Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
4,201 exploits
Nucleicritical
Github Enterprise Authenticated Remote Code Execution
Unsafe Reflection in Github Enterprise Server leading to Command Injection
58RISK
open
Nucleicritical
Fortra GoAnywhere MFT - Authentication Bypass
Authentication Bypass in GoAnywhere MFT
85RISK
open
Nucleimedium
EventON (Free < 2.2.8, Premium < 4.5.5) - Information Disclosure
EventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Email Address Disclosure
60RISK
open
Nucleimedium
Analytics Insights for Google Analytics 4 < 6.3 - Open Redirect
Analytics Insights for Google Analytics 4 < 6.3 - Open Redirect
28RISK
open
Nucleihigh
Ncast busiFacade - Remote Command Execution
Guangzhou Yingke Electronic Technology Ncast Guest Login IPSetup.php information disclosure
60RISK
open
Nucleimedium
Travelpayouts <= 1.1.16 - Open Redirect
Travelpayouts <= 1.1.15 - Open Redirect
28RISK
open
Nucleicritical
Likeshop < 2.5.7.20210311 - Arbitrary File Upload
Likeshop HTTP POST Request File.php userFormImage unrestricted upload
78RISK
open
Nucleimedium
WordPress Simple Job Board - Unauthorized Data Access
Simple Job Board <= 2.10.8 - Missing Authorization to Unauthenticated Information Disclosure
28RISK
open
Nucleihigh
SolarWinds Security Event Manager - Unauthenticated RCE
SolarWinds Security Event Manager Deserialization of Untrusted Data Remote Code Execution Vulnerability
78RISK
open
Nucleicritical
Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection
Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection
43RISK
open
Nucleihigh
Monitorr Services Configuration - Arbitrary File Upload
15RISK
open
Nucleicritical
Arcserve Unified Data Protection - Authentication Bypass
Authentication Bypass via wizardLogin in Arcserve Unified Data Protection
43RISK
open
Nucleihigh
Arcserve Unified Data Protection - Unauthenticated DoS in ASNative.dll
Unauthenticated DoS in Arcserve Unified Data Protection
48RISK
open
Nucleimedium
Combo Blocks < 2.2.76 - Improper Access Control
Combo Blocks < 2.2.76 - Unauthenticated Password Protected Posts Access
33RISK
open
Nucleicritical
Smart S210 Management Platform - Arbitary File Upload
Byzoro Smart S210 Management Platform uploadfile.php unrestricted upload
40RISK
open
Nucleimedium
Issabel Authenticated - Remote Code Execution
Issabel PBX Asterisk-Cli os command injection
40RISK
open
Nucleicritical
CodeChecker <= 6.24.1 - Authentication Bypass
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
55RISK
open
Nucleimedium
PropertyHive < 2.1.1 - Cross-Site Scripting
PropertyHive < 2.1.1 - Reflected XSS
28RISK
open
Nucleihigh
Bulk Me Now! Plugin <= 2.0 - Cross-Site Scripting
Bulk Me Now <= 2.0 - Reflected XSS
36RISK
open
Nucleimedium
WP DeskLite - Reflected XSS
WP DeskLite <= 1.0.0 - Reflected XSS
28RISK
open
Nucleimedium
AffiliateImporterEb <= 1.0.6 - Reflected XSS
AffiliateImporterEb <= 1.0.6 - Reflected XSS
28RISK
open
Nucleimedium
Advance Post Prefix WordPress plugin - Reflected XSS
Advance Post Prefix <= 1.1.1 - Reflected XSS
28RISK
open
Nucleimedium
WP BASE Booking - Reflected XSS
WP BASE Booking of Appointments, Services and Events < 5.0.0 - Reflected XSS
28RISK
open
Nucleihigh
WordPress Competition Form Plugin <= 2.0 - Cross-Site Scripting
Competition Form <= 2.0 - Reflected XSS
36RISK
open
Nucleimedium
BentoML v1.3.9 - Open Redirect
15RISK
open
Nucleicritical
Nokri – Job Board WordPress Theme <= 1.6.2 - Unauthenticated Arbitrary Password Change
Nokri – Job Board WordPress Theme <= 1.6.2 - Unauthenticated Arbitrary Password Change
43RISK
open
Nucleihigh
Error Log Viewer By WP Guru <= 1.0.1.3 - Missing Authorization to Arbitrary File Read
Error Log Viewer By WP Guru <= 1.0.1.3 - Missing Authorization to Unauthenticated Arbitrary File Read
48RISK
open
Nucleimedium
Custom Field Manager WordPress - Cross-Site Scripting
Custom Field Manager <= 1.0 - Reflected XSS Vulnerability
28RISK
open
Nucleimedium
Lazy Blocks <= 3.8.2 - Cross-Site Scripting
Custom Block Builder – Lazy Blocks < 3.8.3 - Reflected XSS
36RISK
open
Nucleicritical
DrayTek Vigor - Command Injection
CVE-2024-12987MEDIUMunder attack
DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.