Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,023GitHub PoC 13,334VulnCheck XDB 8,195Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
4,217 exploits
Nucleicritical
ArgoCD Project API Token Repository Credentials Exposure
Argo CD: Project API Token Exposes Repository Credentials
43RISK
open ↗Nucleimedium
Astro - Unauthorized Third-Party Image Access
Unauthorized third-party images in Astro’s _image endpoint
28RISK
open ↗Nucleihigh
Agent-Zero 0.8.0 - 0.9.4 - Arbitrary File Download
An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to execute a directory tr
23RISK
open ↗Nucleicritical
Directus - Unauthenticated File Modification
Directus allows unauthenticated file upload and file modification due to lacking input sanitization
43RISK
open ↗Nucleihigh
XWiki Platform - Information Disclosure
XWiki Platform's configuration files can be accessed through the webjars API
43RISK
open ↗Nucleihigh
XWiki Platform - Path Traversal
XWiki Platform's configuration files can be accessed through jsx and sx endpoints
43RISK
open ↗Nucleihigh
XWiki - Information Disclosure
The XWiki Jetty package (XJetty) allows accessing any application file through URL
36RISK
open ↗Nucleimedium
WSO2 Management Console - Authentication Bypass
Authentication Bypass via URI Manipulation in Multiple WSO2 Products' Management Console Leading to Partial Information Disclosure
28RISK
open ↗Nucleihigh
LiquidFiles < 4.2 - User Enumeration via Password Reset
LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The appli
56RISK
open ↗Nucleimedium
Avigilon ACM - Host Header Injection
A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplyin
43RISK
open ↗Nucleihigh
Dify v1.6.0 - Server-Side Request Forgery
Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_
28RISK
open ↗Nucleicritical
Datart v1.0.0-rc.3 - Remote Code Execution
An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.
63RISK
open ↗Nucleicritical
HyperComments <= 1.2.2 - Arbitrary Options Update
HyperComments <= 1.2.2 - Unauthenticated (Subscriber+) Arbitrary Options Update
36RISK
open ↗Nucleicritical
Citrix NetScaler Memory Disclosure - CitrixBleed 2
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open ↗Nucleimedium
Commvault Unauthenticated Password Disclosure (WT-2025-0047)
Unauthorized API Access Risk
28RISK
open ↗Nucleimedium
Commvault Initial Administrator Login Process Vulnerability
Vulnerability in Initial Administrator Login Process
28RISK
open ↗Nucleihigh
ESPHome - Authentication Bypass
ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header
36RISK
open ↗Nucleicritical
FreePBX - Remote Code Execution
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open ↗Nucleimedium
Next.js Middleware - Server-Side Request Forgery
Next.js Improper Middleware Redirect Handling Leads to SSRF
28RISK
open ↗Nucleimedium
JumpServer - Open Redirect via Referer Header
JumpServer has an Open Redirect Vulnerability
28RISK
open ↗Nucleihigh
Astro Cloudflare Adapter - Server Side Request Forgery
Astro Cloudflare adapter is vulnerable to Server-Side Request Forgery via /_image endpoint
36RISK
open ↗Nucleimedium
WordPress 3D FlipBook Plugin <= 1.16.17 - Sensitive Information Exposure
WordPress 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery Plugin <= 1.16.16 - Sensitive Data Exposure Vulnerability
28RISK
open ↗Nucleihigh
GeoServer - XML External Entity Injection
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RISK
open ↗Nucleicritical
Flowise <= 3.0.5 - Account Takeover
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RISK
open ↗Nucleicritical
FOGProject <= 1.5.10.1673 - Authentication Bypass
FOG's authentication bypass leads to full SQL DB dump
68RISK
open ↗Nucleilow
Vite Dev Server - Path Traversal
Vite middleware may serve files starting with the same name with the public directory
23RISK
open ↗Nucleihigh
Mockoon < 9.2.0 - Path Traversal
Mockoon has a Path Traversal and LFI in the static file serving endpoint
36RISK
open ↗Nucleimedium
WordPress Gerencianet Oficial <= 3.1.3 - Unauthenticated Order Status Disclosure
WordPress Gerencianet Oficial plugin <= 3.1.3 - Sensitive Data Exposure vulnerability
28RISK
open ↗Nucleicritical
Windows Server Update Service - Insecure Deserialization
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.