Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
72,016cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,023GitHub PoC 13,332VulnCheck XDB 8,195Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
4,217 exploits
Nucleimedium
LearnPress < 4.3.7 - Information Disclosure
LearnPress < 4.3.7 - Unauthenticated Sensitive User Information Disclosure via REST API
48RISK
open ↗Nucleimedium
WordPress WP Go Maps < 10.0.10 - Unauthenticated Marker Data Disclosure
WP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Datatables AJAX Fallback
48RISK
open ↗Nucleimedium
WP Go Maps < 10.0.10 - Unauthenticated Marker Information Disclosure
WP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Marker ID
48RISK
open ↗Nucleihigh
WordPress AudioIgniter <= 2.0.2 - Unauthenticated IDOR
AudioIgniter Music Player <= 2.0.2 - Unauthenticated Insecure Direct Object Reference to 'audioigniter_playlist_id' Parameter
36RISK
open ↗Nucleicritical
WP Maps Pro (wp-google-map-gold) <= 6.1.0 - Unauthenticated Administrator Account Creation
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
68RISK
open ↗Nucleimedium
WordPress MapPress Maps <= 2.96.6 - Unauthenticated IDOR
MapPress Maps for WordPress <= 2.96.6 - Unauthenticated Insecure Direct Object Reference via REST API Endpoints
28RISK
open ↗Nucleicritical
Drupal Core - Anonymous SQL Injection via PostgreSQL Entity Query
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open ↗Nucleihigh
W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read
W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter
36RISK
open ↗Nucleihigh
WP User Manager – User Profile Builder & Membership - Local File Inclusion
WP User Manager <= 2.9.17 - Unauthenticated Path Traversal to Local File Inclusion via 'tab' Query Parameter
56RISK
open ↗Nucleihigh
PraisonAI - Authentication Bypass
PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
61RISK
open ↗Nucleimedium
MISP < 2.5.37 - SQL Injection
MISP: SQL injection via unvalidated ordering parameters in event and shadow attribute listings
43RISK
open ↗Nucleihigh
Deprecated SSHv1 Protocol Detection
The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to
18RISK
open ↗Nucleimedium
Titan FTP Server 3.01 - DoS via LIST Command Disconnection
Titan FTP Server version 3.01 build 163, and possibly other versions before build 169, allows remote authenticated users
38RISK
open ↗Nucleimedium
Pure-FTPd ≤ 1.0.18 - DoS via Connection Limit Exhaustion
The accept_client function in PureFTPd 1.0.18 and earlier allows remote attackers to cause a denial of service by exceed
18RISK
open ↗Nucleimedium
ProFTPD 1.2.x - Username Enumeration via Timing Attack
ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which al
50RISK
open ↗Nucleimedium
Titan FTP ≤ 3.21 - Heap Overflow via Long Commands
Heap-based buffer overflow in Titan FTP 3.21 and earlier allows remote attackers to cause a denial of service (crash) vi
38RISK
open ↗Nucleihigh
Distccd v1 - Remote Code Execution
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote at
60RISK
open ↗Nucleimedium
FileZilla Server < 0.9.6 - DoS via MS-DOS Device Names
FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename cont
18RISK
open ↗Nucleimedium
FileZilla Server < 0.9.6 - DoS via MODE Z Infinite Loop
FileZilla FTP server before 0.9.6, when using MODE Z (zlib compression), allows remote attackers to cause a denial of se
18RISK
open ↗Nucleimedium
FileZilla FTP Server 2.2.22 - Buffer Overflow
Buffer overflow in FileZilla FTP Server 2.2.22 allows remote authenticated attackers to cause a denial of service and po
18RISK
open ↗Nucleimedium
FileZilla Server < 0.9.22 - DoS via Wildcard Commands
FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to t
60RISK
open ↗Nucleicritical
Titan FTP Server 6.03 and 6.0.5.549 - Heap Overflow via Long Commands
Multiple heap-based buffer overflows in Titan FTP Server 6.03 and 6.0.5.549 allow remote attackers to cause a denial of
38RISK
open ↗Nucleicritical
Titan FTP Server 6.05 DELE Command - Heap Overflow
Heap-based buffer overflow in Titan FTP Server 6.05 build 550 allows remote attackers to execute arbitrary code via a lo
38RISK
open ↗Nucleimedium
FileZilla Server < 0.9.31 - SSL/TLS Packet Overflow DoS
Buffer overflow in FileZilla Server before 0.9.31 allows remote attackers to cause a denial of service via unspecified v
18RISK
open ↗Nucleihigh
ProFTPD < 1.3.3c - Directory Traversal via mod_site_misc
Multiple directory traversal vulnerabilities in the mod_site_misc module in ProFTPD before 1.3.3c allow remote authentic
18RISK
open ↗Nucleimedium
vsftpd < 2.3.3 - DoS
The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a deni
60RISK
open ↗Nucleicritical
VSFTPD 2.3.4 - Backdoor Command Execution
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open ↗Nucleilow
Pure-FTPd ≤ 1.0.22 - Directory Traversal
Directory traversal vulnerability in pure-FTPd 1.0.22 and possibly other versions, when running on SUSE Linux Enterprise
18RISK
open ↗Nucleimedium
Titan FTP Server < 10.40 Move Function - Directory Traversal
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke
38RISK
open ↗Nucleimedium
Titan FTP Server Search Function < 10.40 - User Enumeration
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke
38RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.