Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,760cataloged exploits
32,083CVEs with public exploitation
1,932lab-tested
4,191 exploits
Nucleihigh
Codoforum 5.1 - Arbitrary File Upload
Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin
50RISK
open
Nucleihigh
Online Fire Reporting System v1.0 - SQL injection
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=reports&date=.
18RISK
open
Nucleihigh
Online Fire Reporting System v1.0 - SQL injection
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=user/manage_user&id=.
18RISK
open
Nucleicritical
Online Fire Reporting System v1.0 - SQL injection
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_request.
18RISK
open
Nucleicritical
Online Fire Reporting System v1.0 - SQL injection
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_team.
18RISK
open
Nucleicritical
Online Fire Reporting System v1.0 - SQL injection
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_inquiry.
18RISK
open
Nucleihigh
Online Fire Reporting System v1.0 - SQL injection
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/requests/take_action.php?id=.
18RISK
open
Nucleihigh
Complete Online Job Search System 1.0 - SQL Injection
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/admin/company/index.php?view=edit&id=.
18RISK
open
Nucleihigh
Complete Online Job Search System 1.0 - SQL Injection
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=category&search=.
18RISK
open
Nucleihigh
Complete Online Job Search System 1.0 - SQL Injection
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=hiring&search=.
18RISK
open
Nucleihigh
Car Rental Management System 1.0 - SQL Injection
Car Rental Management System v1.0 is vulnerable to SQL Injection via /ip/car-rental-management-system/admin/ajax.php?act
18RISK
open
Nucleihigh
Car Rental Management System 1.0 - SQL Injection
Car Rental Management System v1.0 is vulnerable to SQL Injection via car-rental-management-system/booking.php?car_id=.
18RISK
open
Nucleihigh
Car Rental Management System 1.0 - SQL Injection
Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/view_car.php?id
18RISK
open
Nucleihigh
Car Rental Management System 1.0 - SQL Injection
Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_booking.
18RISK
open
Nucleihigh
Car Rental Management System 1.0 - SQL Injection
Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_user.php
18RISK
open
Nucleicritical
Hospital Management System 1.0 - SQL Injection
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at doc
18RISK
open
Nucleimedium
Open edX <2022-06-06 - Cross-Site Scripting
Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.
18RISK
open
Nucleicritical
Sophos Firewall <= 19.0 MR1 - Remote Code Execution
CVE-2022-3236CRITICALunder attack
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewa
95RISK
open
Nucleicritical
Portal do Software Publico Brasileiro i3geo 7.0.5 - Local File Inclusion
A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3ge
23RISK
open
Nucleimedium
Microweber <1.3.2 - Cross-Site Scripting
HTML code Injection in template search keyword in microweber/microweber
28RISK
open
Nucleicritical
MSNSwitch Firmware MNT.2408 - Authentication Bypass
An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technolog
60RISK
open
Nucleihigh
Lin CMS Spring Boot - Default JWT Token
An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions w
18RISK
open
Nucleimedium
u5cms v8.3.5 - Open Redirect
An issue was discovered in u5cms verion 8.3.5 There is a URL redirection vulnerability that can cause a user's browser t
18RISK
open
Nucleicritical
AWP Classifieds <= 4.2.1 - Unauthenticated SQL Injection
AWP Classifieds Plugin < 4.3 - Unauthenticated SQLi
43RISK
open
Nucleimedium
WWBN AVideo 11.6 - Cross-Site Scripting
A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master
43RISK
open
Nucleimedium
WWBN AVideo 11.6 - Cross-Site Scripting
A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master
43RISK
open
Nucleimedium
WWBN AVideo 11.6 - Cross-Site Scripting
A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master
43RISK
open
Nucleimedium
NUUO NVRsolo Video Recorder 03.06.02 - Cross-Site Scripting
NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerabi
18RISK
open
Nucleihigh
Powertek Firmware <3.30.30 - Authorization Bypass
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypas
68RISK
open
Nucleicritical
WordPress Accordions - Unauthenticated Settings Update
WordPress Accordions plugin <= 2.0.2 - Unauthenticated WordPress Options Change vulnerability
43RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.