Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,967GitHub PoC 13,264VulnCheck XDB 8,156Nuclei 4,201Metasploit 3,462✓ verified onlyrecentpopularrisk
4,201 exploits
Nucleimedium
Astro - Information Disclosure
Server source code is exposed to the public if sourcemaps are enabled
36RISK
open ↗Nucleicritical
Apache Pinot < 1.3.0 - Authentication Bypass
Apache Pinot: Authentication bypass issue. If the path does not contain / and contain . authentication is not required
65RISK
open ↗Nucleimedium
Apache NiFi - Information Disclosure
Apache NiFi: Missing Complete Authorization for Parameter and Service References
23RISK
open ↗Nucleicritical
D-Link DIR-859 - Information Disclosure
A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals
55RISK
open ↗Nucleihigh
Netgear DGN2200 - Improper Authentication
A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individua
36RISK
open ↗Nucleimedium
DedeCMS - Open Redirect via download.php
Dedecms 5.71sp1 and earlier is vulnerable to URL redirect. In the web application, a logic error does not judge the inpu
28RISK
open ↗Nucleimedium
TP-Link Archer A20 v3 Router - Cross-site Scripting
The TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper handling of directory listi
28RISK
open ↗Nucleihigh
WpStickyBar <= 2.1.0 - SQL Injection
WpStickyBar <= 2.1.0 - Unauthenticated SQLi
68RISK
open ↗Nucleihigh
SimpleHelp <= 5.5.7 - Unauthenticated Path Traversal
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enabl
100RISK
open ↗Nucleicritical
Yii2 PHP Framework < 2.0.52 - Remote Code Execution
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regres
95RISK
open ↗Nucleicritical
Vanna - SQL injection
Arbitrary File Write by Prompt Injection via DuckDB SQL in vanna-ai/vanna
43RISK
open ↗Nucleicritical
Palo Alto Expedition - Admin Account Takeover
Expedition: Missing Authentication Leads to Admin Account Takeover
100RISK
open ↗Nucleicritical
GiveWP - PHP Object Injection
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISK
open ↗Nucleimedium
Deep Sea Electronics DSE855 - Authentication Bypass
Deep Sea Electronics DSE855 Configuration Backup Missing Authentication Information Disclosure Vulnerability
28RISK
open ↗Nucleicritical
CZ Loan Management <= 1.1 - SQL Injection
CZ Loan Management <= 1.1 - Unauthenticated SQLi
43RISK
open ↗Nucleicritical
Quiz Maker <= 6.5.8.3 - SQL Injection
Quiz Maker <= 6.5.8.3 - Unauthenticated SQL Injection via 'ays_questions' Parameter
68RISK
open ↗Nucleihigh
Lawo AG vsm LTC Time Sync (vTimeSync) - Path Traversal
Unauthenticated Path Traversal
36RISK
open ↗Nucleimedium
LocalAI - Partial Local File Read
SSRF and Partial LFI in /models/apply Endpoint in mudler/localai
28RISK
open ↗Nucleicritical
Push Notification for Post and BuddyPress <= 1.93 - SQL Injection
Push Notification for Post and BuddyPress <=1.93 - Multiple Unauthenticated SQLi
63RISK
open ↗Nucleimedium
TrakSYS 11.x.x - Sensitive Data Exposure
Parsec Automation TrackSYS pagedefinition direct request
28RISK
open ↗Nucleicritical
PayPlus Payment Gateway < 6.6.9 - SQL Injection
PayPlus Payment Gateway < 6.6.9 - Unauthenticated SQLi
56RISK
open ↗Nucleicritical
WordPress Keydatas ≤ 2.5.2 - Arbitrary File Upload
简数采集器 (Keydatas) <= 2.5.2 - Unauthenticated Arbitrary File Upload
55RISK
open ↗Nucleicritical
NetScaler Console - Sensitive Information Disclosure
Sensitive information disclosure
48RISK
open ↗Nucleihigh
LOLLMS WebUI - Absolute Path Traversal
Absolute Path Traversal in parisneo/lollms-webui
36RISK
open ↗Nucleicritical
UsersWP <= 1.2.10 - Unauthenticated SQL Injection
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress <= 1.2.10 - Unauthenticated SQL Injection via 'uwp_sort_by'
43RISK
open ↗Nucleimedium
WPS Hide Login < 1.9.16.4 - Hidden Login Page Disclosure
WPS Hide Login < 1.9.16.4 - Hidden Login Page Disclosure
28RISK
open ↗Nucleihigh
User Profile Builder < 3.11.8 - File Upload
User Profile Builder < 3.11.8 - Unauthenticated Media Upload
68RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.