Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,760cataloged exploits
32,083CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,934GitHub PoC 13,235VulnCheck XDB 8,150Nuclei 4,193Metasploit 3,462✓ verified onlyrecentpopularrisk
4,193 exploits
Nucleihigh
WP Fastest Cache 1.2.2 - SQL Injection
WP Fastest Cache < 1.2.2 - Unauthenticated SQL Injection
40RISK
open ↗Nucleimedium
Quttera Web Malware Scanner <= 3.4.1.48 - Sensitive Data Exposure
Quttera Web Malware Scanner < 3.4.2.1 - Directory Listing to Sensitive Data Exposure
23RISK
open ↗Nucleihigh
Duplicator < 1.5.7.1; Duplicator Pro < 4.5.14.2 - Unauthenticated Sensitive Data Exposure
Duplicator < 1.5.7.1; Duplicator Pro < 4.5.14.2 - Unauthenticated Sensitive Data Exposure
30RISK
open ↗Nucleihigh
WordPress Backup Migration <= 1.3.6 - Path Traversal
Backup Migration <= 1.3.6 - Unauthenticated Arbitrary Backup Download to Sensitive Information Exposure
36RISK
open ↗Nucleimedium
TOTVS Fluig Platform - Cross-Site Scripting
TOTVS Fluig Platform mobileredir openApp.jsp cross site scripting
23RISK
open ↗Nucleicritical
Control iD iDSecure - Authentication Bypass
Control iD iDSecure passwordCustom Authentication Bypass
75RISK
open ↗Nucleicritical
WordPress My Calendar <3.4.22 - SQL Injection
The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in th
48RISK
open ↗Nucleimedium
OpenCMS 14 & 15 - Cross Site Scripting
Cross-site Scripting in Alkacon Software OpenCms
28RISK
open ↗Nucleimedium
WordPress Toolbar <= 2.2.6 - Open Redirect
WordPress Toolbar <= 2.2.6 - Open Redirect
33RISK
open ↗Nucleimedium
WordPress Download Manager - File Password Exposure
Download Manager < 3.2.83 - Unauthenticated Protected File Download Password Leak
36RISK
open ↗Nucleimedium
Seriously Simple Podcasting < 3.0.0 - Information Disclosure
Seriously Simple Podcasting < 3.0.0 - Unauthenticated Administrator Email Disclosure
28RISK
open ↗Nucleihigh
Prime Mover < 1.9.3 - Sensitive Data Exposure
Prime Mover < 1.9.3 - Directory Listing to Sensitive Data Exposure
48RISK
open ↗Nucleicritical
Citrix Netscaler ADC & Gateway - Out-Of-Bounds Memory Read
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Un
78RISK
open ↗Nucleicritical
Worpress Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RISK
open ↗Nucleihigh
LearnPress <= 4.2.5.7 - SQL Injection
LearnPress <= 4.2.5.7 - Unauthenticated SQL Injection via order_by
75RISK
open ↗Nucleimedium
Mlflow - Cross-Site Scripting
Reflected XSS via Content-Type Header in mlflow/mlflow
28RISK
open ↗Nucleimedium
WordPress FastDup <= 2.1.9 Sensitive Information Exposure - Directory Listing
FastDup – Fastest WordPress Migration & Duplicator < 2.2 - Directory Listing to Account Takeover and Sensitive Data Exposure
28RISK
open ↗Nucleicritical
Essential Blocks < 4.4.3 - Local File Inclusion
Essential Blocks < 4.4.3 - Unauthenticated Local File Inclusion
75RISK
open ↗Nucleicritical
LearnPress < 4.2.5.8 - Remote Code Execution
LearnPress <= 4.2.5.7 - Command Injection
56RISK
open ↗Nucleihigh
Hongjing e-HR 2020 - SQL Injection
Hongjing e-HR Login Interface loadhistroyorgtree sql injection
36RISK
open ↗Nucleimedium
WP Go Maps (formerly WP Google Maps) < 9.0.29 - Cross-Site Scripting
WP Go Maps (formerly WP Google Maps) <= 9.0.28 - Reflected Cross-Site Scripting
28RISK
open ↗Nucleicritical
WordPress WP Clone <= 2.4.2 - Database Backup Exposure
Clone < 2.4.3 - Unauthenticated Backup Download
36RISK
open ↗Nucleimedium
Payment Gateway for Telcell < 2.0.4 - Open Redirect
Payment Gateway for Telcell <= 2.0.1 - Unauthenticated Open Redirect
28RISK
open ↗Nucleicritical
WordPress File Manager <= 7.2.1 - Directory Traversal
File Manager And File Manager Pro (Multiple Versions) - Directory Traversal
43RISK
open ↗Nucleicritical
WordPress POST SMTP Mailer <= 2.8.7 - Authorization Bypass
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API
85RISK
open ↗Nucleicritical
Hikvision IP ping.php - Command Execution
Hikvision Intercom Broadcasting System ping.php os command injection
70RISK
open ↗Nucleicritical
Better Search Replace < 1.4.5 - PHP Object Injection
Better Search Replace <= 1.4.4 - Unauthenticated PHP Object Injection
68RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.