Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
4,193 exploits
Nucleicritical
PrestaShop productsalert - SQL Injection
SQL injection vulnerability in the module "Products Alert" (productsalert) before 1.7.4 from Smart Modules for PrestaSho
36RISK
open
Nucleicritical
Web Directory Free < 1.7.3 - Local File Inclusion
Web Directory Free < 1.7.3 - Unauthenticated LFI
63RISK
open
Nucleihigh
CRMEB v.5.2.2 - SQL Injection
SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProduct
28RISK
open
Nucleihigh
Jan v0.4.12 'readFileSync' - Path Traversal
Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.
36RISK
open
Nucleicritical
Jan v0.4.12 - Arbitrary File Upload
An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute
43RISK
open
Nucleihigh
Splunk Enterprise - Local File Inclusion
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RISK
open
Nucleicritical
Ollama - Remote Code Execution
Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path,
78RISK
open
Nucleimedium
Argo CD Unauthenticated Access to sensitive setting
Unauthenticated Access to sensitive settings in Argo CD
28RISK
open
Nucleimedium
WP Extended < 3.0.0 - Stored Cross-Site Scripting
WordPress WP Extended plugin <= 2.4.7 - Cross Site Scripting (XSS) vulnerability
36RISK
open
Nucleimedium
WP-Lister Lite for Amazon <= 2.6.16 - Cross-Site Scripting
WordPress WP-Lister Lite for Amazon plugin <= 2.6.16 - Reflected Cross Site Scripting (XSS) vulnerability
36RISK
open
Nucleicritical
SecurEnvoy Two Factor Authentication - LDAP Injection
Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-suppl
63RISK
open
Nucleihigh
Electrolink FM/DAB/TV Transmitter (controlloLogin.js) - Credentials Disclosure
Electrolink FM/DAB/TV Transmitter Cleartext Storage of Sensitive Information
36RISK
open
Nucleimedium
Hostel < 1.1.5.3 - Cross-Site Scripting
Hostel < 1.1.5.3 - Reflected XSS
28RISK
open
Nucleimedium
GnuBoard5 5.5.16 - Open Redirect
An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the in
28RISK
open
Nucleihigh
OfficeWeb365 Indexs Interface - Arbitrary File Read
Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 al
36RISK
open
Nucleicritical
Craft CMS <=v3.7.31 - SQL Injection
Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.
48RISK
open
Nucleimedium
SiteGuard WP Plugin <= 1.7.6 - Login Page Disclosure
SiteGuard WP Plugin provides a functionality to customize the path to the login page wp-login.php and implements a measu
28RISK
open
Nucleimedium
Base64 Encoder/Decoder <= 0.9.2 - Cross-Site Scripting
Base64 Encoder/Decoder <= 0.9.2 - Reflected XSS
28RISK
open
Nucleihigh
TurboMeeting - Post-Authentication Command Injection
A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allow
36RISK
open
Nucleicritical
TurboMeeting - Boolean-based SQL Injection
A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x all
55RISK
open
Nucleimedium
CodiMD <2.5.4 - Insecure Filename Randomization
CodiMD - Missing Image Access Controls and Unauthorized Image Access
28RISK
open
Nucleihigh
Apache HTTPd Windows UNC - Server-Side Request Forgery
Apache HTTP Server on WIndows UNC SSRF
48RISK
open
Nucleihigh
Apache HTTP Server - ACL Bypass
Apache HTTP Server proxy encoding problem
41RISK
open
Nucleicritical
Sonicwall - Pre-Authentication Arbitrary File Read
CVE-2024-38475CRITICALunder attack
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RISK
open
Nucleihigh
Mlflow < 2.11.0 - Path Traversal
Path Traversal Bypass in mlflow/mlflow
48RISK
open
Nucleimedium
Uniview NVR301-04S2-P4 - Cross-Site Scripting
Uniview NVR301-04S2-P4 Cross-site Scripting
28RISK
open
Nucleihigh
NextChat - Server-Side Request Forgery
NextChat Server-Side Request Forgery (SSRF)
36RISK
open
Nucleihigh
Ivanti Avalanche SmartDeviceServer - XML External Entity
XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on t
58RISK
open
Nucleicritical
FormLift for Infusionsoft Web Forms <= 7.5.17 - SQL Injection
WordPress formlift plugin <= 7.5.17 - Unauthenticated Blind SQL Injection vulnerability
43RISK
open
Nucleihigh
WebMvc.fn/WebFlux.fn - Path Traversal
CVE-2024-38816: Path traversal vulnerability in functional web frameworks
61RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.