Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,967GitHub PoC 13,264VulnCheck XDB 8,156Nuclei 4,201Metasploit 3,462✓ verified onlyrecentpopularrisk
4,201 exploits
Nucleihigh
Qualitor <= v8.24 - Server-Side Request Forgery
Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /request/viewValidacao.p
36RISK
open ↗Nucleimedium
LoLLMS WebUI - Subfolder Prediction via Path Traversal
Path Traversal in parisneo/lollms-webui
28RISK
open ↗Nucleihigh
Netis Wifi Router - Information Disclosure
An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi
23RISK
open ↗Nucleicritical
NetAlert X - Arbitary File Read
NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and
48RISK
open ↗Nucleicritical
ServiceNow UI Macros - Template Injection
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open ↗Nucleicritical
Progress Software WhatsUp Gold GetFileWithoutZip Directory Traversal - Remote Code Execution
WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability
100RISK
open ↗Nucleicritical
Vendure - Arbitrary File Read
Vendure asset server plugin has local file read vulnerability with AssetServerPlugin & LocalAssetStorageStrategy
75RISK
open ↗Nucleicritical
WordPress InstaWP Connect <= 0.1.0.38 - Unauthenticated User Creation
InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.38 - Missing Authorization to Unauthenticated API setup/Arbitrary Options Update/Administrative User Creation
63RISK
open ↗Nucleihigh
ZimaOS <= v1.2.4 - Sensitive Information Disclosure
ZimaOS (Installed Applications and System Information) has Unauthorized Sensitive Data Leak
41RISK
open ↗Nucleicritical
Plenti < v0.7.2 - OS Command Injection
Plenti arbitrary file write vulnerability
36RISK
open ↗Nucleihigh
Sonatype Nexus Repository Manager 3 - Local File Inclusion
Nexus Repository 3 - Path Traversal
61RISK
open ↗Nucleihigh
Zitadel - User Registration Bypass
Zitadel User Registration Bypass Vulnerability
36RISK
open ↗Nucleimedium
Scoold < 1.64.0 - Authentication Bypass
Semicolon Path Injection on API /api;/config
36RISK
open ↗Nucleihigh
Symfony Profiler - Remote Access via Injected Arguments
Ability to change environment from query in symfony/runtime
48RISK
open ↗Nucleicritical
WordPress Stacks Mobile App Builder <=5.2.3 - Authentication Bypass
WordPress Stacks Mobile App Builder plugin <= 5.2.3 - Account Takeover vulnerability
63RISK
open ↗Nucleicritical
WP Query Console <= 1.0 - Remote Code Execution
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RISK
open ↗Nucleicritical
WordPress Easy Digital Downloads <= 3.2.12 - SQL Injection
WordPress Easy Digital Downloads plugin <= 3.2.12 - SQL Injection vulnerability
43RISK
open ↗Nucleicritical
Aviatrix Controller - Remote Code Execution
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutraliza
100RISK
open ↗Nucleihigh
Cleo Harmony < 5.8.0.21 - Arbitary File Read
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up
100RISK
open ↗Nucleihigh
Nexus Repository 2 - Remote Code Execution
Nexus Repository 2 - Remote Code Execution
56RISK
open ↗Nucleicritical
Hash Form <= 1.1.0 - Arbitrary File Upload
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RISK
open ↗Nucleimedium
GestioIP - Reflected Cross-Site Scripting
The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS). It allows data exfiltration and en
48RISK
open ↗Nucleihigh
DATAGERRY - Improper Access Control
The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability.
48RISK
open ↗Nucleicritical
openSIS Classic v9.1 - SQL Injection
SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The
63RISK
open ↗Nucleimedium
TOTOLINK CX-A3002RU - Remote Code Execution
An issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121.1002 and TOTOLINK-CX-N300R
28RISK
open ↗Nucleicritical
CyberPanel - Command Injection
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RISK
open ↗Nucleicritical
ZoneMinder v1.37.* <= 1.37.64 - SQL Injection
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RISK
open ↗Nucleimedium
Changedetection.io <= 0.47.4 - Path Traversal
changedetection.io Path Traversal vulnerability
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.