gogs <= 0.13.3 - Remote Code Execution
CVE-2025-8110HIGHunder attack
File overwrite in file update API in Gogs
100RISK
open
Nucleimedium
Trilium <0.52.4 - Cross-Site Scripting
Cross-site Scripting (XSS) - Reflected in zadam/trilium
28RISK
open
Nucleicritical
Spring Cloud Gateway Code Injection
CVE-2022-22947CRITICALunder attack
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
Nucleicritical
VMware Workspace ONE Access - Server-Side Template Injection
CVE-2022-22954CRITICALunder attackransomware
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open
Nucleicritical
VMware Workspace ONE Access - Authentication Bypass
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth
30RISK
open
Nucleicritical
Spring Cloud - Remote Code Execution
CVE-2022-22963CRITICALunder attack
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
Nucleicritical
Spring - Remote Code Execution
CVE-2022-22965CRITICALunder attack
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
Nucleicritical
VMware Workspace ONE Access/Identity Manager/vRealize Automation - Authentication Bypass
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability aff
50RISK
open
Nucleimedium
SINEMA Remote Connect Server < V2.0 - Open Redirect
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an
18RISK
open
Nucleicritical
Zabbix - SAML SSO Authentication Bypass
CVE-2022-23131CRITICALunder attack
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISK
open
Nucleimedium
Zabbix Setup Configuration Authentication Bypass
CVE-2022-23134LOWunder attack
Possible view of the setup pages by unauthenticated users if config file already exists
95RISK
open
Nucleicritical
WordPress VR Calendar <=2.3.2 - Remote Code Execution
VR Calendar < 2.3.2 - Unauthenticated Arbitrary Function Call
23RISK
open
Nucleicritical
Crestron Device - Credentials Disclosure
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI
60RISK
open
Nucleihigh
BigAnt Server v5.6.06 - Local File Inclusion
BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks.
23RISK
open
Nucleimedium
BigAnt Server 5.6.06 - Improper Access Control
BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes.
18RISK
open
Nucleimedium
Cedar Gate EZ-NET <= 6.8.0 - Cross-Site Scripting
The Cedar Gate EZ-NET portal 6.5.5 6.8.0 Internet portal has a call to display messages to users which does not properly
28RISK
open
Nucleimedium
MeterSphere < 2.5.0 SSRF
Server-Side Request Forgery in Metersphere leads to Cross-Site Scripting
36RISK
open
Nucleimedium
WordPress Simply Schedule Appointments <1.5.7.7 - Information Disclosure
Simply Schedule Appointments < 1.5.7.7 - Unauthenticated Email Address Disclosure
18RISK
open
Nucleimedium
WordPress Directorist <7.3.1 - Information Disclosure
Directorist < 7.3.1 - Unauthenticated Email Address Disclosure
18RISK
open
Nucleimedium
Zoho ManageEngine - Internal Hostname Disclosure
Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname
23RISK
open
Nucleihigh
WordPress Easy Student Results <=2.2.8 - Improper Authorization
Easy Student Results <= 2.2.8 - Sensitive Information Disclosure via REST API
18RISK
open
Nucleimedium
phpMyAdmin < 5.1.2 - Cross-Site Scripting
An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup
28RISK
open
Nucleimedium
WordPress Feed Them Social <3.0.1 - Cross-Site Scripting
Feed Them Social < 3.0.1 - Reflected Cross-Site Scripting
18RISK
open
Nucleihigh
AVEVA InTouch Access Anywhere Secure Gateway - Local File Inclusion
AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an
68RISK
open
previouspage 127 / 141next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.