Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
4,193 exploits
Nucleihigh
Apache OFBiz Directory Traversal - Remote Code Execution
CVE-2024-32113CRITICALunder attack
Apache OFBiz: Path traversal leading to RCE
100RISK
open
Nucleihigh
Apache ActiveMQ 6.x < 6.1.2 - Broken Access Control
Apache ActiveMQ: Jolokia and REST API were not secured with default configuration
36RISK
open
Nucleicritical
WordPress Realtyna Organic IDX Plugin <= 4.14.4 - SQL Injection
WordPress Realtyna Organic IDX plugin + WPL Real Estate plugin <= 4.14.4 - Unauthenticated SQL Injection vulnerability
43RISK
open
Nucleicritical
Stash < 0.26.0 - SQL Injection
Stash up to v0.25.1 was discovered to contain a SQL injection vulnerability via the sort parameter.
28RISK
open
Nucleicritical
H3C ER8300G2-X - Password Disclosure
H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accesse
75RISK
open
Nucleimedium
Popup4Phone <= 1.3.2 - Unauthenticated Stored Cross-Site Scripting
Popup4Phone <= 1.3.2 - Unauthenticated Stored XSS
28RISK
open
Nucleicritical
Chuanhu Chat - Directory Traversal
Path Traversal in gaizhenbiao/chuanhuchatgpt
43RISK
open
Nucleihigh
RaidenMAILD Mail Server v.4.9.4 - Path Traversal
Directory Traversal vulnerability in RaidenMAILD Mail Server v.4.9.4 and before allows a remote attacker to obtain sensi
36RISK
open
Nucleicritical
Mura/Masa CMS - SQL Injection
MasaCMS SQL Injection vulnerability
85RISK
open
Nucleicritical
Change Detection - Server Side Template Injection
Server Side Template Injection in Jinja2 allows Remote Command Execution
85RISK
open
Nucleicritical
WP-Recall <= 16.26.5 - SQL Injection
WordPress WP-Recall plugin <= 16.26.5 - SQL Injection vulnerability
43RISK
open
Nucleicritical
D-Link Network Attached Storage - Backdoor Account
CVE-2024-3272CRITICALunder attack
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded credentials
100RISK
open
Nucleicritical
D-Link Network Attached Storage - Command Injection and Backdoor Account
CVE-2024-3273HIGHunder attack
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISK
open
Nucleicritical
CyberPower - Missing Authentication
CyberPower PowerPanel Enterprise Missing Authentication
43RISK
open
Nucleihigh
CyberPower < v2.8.3 - SQL Injection
CyberPower PowerPanel Enterprise SQL Injection
36RISK
open
Nucleihigh
CyberPower - SQL Injection
CyberPower PowerPanel Enterprise SQL Injection
36RISK
open
Nucleihigh
CyberPower - SQL Injection
CyberPower PowerPanel Enterprise SQL Injection
36RISK
open
Nucleihigh
CyberPower < v2.8.3 - SQL Injection
CyberPower PowerPanel Enterprise SQL Injection
36RISK
open
Nucleimedium
D-LINK DNS-320L,DNS-320LW and DNS-327L - Information Disclosure
D-Link DNS-320L/DNS-320LW/DNS-327L HTTP GET Request info.cgi information disclosure
40RISK
open
Nucleimedium
Simply Static - Information Disclosure
WordPress Simply Static plugin <= 3.1.3 - Sensitive Data Exposure via Log File vulnerability
36RISK
open
Nucleimedium
iTop Hub Connector - Information Disclosure
iTop hub connector Information disclosure
28RISK
open
Nucleicritical
Lobe Chat <= v0.150.5 - Server-Side Request Forgery
lobe-chat `/api/proxy` endpoint Server-Side Request Forgery vulnerability
55RISK
open
Nucleicritical
Delmia Apriso - Pre-Authentication Unsafe .NET Object Deserialization
Pre-authentication Unsafe .NET object deserialization vulnerability affecting DELMIA Apriso Release 2019 through Release 2024
43RISK
open
Nucleimedium
D-LINK DIR-845L bsc_sms_inbox.php file - Information Disclosure
D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.
28RISK
open
Nucleihigh
Prison Management System - SQL Injection Authentication Bypass
Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the
56RISK
open
Nucleimedium
LumisXP - Cross-site Scripting
A cross-site scripting (XSS) vulnerability in the component XsltResultControllerHtml.jsp of Lumisxp v15.0.x to v16.1.x a
28RISK
open
Nucleimedium
User Meta WP Plugin < 3.1 - Sensitive Information Exposure
WordPress User Meta plugin <= 3.0 - Sensitive Data Exposure vulnerability
28RISK
open
Nucleihigh
Sharp Multifunction Printers - Directory Listing
Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for th
36RISK
open
Nucleimedium
Sharp Multifunction Printers - Cookie Exposure
"sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides log
55RISK
open
Nucleimedium
SOPlanning 1.52.00 Cross Site Scripting
SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.
48RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.