Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,967GitHub PoC 13,264VulnCheck XDB 8,156Nuclei 4,201Metasploit 3,462✓ verified onlyrecentpopularrisk
4,201 exploits
Nucleimedium
Advanced Custom Fields < 6.1.6 - Cross-Site Scripting
WordPress Advanced Custom Fields / Advanced Custom Fields PRO plugins <= 6.1.5 vulnerable to Cross Site Scripting (XSS)
68RISK
open ↗Nucleimedium
Tree Page View Plugin < 1.6.7 - Cross-Site Scripting
WordPress CMS Tree Page View Plugin <= 1.6.7 is vulnerable to Cross Site Scripting (XSS)
56RISK
open ↗Nucleicritical
Easy Digital Downloads - Privilege Escalation
WordPress Easy Digital Downloads Plugin 3.1-3.1.1.4.1 is vulnerable to Privilege Escalation
43RISK
open ↗Nucleimedium
Moodle - Cross-Site Scripting/Remote Code Execution
Moodle: tinymce loaders susceptible to arbitrary folder creation
28RISK
open ↗Nucleihigh
Repetier Server - Directory Traversal
Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstra
56RISK
open ↗Nucleimedium
Protect WP Admin < 4.0 - Unauthenticated Protection Bypass
Protect WP Admin < 4.0 - Unauthenticated Protection Bypass
18RISK
open ↗Nucleicritical
Cassia Gateway Firmware - Remote Code Execution
In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config
75RISK
open ↗Nucleicritical
TimeKeeper by FSMLabs - Remote Code Execution
An issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper st
30RISK
open ↗Nucleihigh
GL.iNET SSID Key Disclosure
An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configurati
41RISK
open ↗Nucleimedium
ChurchCRM v4.5.3 - Cross-Site Scripting
A stored Cross-site scripting (XSS) vulnerability in the FundRaiserEditor.php component of ChurchCRM v4.5.3 allows attac
28RISK
open ↗Nucleihigh
tagDiv Composer < 4.2 - Stored Cross-Site Scripting
tagDiv Composer < 4.2 - Unauthenticated Stored XSS
28RISK
open ↗Nucleimedium
Owncast - Server Side Request Forgery
Server-Side Request Forgery (SSRF) in owncast/owncast
36RISK
open ↗Nucleicritical
WordPress MStore API <= 4.0.1 - Unauthenticated SQL Injection
MStore API <= 4.0.1 - Unauthenticated SQL Injection
43RISK
open ↗Nucleihigh
Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints
WordPress Integrate Google Drive plugin <= 1.1.99 - Unauthenticated Broken Access Control vulnerability
63RISK
open ↗Nucleimedium
EventON Lite < 2.1.2 - Arbitrary File Download
EventON < 2.1.2 - Unauthenticated Post Access via IDOR
38RISK
open ↗Nucleihigh
Ghost CMS < 5.42.1 - Path Traversal
Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2
68RISK
open ↗Nucleicritical
WordPress Elementor Lite 5.7.1 - Arbitrary Password Reset
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISK
open ↗Nucleihigh
Openfire Administration Console - Authentication Bypass
Openfire administration console authentication bypass
100RISK
open ↗Nucleicritical
Ivanti Avalanche - Remote Code Execution
An unauthenticated attacker could achieve the code execution through a RemoteControl server.
58RISK
open ↗Nucleicritical
Subscribe to Category <= 2.7.4 - SQL Injection
WordPress Subscribe to Category Plugin <= 2.7.4 is vulnerable to SQL Injection
63RISK
open ↗Nucleicritical
MStore API <= 4.10.7 - Unauthorized Account Access and Privilege Escalation
MStore API <= 4.10.7 - Unauthorized Account Access and Privilege Escalation
43RISK
open ↗Nucleicritical
Emby Server - Authentication Bypass
Emby Server Proxy Header Spoofing Vulnerability
43RISK
open ↗Nucleicritical
MobileIron Core - Remote Unauthenticated API Access
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted fu
100RISK
open ↗Nucleimedium
XWiki - Cross-Site Scripting
XWiki Platform vulnerable to cross-site scripting in target parameter via share page by email
36RISK
open ↗Nucleimedium
XWiki >= 6.0-rc-1 - Cross-Site Scripting
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in delete template
43RISK
open ↗Nucleimedium
XWiki - Cross-Site Scripting
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in restore template
43RISK
open ↗Nucleimedium
XWiki >= 3.4-milestone-1 - Cross-Site Scripting
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in deletespace template
43RISK
open ↗Nucleimedium
XWiki >= 2.5-milestone-2 - Cross-Site Scripting
XWiki Platform vulnerable to reflected cross-site scripting via back and xcontinue parameters in resubmit template
43RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.