Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,760cataloged exploits
32,083CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,934GitHub PoC 13,235VulnCheck XDB 8,150Nuclei 4,193Metasploit 3,462✓ verified onlyrecentpopularrisk
4,193 exploits
Nucleimedium
WBCE CMS v1.5.4 - Cross Site Scripting (Stored)
A cross-site scripting (XSS) vulnerability in /admin/users/index.php of WBCE CMS v1.5.4 allows attackers to execute arbi
28RISK
open ↗Nucleimedium
WBCE CMS v1.5.4 - Cross Site Scripting (Stored)
A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute ar
28RISK
open ↗Nucleihigh
Linx Sphere - Directory Traversal
A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attacke
36RISK
open ↗Nucleihigh
Download Monitor <= 4.7.60 - Sensitive Information Exposure
WordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data Exposure
60RISK
open ↗Nucleimedium
WordPress Paytm Payment Gateway <=2.7.0 - Server-Side Request Forgery
WordPress Paytm Payment Gateway Plugin <= 2.7.0 is vulnerable to Server Side Request Forgery (SSRF)
48RISK
open ↗Nucleimedium
Stock Ticker <= 3.23.2 - Cross-Site-Scripting
WordPress Stock Ticker Plugin <= 3.23.2 is vulnerable to Cross Site Scripting (XSS)
48RISK
open ↗Nucleicritical
APsystems ECU-R Firmware - Command Injection
Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attack
65RISK
open ↗Nucleicritical
WordPress Paytm Payment Gateway <=2.7.3 - SQL Injection
WordPress Paytm Payment Gateway Plugin <= 2.7.3 is vulnerable to SQL Injection
36RISK
open ↗Nucleicritical
LearnPress Plugin < 4.2.0 - Unauthenticated Time-Based Blind SQLi
WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL Injection
63RISK
open ↗Nucleihigh
WordPress PhonePe Payment Solutions <=1.0.15 - Server-Side Request Forgery
WordPress PhonePe Payment Solutions Plugin <= 1.0.15 is vulnerable to Server Side Request Forgery (SSRF)
40RISK
open ↗Nucleihigh
WordPress Download Manager <= 3.2.59 - Reflected XSS
WordPress Download Manager Plugin <= 3.2.59 is vulnerable to Cross Site Scripting (XSS)
36RISK
open ↗Nucleimedium
ILIAS eLearning <7.16 - Open Redirect
ILIAS before 7.16 has an Open Redirect.
28RISK
open ↗Nucleicritical
KubeView <=0.1.31 - Information Disclosure
KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does n
55RISK
open ↗Nucleicritical
WBCE CMS v1.5.4 - Remote Code Execution
WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.
55RISK
open ↗Nucleicritical
Helmet Store Showroom v1.0 - SQL Injection
There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to by
43RISK
open ↗Nucleimedium
Helmet Store Showroom - Cross Site Scripting
Helmet Store Showroom 1.0 is vulnerable to Cross Site Scripting (XSS).
28RISK
open ↗Nucleicritical
Cacti <=1.2.22 - Remote Command Injection
Unauthenticated Command Injection
100RISK
open ↗Nucleimedium
Linear eMerge E3-Series - Cross-Site Scripting
Certain Linear eMerge E3-Series devices are vulnerable to XSS via the type parameter (e.g., to the badging/badge_templat
28RISK
open ↗Nucleihigh
Bangresto - SQL Injection
mesinkasir Bangresto 1.0 is vulnberable to SQL Injection via the itemqty%5B%5D parameter.
48RISK
open ↗Nucleimedium
NexusPHP <1.7.33 - Cross-Site Scripting
Multiple reflective cross-site scripting (XSS) vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to injec
28RISK
open ↗Nucleimedium
kkFileView 4.1.0 - Cross-Site Scripting
kkFileView v4.1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /control
28RISK
open ↗Nucleicritical
Masa CMS - Authentication Bypass
A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authenticatio
18RISK
open ↗Nucleicritical
Mura CMS <10.0.580 - Authentication Bypass
A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a
43RISK
open ↗Nucleihigh
Smart Office Web 20.28 - Information Disclosure
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the
68RISK
open ↗Nucleihigh
Apache OFBiz < 18.12.07 - Local File Inclusion
Apache OFBiz: Arbitrary file reading vulnerability
41RISK
open ↗Nucleicritical
LearnPress Plugin < 4.2.0 - Local File Inclusion
WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to Local File Inclusion
63RISK
open ↗Nucleicritical
Thinkphp Lang - Local File Inclusion
ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is en
48RISK
open ↗Nucleicritical
ManageEngine - Remote Command Execution
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISK
open ↗Nucleicritical
IBM Aspera Faspex <=4.4.2 PL1 - Remote Code Execution
IBM Aspera Faspex code execution
100RISK
open ↗Nucleimedium
OpenCATS 0.9.7 - Cross-Site Scripting
Opencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /openca
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.