Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
4,201 exploits
Nucleimedium
Astro - Information Disclosure
Server source code is exposed to the public if sourcemaps are enabled
36RISK
open
Nucleicritical
Apache Pinot < 1.3.0 - Authentication Bypass
Apache Pinot: Authentication bypass issue. If the path does not contain / and contain . authentication is not required
65RISK
open
Nucleimedium
Apache NiFi - Information Disclosure
Apache NiFi: Missing Complete Authorization for Parameter and Service References
23RISK
open
Nucleicritical
D-Link DIR-859 - Information Disclosure
A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals
55RISK
open
Nucleihigh
Netgear DGN2200 - Improper Authentication
A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individua
36RISK
open
Nucleicritical
TP-Link Archer C20 - Authentication Bypass
18RISK
open
Nucleicritical
TP-LINK WR840N v6 up to 0.9.1 4.16 - Improper Authentication
15RISK
open
Nucleimedium
DedeCMS - Open Redirect via download.php
Dedecms 5.71sp1 and earlier is vulnerable to URL redirect. In the web application, a logic error does not judge the inpu
28RISK
open
Nucleimedium
TP-Link Archer A20 v3 Router - Cross-site Scripting
The TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper handling of directory listi
28RISK
open
Nucleihigh
WpStickyBar <= 2.1.0 - SQL Injection
WpStickyBar <= 2.1.0 - Unauthenticated SQLi
68RISK
open
Nucleihigh
SimpleHelp <= 5.5.7 - Unauthenticated Path Traversal
CVE-2024-57727CRITICALunder attackransomware
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enabl
100RISK
open
Nucleicritical
Yii2 PHP Framework < 2.0.52 - Remote Code Execution
CVE-2024-58136CRITICALunder attack
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regres
95RISK
open
Nucleicritical
Vanna - SQL injection
Arbitrary File Write by Prompt Injection via DuckDB SQL in vanna-ai/vanna
43RISK
open
Nucleicritical
Palo Alto Expedition - Admin Account Takeover
CVE-2024-5910CRITICALunder attack
Expedition: Missing Authentication Leads to Admin Account Takeover
100RISK
open
Nucleicritical
GiveWP - PHP Object Injection
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISK
open
Nucleimedium
PrivateGPT < 0.5.0 - Open Redirect
Open Redirect in imartinez/privategpt
33RISK
open
Nucleimedium
Deep Sea Electronics DSE855 - Authentication Bypass
Deep Sea Electronics DSE855 Configuration Backup Missing Authentication Information Disclosure Vulnerability
28RISK
open
Nucleicritical
CZ Loan Management <= 1.1 - SQL Injection
CZ Loan Management <= 1.1 - Unauthenticated SQLi
43RISK
open
Nucleicritical
Quiz Maker <= 6.5.8.3 - SQL Injection
Quiz Maker <= 6.5.8.3 - Unauthenticated SQL Injection via 'ays_questions' Parameter
68RISK
open
Nucleihigh
Lawo AG vsm LTC Time Sync (vTimeSync) - Path Traversal
Unauthenticated Path Traversal
36RISK
open
Nucleimedium
LocalAI - Partial Local File Read
SSRF and Partial LFI in /models/apply Endpoint in mudler/localai
28RISK
open
Nucleicritical
Push Notification for Post and BuddyPress <= 1.93 - SQL Injection
Push Notification for Post and BuddyPress <=1.93 - Multiple Unauthenticated SQLi
63RISK
open
Nucleimedium
TrakSYS 11.x.x - Sensitive Data Exposure
Parsec Automation TrackSYS pagedefinition direct request
28RISK
open
Nucleicritical
PayPlus Payment Gateway < 6.6.9 - SQL Injection
PayPlus Payment Gateway < 6.6.9 - Unauthenticated SQLi
56RISK
open
Nucleicritical
WordPress Keydatas ≤ 2.5.2 - Arbitrary File Upload
简数采集器 (Keydatas) <= 2.5.2 - Unauthenticated Arbitrary File Upload
55RISK
open
Nucleicritical
NetScaler Console - Sensitive Information Disclosure
Sensitive information disclosure
48RISK
open
Nucleihigh
LOLLMS WebUI - Absolute Path Traversal
Absolute Path Traversal in parisneo/lollms-webui
36RISK
open
Nucleicritical
UsersWP <= 1.2.10 - Unauthenticated SQL Injection
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress <= 1.2.10 - Unauthenticated SQL Injection via 'uwp_sort_by'
43RISK
open
Nucleimedium
WPS Hide Login < 1.9.16.4 - Hidden Login Page Disclosure
WPS Hide Login < 1.9.16.4 - Hidden Login Page Disclosure
28RISK
open
Nucleihigh
User Profile Builder < 3.11.8 - File Upload
User Profile Builder < 3.11.8 - Unauthenticated Media Upload
68RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.