Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
4,201 exploits
Nucleimedium
WordPress 1 Click Migration Plugin < 2.3 - Information Exposure
1 Click WordPress Migration Plugin – 100% FREE for a limited time <= 2.2 - Unauthenticated Sensitive Information Exposure via Database Backup in class-ocm-backup.php
28RISK
open
Nucleimedium
LifterLMS < 8.0.1 - Cross-Site Scripting
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes < 8.0.1 - Reflected XSS
28RISK
open
Nucleihigh
WordPress WPMovieLibrary Plugin <= 2.1.4.8 - Cross-Site Scripting
WPMovieLibrary <= 2.1.4.8 - Reflected XSS
36RISK
open
Nucleihigh
Tube Video Ads Lite - Reflected XSS
Tube Video Ads Lite <= 1.5.7 - Reflected XSS
36RISK
open
Nucleimedium
OWL Carousel Slider - Cross-Site Scripting
WP Touch Slider <= 2.2 - Reflected XSS
28RISK
open
Nucleimedium
WP Pricing Table - Reflected XSS
WP Pricing Table <= 1.1 - Reflected XSS
28RISK
open
Nucleimedium
NewsTicker <= 1.0 - Reflected Cross-Site Scripting
News List <= 1.0 - Reflected XSS
28RISK
open
Nucleimedium
Post Sync Plugin <= 1.1 - Cross-Site Scripting
Post Sync <= 1.1 - Reflected XSS
28RISK
open
Nucleihigh
Themes Coder Ecommerce <= 1.3.4 - SQL Injection
Themes Coder <= 1.3.4 - Unauthenticated SQLi
36RISK
open
Nucleimedium
MemberSpace WordPress - Cross-Site Scripting
MemberSpace – Membership Plugin and Paid Subscriptions < 2.1.14 - Reflected XSS
28RISK
open
Nucleimedium
Relevanssi (A Better Search) <= 4.22.0 - Query Log Export
Relevanssi – A Better Search <= 4.22.0 (Free) and <= 2.25.0 (Premium) - Missing Authorization to Unauthenticated Query Log Export
40RISK
open
Nucleimedium
WordPress SEO Tools Plugin 4.0.7 - Cross-Site Scripting
SEO Tools <= 4.0.7 - Reflected XSS
28RISK
open
Nucleihigh
WPMobile.App <= 11.56 - Open Redirect
WPMobile.App <= 11.56 - Open Redirect via 'redirect' Parameter
36RISK
open
Nucleicritical
St. Joe ERP system - SQL Injection
St. Joe ERP System SingleRowQueryConverter SQL Injection
63RISK
open
Nucleimedium
Studiocart <= 2.9.0 - Cross-Site Scripting
Studiocart <= 2.9.0 - Reflected XSS
36RISK
open
Nucleihigh
Mlflow < 2.9.2 - Path Traversal
Path Traversal Vulnerability in mlflow/mlflow
36RISK
open
Nucleicritical
MasterStudy LMS WordPress Plugin <= 3.2.5 - SQL Injection
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection
85RISK
open
Nucleihigh
Gradio 4.3-4.12 - Local File Read
Arbitrary Local File Read via Component Method Invocation in gradio-app/gradio
56RISK
open
Nucleicritical
NotificationX <= 2.8.2 - SQL Injection
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RISK
open
Nucleicritical
ConnectWise ScreenConnect 23.9.7 - Authentication Bypass
CVE-2024-1709CRITICALunder attackransomware
Authentication bypass using an alternate path or channel
100RISK
open
Nucleihigh
Gradio > 4.19.1 UploadButton - Path Traversal
Local File Inclusion in gradio-app/gradio
58RISK
open
Nucleihigh
Tutor LMS <= 2.1.10 - SQL Injection
Tutor LMS – eLearning and online course solution <= 2.6.1 - Authenticated (Subscriber+) SQL Injection
36RISK
open
Nucleimedium
Cisco Finesse - Server-Side Request Forgery (SSRF)
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker t
61RISK
open
Nucleicritical
Cisco SSM On-Prem <= 8-202206 - Password Reset Account Takeover
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauth
85RISK
open
Nucleicritical
Hardcoded Admin Credentials For Cisco Smart Licensing Utility API
CVE-2024-20439CRITICALunder attack
A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an a
95RISK
open
Nucleihigh
Cisco Smart Licensing Utility UnAuthenticated Logs Exposure Leaking Plaintext Credentials
A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive inf
48RISK
open
Nucleihigh
Artica Proxy - Unauthenticated LFI
Artica Proxy Unauthenticated LFI Protection Bypass Vulnerability
68RISK
open
Nucleihigh
Adobe ColdFusion - Arbitrary File Read
CVE-2024-20767HIGHunder attack
ColdFusion | Improper Access Control (CWE-284)
100RISK
open
Nucleihigh
Oracle Retail Xstore Suite - Pre-authenticated Path Traversal
Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported
36RISK
open
Nucleimedium
Dash Framework - Cross-site Scripting
Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; v
28RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.