Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,003GitHub PoC 13,307VulnCheck XDB 8,182Nuclei 4,217Metasploit 3,462✓ verified onlyrecentpopularrisk
4,217 exploits
Nucleicritical
SolarWinds Serv-U FTP - Remote Code Execution
Serv-U Remote Memory Escape Vulnerability
100RISK
open ↗Nucleicritical
RealTek AP Router SDK - Arbitrary Command Injection
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as
95RISK
open ↗Nucleihigh
PowerDNS Authoritative Server - Denial of Service
PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE
30RISK
open ↗Nucleihigh
Oracle WebLogic Server - Unauthorized Access
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISK
open ↗Nucleicritical
VMWare Aria Operations - Remote Code Execution
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key g
75RISK
open ↗Nucleicritical
Acronis Cyber Infrastructure - Default Password
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastruct
85RISK
open ↗Nucleicritical
Apache ActiveMQ - Remote Code Execution
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open ↗Nucleimedium
OpenSSH Terrapin Attack - Detection
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remot
50RISK
open ↗Nucleihigh
Jenkins < 2.441 - Arbitrary File Read
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open ↗Nucleicritical
Zimbra Collaboration Suite < 9.0.0 - Remote Code Execution
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISK
open ↗Nucleihigh
CUPS - Remote Code Execution
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open ↗Nucleimedium
Citrix NetScaler ADC & Gateway - Reflected XSS / Open Redirect
Cross-Site Scripting (XSS)
33RISK
open ↗Nucleihigh
MongoDB Server - Information Disclosure (MongoBleed)
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗Nucleimedium
WordPress Yuzo <5.12.94 - Cross-Site Scripting
The Yuzo Related Posts plugin 5.12.94 for WordPress has XSS because it mistakenly expects that is_admin() verifies that
18RISK
open ↗Nucleihigh
Yellow Pencil Visual Theme Customizer < 7.2.1 - Privilege Escalation
The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress all
18RISK
open ↗Nucleihigh
GrandNode 4.40 - Local File Inclusion
A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows
50RISK
open ↗Nucleicritical
Deltek Maconomy 2.2.5 - Local File Inclusion
Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as
60RISK
open ↗Nucleimedium
WebPort 1.19.1 - Cross-Site Scripting
Web Port 1.19.1 allows XSS via the /log type parameter.
38RISK
open ↗Nucleimedium
Zyxel ZyWal/USG/UAG Devices - Cross-Site Scripting
A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall,
18RISK
open ↗Nucleicritical
Zyxel ZyWall UAG/USG - Account Creation Access
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attack
30RISK
open ↗Nucleihigh
IceWarp Mail Server <=10.4.4 - Local File Inclusion
IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index
50RISK
open ↗Nucleicritical
Zeroshell 3.9.0 - Remote Command Execution
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open ↗Nucleihigh
Shopware < 5.5.8 - Cross-Site Scripting
Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI.
36RISK
open ↗Nucleimedium
LiveZilla Server 8.0.1.0 - Cross-Site Scripting
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.
38RISK
open ↗Nucleicritical
Citrix SD-WAN Center - Remote Command Injection
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of
30RISK
open ↗Nucleicritical
Citrix SD-WAN Center - Remote Command Injection
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of
30RISK
open ↗Nucleicritical
Citrix SD-WAN Center - Remote Command Injection
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of
30RISK
open ↗Nucleicritical
Citrix SD-WAN Center - Remote Command Injection
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of
30RISK
open ↗Nucleicritical
Citrix SD-WAN and NetScaler SD-WAN - SQL Injection
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
100RISK
open ↗Nucleicritical
Citrix SD-WAN Center - Local File Inclusion
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal.
30RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.