Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,666cataloged exploits
32,032CVEs with public exploitation
1,932lab-tested
4,191 exploits
Nucleihigh
Spring Framework Path Traversal in Functional Web Frameworks
Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to pa
48RISK
open
Nucleicritical
Apache OFBiz - Improper Authorization & Remote Code Execution
CVE-2024-38856HIGHunder attack
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open
Nucleicritical
Dokan Pro <= 3.10.3 - SQL Injection
Dokan Pro <= 3.10.3 - Unauthenticated SQL Injection
75RISK
open
Nucleihigh
EfroTech Timetrax v8.3 - Sql Injection
EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in t
63RISK
open
Nucleihigh
WordPress Custom 404 Pro <= 3.11.1 - Reflected XSS
WordPress Custom 404 Pro plugin <= 3.11.1 - Reflected Cross Site Scripting (XSS) vulnerability
36RISK
open
Nucleihigh
Rocket.Chat - Server-Side Request Forgery (SSRF)
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
56RISK
open
Nucleimedium
Apache Superset < 4.0.2 - SQL Injection
Apache Superset: Improper SQL authorisation, parse not checking for specific engine functions
28RISK
open
Nucleihigh
Solara <1.35.1 - Local File Inclusion
Local File Inclusion in Solara
36RISK
open
Nucleicritical
1Panel SQL Injection - Authenticated
a sqlinjection in 1Panel
48RISK
open
Nucleicritical
FOG Project < 1.5.10.34 - Remote Command Execution
FOG has a command injection in /fog/management/export.php?filename=
68RISK
open
Nucleihigh
Bazarr < 1.4.3 - Arbitrary File Read
An issue in the component /api/swaggerui/static of Bazaar v1.4.3 allows unauthenticated attackers to execute a directory
36RISK
open
Nucleicritical
CrushFTP VFS - Sandbox Escape LFR
CVE-2024-4040CRITICALunder attack
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
Nucleicritical
Devika v1 - Path Traversal
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path tr
68RISK
open
Nucleicritical
Veeam Backup & Replication - Unauthenticated
CVE-2024-40711CRITICALunder attackransomware
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code exec
100RISK
open
Nucleicritical
Apache CloudStack - SAML Signature Exclusion
Apache CloudStack: SAML Signature Exclusion
41RISK
open
Nucleihigh
Cluster Control CMON API - Directory Traversal
Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and
36RISK
open
Nucleihigh
OpenAM<=15.0.3 FreeMarker - Template Injection
OpenAM FreeMarker template injection
36RISK
open
Nucleihigh
Mitel MiCollab - Authentication Bypass
CVE-2024-41713CRITICALunder attackransomware
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could
100RISK
open
Nucleimedium
The Events Calendar < 6.4.0.1 - Cross-site Scripting
The Events Calendar < 6.4.0.1 - Reflected XSS
63RISK
open
Nucleimedium
Twisted - Open Redirect & XSS
HTML injection in HTTP redirect body
28RISK
open
Nucleimedium
Open Redirect in Login Redirect - MobSF
Mobile Security Framework (MobSF) has an Open Redirect in Login Redirect
28RISK
open
Nucleicritical
Roundcube Webmail - Cross-Site Scripting
CVE-2024-42009CRITICALunder attack
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RISK
open
Nucleimedium
BlueNet Technology Clinical Browsing System 1.2.1 - Sql Injection
BlueNet Technology Clinical Browsing System deleteStudy.php sql injection
33RISK
open
Nucleicritical
Angular-Base64-Upload - Remote Code Execution
angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Explo
75RISK
open
Nucleimedium
AcuToWeb server/10.5.0.7577c8b - Cross-Site Scripting
Cross Site Scripting vulnerability in AcuToWeb server v.10.5.0.7577C8b allows a remote attacker to execute arbitrary cod
28RISK
open
Nucleicritical
Email Subscribers by Icegram Express <= 5.7.20 - Unauthenticated SQL Injection via Hash
Email Subscribers by Icegram Express <= 5.7.20 - Unauthenticated SQL Injection via hash
68RISK
open
Nucleicritical
Cost Calculator Builder <= 3.2.15 - SQL Injection
WordPress Cost Calculator Builder plugin <= 3.2.15 - SQL Injection vulnerability
43RISK
open
Nucleicritical
BerqWP <= 1.7.6 - Arbitrary File Upload
WordPress BerqWP plugin <= 1.7.6 - Unauthenticated Arbitrary File Upload vulnerability
63RISK
open
Nucleihigh
LoLLMS WebUI < 9.8 - Path Traversal
Path Traversal in parisneo/lollms-webui
48RISK
open
Nucleihigh
Gradio - Server-Side Request Forgery
Server-Side Request Forgery (SSRF) in gradio-app/gradio
48RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.