Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
4,217 exploits
Nucleimedium
mojoPortal <=2.9.0.1 - Directory Traversal
mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. A
28RISK
open
Nucleimedium
Skitter Slideshow <= 2.5.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
WordPress Skitter Slideshow plugin <= 2.5.2 - Cross Site Scripting (XSS) vulnerability
28RISK
open
Nucleicritical
Order Delivery Date Pro for WooCommerce < 12.3.1 - Arbitrary Option Update
Order Delivery Date Pro for WooCommerce < 12.3.1 - Unauthenticated Arbitrary Option Update
63RISK
open
Nucleicritical
Vipshop Saturn Console <= 3.5.1 - SQL Injection via ClusterKey Component
SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via
48RISK
open
Nucleicritical
FoxCMS v.1.2.5 - Remote Code Execution
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISK
open
Nucleihigh
D-Link DIR-823X set_prohibiting - Command Injection
CVE-2025-29635HIGHunder attack
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrar
88RISK
open
Nucleihigh
XWiki REST API - Private Pages Disclosure
XWiki allows unregistered users to access private pages information through REST endpoint
36RISK
open
Nucleicritical
Next.js Middleware Bypass
Authorization Bypass in Next.js Middleware
85RISK
open
Nucleimedium
Vite - Arbitrary File Read
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
Nucleicritical
GeoServer WFS - XXE Processing Vulnerability
GeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handling
55RISK
open
Nucleicritical
Gladinet CentreStack < 16.4.10315.56368 Use of Hard-coded Key Leads to Unauthenticated RCE
CVE-2025-30406CRITICALunder attack
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RISK
open
Nucleihigh
WordPress WP01 - Path Traversal
WordPress WP01 plugin <= 2.6.2 - Arbitrary File Download Vulnerability
56RISK
open
Nucleihigh
SureTriggers – All-in-One Automation Platform ≤ 1.0.78 - Authentication Bypass
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RISK
open
Nucleimedium
Vite Development Server - Path Traversal
CVE-2025-31125MEDIUMunder attack
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RISK
open
Nucleihigh
Yeswiki < 4.5.2 - Unauthenticated Path Traversal
Path Traversal allowing arbitrary read of files in Yeswiki
56RISK
open
Nucleicritical
CrushFTP - Authentication Bypass
CVE-2025-31161CRITICALunder attackransomware
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
Nucleicritical
SAP NetWeaver Visual Composer Metadata Uploader - Deserialization
CVE-2025-31324CRITICALunder attackransomware
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISK
open
Nucleimedium
Vite server.fs.deny Bypass - Local File Inclusion
Vite allows server.fs.deny to be bypassed with .svg or relative paths
40RISK
open
Nucleihigh
MinIO - Incomplete Signature Validation for Unsigned-Trailer Uploads
MinIO performs incomplete signature validation for unsigned-trailer uploads
36RISK
open
Nucleimedium
1 Click WordPress Migration <= 2.2 - Unauthenticated Information Disclsoure
WordPress 1 Click WordPress Migration plugin <= 2.5.7 - Sensitive Data Exposure vulnerability
28RISK
open
Nucleihigh
Rocket TRUfusion Enterprise - Server Side Request Forgery
Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is
36RISK
open
Nucleimedium
Vite - Path Traversal
Vite has an `server.fs.deny` bypass with an invalid `request-target`
28RISK
open
Nucleicritical
XWiki Platform - SQL Injection
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RISK
open
Nucleimedium
XWiki Platform - Cross-Site Scripting
XWiki Platform contains Reflected XSS vulnerability in two templates
28RISK
open
Nucleicritical
CraftCMS - Remote Code Execution
CVE-2025-32432CRITICALunder attack
Craft CMS Allows Remote Code Execution
100RISK
open
Nucleihigh
MeteoBridge <= 6.1 - Remote Code Execution
CVE-2025-4008HIGHunder attack
Arbitrary Command Injection in Smartbedded MeteoBridge
88RISK
open
Nucleicritical
Evertz SDVN 3080ipx-10G - Unauthenticated Arbitrary Command Injection
Unauthenticated Arbitrary Command Injection in Evertz SDVN
65RISK
open
Nucleihigh
SolarWinds Web Help Desk < 12.8.8 Hotfix 1 (HF1) - Security Control Bypass
CVE-2025-40536HIGHunder attack
SolarWinds Web Help Desk Security Control Bypass Vulnerability
100RISK
open
Nucleicritical
SolarWinds Web Help Desk < 2026.1 - Unauthenticated JNDI Injection RCE
CVE-2025-40551CRITICALunder attack
SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability
95RISK
open
Nucleicritical
SolarWinds Web Help Desk - Authentication Bypass
SolarWinds Web Help Desk Authentication Bypass Vulnerability
75RISK
open
previouspage 133 / 141next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.