Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
4,193 exploits
Nucleihigh
React Server Components - Denial of Service
A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 1
68RISK
open
Nucleicritical
FUXA <= 1.2.7 - Hardcoded JWT Secret Authentication Bypass
FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-code
43RISK
open
Nucleicritical
SPIP Saisies - Remote Code Execution
SPIP Saisies Plugin < 5.11.1 Remote Code Execution
63RISK
open
Nucleimedium
BMC FootPrints - Authentication Bypass
BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass
48RISK
open
Nucleihigh
BMC FootPrints 'searchWeb' - Server-Side Request Forgery
BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in searchWeb
33RISK
open
Nucleihigh
BMC FootPrints 'feedUrl' - Server-Side Request Forgery
BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in externalfeed/RSS
33RISK
open
Nucleicritical
Zoo Management System 1.0 - SQL Injection
PHPGurukul Zoo Management System index.php sql injection
28RISK
open
Nucleihigh
Ditty < 3.1.58 - Server-Side Request Forgery
Ditty < 3.1.58 - Unauthenticated SSRF
41RISK
open
Nucleihigh
Gogs <= 0.13.3 - Remote Code Execution
CVE-2025-8110HIGHunder attack
File overwrite in file update API in Gogs
100RISK
open
Nucleicritical
ChanCMS <= 3.1. - Remote Code Execution
yanyutao0402 ChanCMS collect.js getArticle deserialization
28RISK
open
Nucleimedium
LibreChat <= 0.7.9 - HTML Injection via Accept-Language Header
HTML Injection in Accept-Language Header in danny-avila/librechat
28RISK
open
Nucleicritical
Chef Automate < 4.13.295 — SQL Injection
Chef Automate compliance service SQL Injection Vulnerability
48RISK
open
Nucleicritical
Flowise < 3.0.1 - Remote Command Execution
Unsupervised OS command execution leads to remote code execution by unauthenticated network attackers
65RISK
open
Nucleimedium
Trinity Audio <= 5.21.0 - Information Exposure
Trinity Audio <= 5.21.0 - Unauthenticated Information Exposure
28RISK
open
Nucleicritical
RestroPress 3.0.0-3.2.1 - Authentication Bypass
RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT
63RISK
open
Nucleimedium
N-central - Authentication Bypass
N-central unauthenticated sessionID generation
60RISK
open
Nucleicritical
Loan Management System 1.0 - SQL Injection
Campcodes Online Loan Management System ajax.php sql injection
28RISK
open
Nucleimedium
The Events Calendar <= 6.15.2 - Information Disclosure
The Events Calendar <= 6.15.2 - Missing Authorization to Unauthenticated Password-Protected Information Disclosure
28RISK
open
Nucleimedium
Featured Image from URL (FIFU) <= 5.2.7 - Unauthenticated Information Exposure via Log File
Featured Image from URL (FIFU) <= 5.2.7 - Unauthenticated Information Exposure via Log File
33RISK
open
Nucleicritical
MLflow Job API - Authentication Bypass
Missing Authentication for Critical Function in mlflow/mlflow
36RISK
open
Nucleihigh
LolLMS < 2.2.0 - Server-Side Request Forgery
Server-Side Request Forgery (SSRF) in parisneo/lollms
36RISK
open
Nucleimedium
WordPress List Site Contributors < 1.1.8 - Reflected XSS
List Site Contributors <= 1.1.8 - Reflected Cross-Site Scripting via alpha
28RISK
open
Nucleicritical
Ninja Forms File Uploads <= 3.3.26 - Arbitrary File Upload
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISK
open
Nucleicritical
Langflow < 1.3.0 - Remote Code Execution via validate_code() exec()
CVE-2026-0770CRITICALunder attack
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
98RISK
open
Nucleihigh
Frontend File Manager Plugin <= 23.5 - Unauthenticated Arbitrary Email Sending
Frontend File Manager Plugin <= 23.5 - Unauthenticated Arbitrary Email Sending
28RISK
open
Nucleicritical
Prodigy Commerce <= 3.3.0 - Local File Inclusion
Prodigy Commerce <= 3.3.0 - Unauthenticated Local File Inclusion via parameters[template_name]
63RISK
open
Nucleicritical
Ivanti Sentry - OS Command Injection
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RISK
open
Nucleicritical
Hippoo Mobile App for WooCommerce <= 1.9.4 - Authentication Bypass to Admin Account Takeover
Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API
63RISK
open
Nucleihigh
YMC Filter WordPress - Unauthenticated Post Disclosure
YMC Smart Filter < 3.11.3 - Unauthenticated Private/Draft Post Disclosure
56RISK
open
Nucleihigh
Django RasterField - SQL Injection
Potential SQL injection via raster lookups on PostGIS
28RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.