Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,760cataloged exploits
32,083CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,934GitHub PoC 13,235VulnCheck XDB 8,150Nuclei 4,193Metasploit 3,462✓ verified onlyrecentpopularrisk
4,193 exploits
Nucleicritical
Cisco HyperFlex HX Data Platform - Remote Command Execution
Cisco HyperFlex HX Command Injection Vulnerabilities
100RISK
open ↗Nucleimedium
Cisco HyperFlex HX Data Platform - Arbitrary File Upload
Cisco HyperFlex HX Data Platform File Upload Vulnerability
50RISK
open ↗Nucleicritical
SonicWall Email Security <= 10.0.9.x - Unauthenticated Admin Account Creation
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account
100RISK
open ↗Nucleimedium
SonicWall SonicOS 7.0 - Open Redirect
A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management
43RISK
open ↗Nucleicritical
SonicWall SMA100 Stack - Buffer Overflow/Remote Code Execution
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows
100RISK
open ↗Nucleihigh
Odoo Apps - Cross-Site Scripting via Prototype Pollution
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-bbq 1.2.1 allows a m
18RISK
open ↗Nucleicritical
Buffalo WSR-2533DHPL2 - Path Traversal
A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3
95RISK
open ↗Nucleihigh
Buffalo WSR-2533DHPL2 - Configuration File Injection
The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not pr
18RISK
open ↗Nucleihigh
Buffalo WSR-2533DHPL2 - Improper Access Control
The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not pr
18RISK
open ↗Nucleihigh
TCExam <= 14.8.1 - Sensitive Information Exposure
When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the
18RISK
open ↗Nucleihigh
Draytek VigorConnect 1.6.0-B - Local File Inclusion
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the D
88RISK
open ↗Nucleihigh
Draytek VigorConnect 6.0-B3 - Local File Inclusion
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the W
78RISK
open ↗Nucleimedium
Gryphon Tower - Cross-Site Scripting
A reflected cross-site scripting vulnerability exists in the url parameter of the /cgi-bin/luci/site_access/ page on the
18RISK
open ↗Nucleimedium
Trendnet AC2600 TEW-827DRU - Credentials Disclosure
Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses information via redirection from the setup wizard. Authe
30RISK
open ↗Nucleicritical
Trendnet AC2600 TEW-827DRU 2.08B01 - Admin Password Change
Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauth
23RISK
open ↗Nucleihigh
Netgear RAX43 1.0.3.96 - Command Injection/Authentication Bypass Buffer Overrun
Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable
18RISK
open ↗Nucleimedium
Keycloak 10.0.0 - 18.0.0 - Cross-Site Scripting
A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.
30RISK
open ↗Nucleicritical
Acmailer - Improper Access Control to OS Command Injection
Improper access control vulnerability in acmailer ver. 4.0.1 and earlier, and acmailer DB ver. 1.1.3 and earlier allows
18RISK
open ↗Nucleimedium
WordPress Quiz and Survey Master <7.1.14 - Cross-Site Scripting
Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject
18RISK
open ↗Nucleicritical
MovableType - Remote Command Injection
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISK
open ↗Nucleimedium
Adobe ColdFusion - Cross-Site Scripting
ColdFusion Improper neutralization of web input during page generation could lead to arbitrary JavaScript execution in the browser
40RISK
open ↗Nucleihigh
MinIO Browser API - Server-Side Request Forgery
Server-Side Request Forgery in MinIO Browser API
41RISK
open ↗Nucleihigh
Node.JS System Information Library <5.3.1 - Remote Command Injection
Command Injection Vulnerability
100RISK
open ↗Nucleimedium
WordPress Mediumish Theme <=1.0.47 - Cross-Site Scripting
Mediumish <= 1.0.47 - Unauthenticated Reflected Cross-Site Scripting (XSS)
18RISK
open ↗Nucleimedium
WordPress Bello Directory & Listing Theme <1.6.0 - Cross-Site Scripting
Bello < 1.6.0 - Unauthenticated Reflected XSS & XFS
23RISK
open ↗Nucleimedium
WordPress Car Repair Services & Auto Mechanic Theme <4.0 - Cross-Site Scripting
Car Repair Services < 4.0 - Unauthenticated Reflected XSS & XFS
18RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.