Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,760cataloged exploits
32,083CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,934GitHub PoC 13,235VulnCheck XDB 8,150Nuclei 4,193Metasploit 3,462✓ verified onlyrecentpopularrisk
4,193 exploits
Nucleihigh
WordPress Front End Users - Reflected XSS
Front End Users <= 3.2.32 - Reflected XSS
36RISK
open ↗Nucleimedium
WordPress Stray Random Quotes <= 1.9.9 - Cross-Site Scripting
Stray Random Quotes <= 1.9.9 - Reflected XSS
28RISK
open ↗Nucleimedium
WordPress 1 Click Migration Plugin < 2.3 - Information Exposure
1 Click WordPress Migration Plugin – 100% FREE for a limited time <= 2.2 - Unauthenticated Sensitive Information Exposure via Database Backup in class-ocm-backup.php
28RISK
open ↗Nucleimedium
LifterLMS < 8.0.1 - Cross-Site Scripting
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes < 8.0.1 - Reflected XSS
28RISK
open ↗Nucleihigh
WordPress WPMovieLibrary Plugin <= 2.1.4.8 - Cross-Site Scripting
WPMovieLibrary <= 2.1.4.8 - Reflected XSS
36RISK
open ↗Nucleihigh
Tube Video Ads Lite - Reflected XSS
Tube Video Ads Lite <= 1.5.7 - Reflected XSS
36RISK
open ↗Nucleimedium
OWL Carousel Slider - Cross-Site Scripting
WP Touch Slider <= 2.2 - Reflected XSS
28RISK
open ↗Nucleimedium
NewsTicker <= 1.0 - Reflected Cross-Site Scripting
News List <= 1.0 - Reflected XSS
28RISK
open ↗Nucleimedium
Post Sync Plugin <= 1.1 - Cross-Site Scripting
Post Sync <= 1.1 - Reflected XSS
28RISK
open ↗Nucleihigh
Themes Coder Ecommerce <= 1.3.4 - SQL Injection
Themes Coder <= 1.3.4 - Unauthenticated SQLi
36RISK
open ↗Nucleimedium
MemberSpace WordPress - Cross-Site Scripting
MemberSpace – Membership Plugin and Paid Subscriptions < 2.1.14 - Reflected XSS
28RISK
open ↗Nucleimedium
Relevanssi (A Better Search) <= 4.22.0 - Query Log Export
Relevanssi – A Better Search <= 4.22.0 (Free) and <= 2.25.0 (Premium) - Missing Authorization to Unauthenticated Query Log Export
40RISK
open ↗Nucleimedium
WordPress SEO Tools Plugin 4.0.7 - Cross-Site Scripting
SEO Tools <= 4.0.7 - Reflected XSS
28RISK
open ↗Nucleihigh
WPMobile.App <= 11.56 - Open Redirect
WPMobile.App <= 11.56 - Open Redirect via 'redirect' Parameter
36RISK
open ↗Nucleicritical
St. Joe ERP system - SQL Injection
St. Joe ERP System SingleRowQueryConverter SQL Injection
63RISK
open ↗Nucleimedium
Studiocart <= 2.9.0 - Cross-Site Scripting
Studiocart <= 2.9.0 - Reflected XSS
36RISK
open ↗Nucleicritical
MasterStudy LMS WordPress Plugin <= 3.2.5 - SQL Injection
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection
85RISK
open ↗Nucleihigh
Gradio 4.3-4.12 - Local File Read
Arbitrary Local File Read via Component Method Invocation in gradio-app/gradio
56RISK
open ↗Nucleicritical
NotificationX <= 2.8.2 - SQL Injection
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RISK
open ↗Nucleicritical
ConnectWise ScreenConnect 23.9.7 - Authentication Bypass
Authentication bypass using an alternate path or channel
100RISK
open ↗Nucleihigh
Gradio > 4.19.1 UploadButton - Path Traversal
Local File Inclusion in gradio-app/gradio
58RISK
open ↗Nucleihigh
Tutor LMS <= 2.1.10 - SQL Injection
Tutor LMS – eLearning and online course solution <= 2.6.1 - Authenticated (Subscriber+) SQL Injection
36RISK
open ↗Nucleimedium
Cisco Finesse - Server-Side Request Forgery (SSRF)
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker t
61RISK
open ↗Nucleicritical
Cisco SSM On-Prem <= 8-202206 - Password Reset Account Takeover
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauth
85RISK
open ↗Nucleicritical
Hardcoded Admin Credentials For Cisco Smart Licensing Utility API
A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an a
95RISK
open ↗Nucleihigh
Cisco Smart Licensing Utility UnAuthenticated Logs Exposure Leaking Plaintext Credentials
A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive inf
48RISK
open ↗Nucleihigh
Artica Proxy - Unauthenticated LFI
Artica Proxy Unauthenticated LFI Protection Bypass Vulnerability
68RISK
open ↗Nucleihigh
Adobe ColdFusion - Arbitrary File Read
ColdFusion | Improper Access Control (CWE-284)
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.