Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
4,217 exploits
Nucleihigh
Jan v0.4.12 'readFileSync' - Path Traversal
Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.
36RISK
open
Nucleicritical
Jan v0.4.12 - Arbitrary File Upload
An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute
43RISK
open
Nucleihigh
Splunk Enterprise - Local File Inclusion
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RISK
open
Nucleicritical
Ollama - Remote Code Execution
Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path,
78RISK
open
Nucleimedium
Argo CD Unauthenticated Access to sensitive setting
Unauthenticated Access to sensitive settings in Argo CD
28RISK
open
Nucleimedium
WP Extended < 3.0.0 - Stored Cross-Site Scripting
WordPress WP Extended plugin <= 2.4.7 - Cross Site Scripting (XSS) vulnerability
36RISK
open
Nucleimedium
WP-Lister Lite for Amazon <= 2.6.16 - Cross-Site Scripting
WordPress WP-Lister Lite for Amazon plugin <= 2.6.16 - Reflected Cross Site Scripting (XSS) vulnerability
36RISK
open
Nucleicritical
SecurEnvoy Two Factor Authentication - LDAP Injection
Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-suppl
63RISK
open
Nucleihigh
Electrolink FM/DAB/TV Transmitter (controlloLogin.js) - Credentials Disclosure
Electrolink FM/DAB/TV Transmitter Cleartext Storage of Sensitive Information
36RISK
open
Nucleimedium
Hostel < 1.1.5.3 - Cross-Site Scripting
Hostel < 1.1.5.3 - Reflected XSS
28RISK
open
Nucleimedium
GnuBoard5 5.5.16 - Open Redirect
An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the in
28RISK
open
Nucleihigh
OfficeWeb365 Indexs Interface - Arbitrary File Read
Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 al
36RISK
open
Nucleicritical
Craft CMS <=v3.7.31 - SQL Injection
Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.
48RISK
open
Nucleimedium
SiteGuard WP Plugin <= 1.7.6 - Login Page Disclosure
SiteGuard WP Plugin provides a functionality to customize the path to the login page wp-login.php and implements a measu
28RISK
open
Nucleimedium
Base64 Encoder/Decoder <= 0.9.2 - Cross-Site Scripting
Base64 Encoder/Decoder <= 0.9.2 - Reflected XSS
28RISK
open
Nucleihigh
TurboMeeting - Post-Authentication Command Injection
A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allow
36RISK
open
Nucleicritical
TurboMeeting - Boolean-based SQL Injection
A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x all
55RISK
open
Nucleimedium
CodiMD <2.5.4 - Insecure Filename Randomization
CodiMD - Missing Image Access Controls and Unauthorized Image Access
28RISK
open
Nucleihigh
Apache HTTPd Windows UNC - Server-Side Request Forgery
Apache HTTP Server on WIndows UNC SSRF
48RISK
open
Nucleihigh
Apache HTTP Server - ACL Bypass
Apache HTTP Server proxy encoding problem
41RISK
open
Nucleicritical
Sonicwall - Pre-Authentication Arbitrary File Read
CVE-2024-38475CRITICALunder attack
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RISK
open
Nucleihigh
Mlflow < 2.11.0 - Path Traversal
Path Traversal Bypass in mlflow/mlflow
48RISK
open
Nucleimedium
Uniview NVR301-04S2-P4 - Cross-Site Scripting
Uniview NVR301-04S2-P4 Cross-site Scripting
28RISK
open
Nucleicritical
Progress Telerik Report Server - Authentication Bypass
CVE-2024-4358CRITICALunder attack
Registration Authentication Bypass Vulnerability
100RISK
open
Nucleicritical
WordPress TI WooCommerce Wishlist Plugin <= 2.8.2 - SQL Injection
WordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
68RISK
open
Nucleicritical
YARPP <= 5.30.10 - Missing Authorization
WordPress Yet Another Related Posts Plugin (YARPP) plugin <= 5.30.10 - Broken Access Control vulnerability
40RISK
open
Nucleicritical
SendGrid for WordPress <= 1.4 - SQL Injection
WordPress SendGrid for WordPress plugin <= 1.4 - SQL Injection vulnerability
36RISK
open
Nucleimedium
Sunshine Photo Cart <= 3.2.5 - Reflected Cross-Site Scripting
WordPress Sunshine Photo Cart plugin <= 3.2.5 - Cross Site Scripting (XSS) vulnerability
36RISK
open
Nucleicritical
WordPress CAS Theme <= 1.0.0 - Server-Side Request Forgery
CAS <= 1.0.0 - Unauthenticated SSRF
63RISK
open
Nucleihigh
LiteSpeed Cache <= 6.4.1 - Sensitive Information Exposure
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RISK
open
previouspage 128 / 141next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.