Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
4,201 exploits
Nucleihigh
Aquatronica Controller System <= 5.1.6 - Information Disclosure
Aquatronica Controller System Complete Information Disclosure
63RISK
open
Nucleihigh
Omnissa Workspace ONE UEM - Path Traversal
Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to ga
61RISK
open
Nucleicritical
Fortinet FortiWeb - SQL Injection
CVE-2025-25257CRITICALunder attack
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISK
open
Nucleimedium
Label Studio < 1.16.0 - Cross-Site Scripting
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
28RISK
open
Nucleihigh
File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read
File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read
56RISK
open
Nucleicritical
Vue Vben Admin - Default Credentials
Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials.
43RISK
open
Nucleihigh
WordPress The Wound Theme <= 0.0.1 - Local File Inclusion
The Wound <= 0.0.1 - Unauthenticated LFI
36RISK
open
Nucleicritical
User Registration & Membership <= 4.1.1 - Unauthenticated Privilege Escalation
User Registration & Membership < 4.1.2- Unauthenticated Privilege Escalation
68RISK
open
Nucleihigh
MagnusBilling Login Logs - Cross-Site Scripting
MagnusBilling Stored Cross-Site Scripting in Login Logs
36RISK
open
Nucleihigh
MagnusBilling Alarm Module - Cross-Site Scripting
MagnusBilling Stored Cross-Site Scripting in Alarm Module
36RISK
open
Nucleicritical
ICTBroadcast - Command Injection
ICTBroadcast <= 7.4 Unauthenticated Session Cookie RCE
63RISK
open
Nucleihigh
FlowiseAI Flowise <= 2.2.6 - Arbitrary File Upload
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
75RISK
open
Nucleihigh
InstaWP Connect < 0.1.0.86 - Local PHP File Inclusion
InstaWP Connect <= 0.1.0.85 - Unauthenticated Local PHP File Inclusion
41RISK
open
Nucleicritical
FREEDOM Administration - Default Login
The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with defaul
43RISK
open
Nucleicritical
OttoKit < 1.0.83 - SureTriggers allows Privilege Escalation
WordPress SureTriggers <= 1.0.82 - Privilege Escalation Vulnerability
75RISK
open
Nucleimedium
Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting
Yonyou UFIDA ERP-NC login.jsp cross site scripting
28RISK
open
Nucleimedium
Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting
Yonyou UFIDA ERP-NC menu.jsp cross site scripting
28RISK
open
Nucleimedium
Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting
Yonyou UFIDA ERP-NC systop.jsp cross site scripting
28RISK
open
Nucleimedium
Navidrome <=0.54.5 - Authentication Bypass in Subsonic API
Navidrome has authentication bypass in Subsonic API with non-existent username
28RISK
open
Nucleimedium
Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting
Yonyou UFIDA ERP-NC top.jsp cross site scripting
28RISK
open
Nucleihigh
Joplin 3.3.3 Server - Privilege Escalation
Privilege escalation in Joplin server via user patch endpoint
36RISK
open
Nucleimedium
Sitecore Experience Manager (XM)/Experience Platform (XP) 10.4 - Insecure Deserialization
Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through
60RISK
open
Nucleicritical
TRUfusion Enterprise <= 7.10.4.0 - Path Traversal
TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, t
36RISK
open
Nucleicritical
TRUfusion Enterprise <= 7.10.4.0 - Authentication Bypass
TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints s
36RISK
open
Nucleihigh
TRUfusion Enterprise <= 7.10.4.0 - Admin Contact Portal
TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unau
41RISK
open
Nucleicritical
Kentico Xperience 13 CMS - Staging Service Authentication Bypass (WT-2025-0011)
CVE-2025-2746CRITICALunder attack
Kentico Xperience <= 13.0.172 Staging Sync Server Digest Password Authentication Bypass
100RISK
open
Nucleicritical
Web-Check < 2.0.1 Screenshot API - OS Command Injection
Web-Check allows command Injection via Unvalidated URL in Screenshot API
68RISK
open
Nucleihigh
Infoblox NetMRI < 7.6.1 - Unauthenticated Command Injection in get_saml_request
An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.
48RISK
open
Nucleicritical
NetMRI Unauthenticated SQL Injection via skipjackUsername
An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.
55RISK
open
Nucleimedium
NetMRI < 7.6.1 - Authentication Bypass via Hardcoded Credentials
An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.
40RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.