Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
4,201 exploits
Nucleimedium
Advanced Custom Fields < 6.1.6 - Cross-Site Scripting
WordPress Advanced Custom Fields / Advanced Custom Fields PRO plugins <= 6.1.5 vulnerable to Cross Site Scripting (XSS)
68RISK
open
Nucleimedium
Tree Page View Plugin < 1.6.7 - Cross-Site Scripting
WordPress CMS Tree Page View Plugin <= 1.6.7 is vulnerable to Cross Site Scripting (XSS)
56RISK
open
Nucleicritical
Easy Digital Downloads - Privilege Escalation
WordPress Easy Digital Downloads Plugin 3.1-3.1.1.4.1 is vulnerable to Privilege Escalation
43RISK
open
Nucleimedium
Moodle - Cross-Site Scripting/Remote Code Execution
Moodle: tinymce loaders susceptible to arbitrary folder creation
28RISK
open
Nucleihigh
Repetier Server - Directory Traversal
Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstra
56RISK
open
Nucleimedium
Protect WP Admin < 4.0 - Unauthenticated Protection Bypass
Protect WP Admin < 4.0 - Unauthenticated Protection Bypass
18RISK
open
Nucleicritical
Cassia Gateway Firmware - Remote Code Execution
In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config
75RISK
open
Nucleicritical
TimeKeeper by FSMLabs - Remote Code Execution
An issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper st
30RISK
open
Nucleihigh
GL.iNET SSID Key Disclosure
An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configurati
41RISK
open
Nucleimedium
ChurchCRM v4.5.3 - Cross-Site Scripting
A stored Cross-site scripting (XSS) vulnerability in the FundRaiserEditor.php component of ChurchCRM v4.5.3 allows attac
28RISK
open
Nucleihigh
tagDiv Composer < 4.2 - Stored Cross-Site Scripting
tagDiv Composer < 4.2 - Unauthenticated Stored XSS
28RISK
open
Nucleimedium
Owncast - Server Side Request Forgery
Server-Side Request Forgery (SSRF) in owncast/owncast
36RISK
open
Nucleicritical
WordPress MStore API <= 4.0.1 - Unauthenticated SQL Injection
MStore API <= 4.0.1 - Unauthenticated SQL Injection
43RISK
open
Nucleimedium
XWiki - Open Redirect
URL Redirection to Untrusted Site in XWiki
40RISK
open
Nucleihigh
Netmaker - Hardcoded DNS Secret Key
Netmaker has Hardcoded DNS Secret Key
36RISK
open
Nucleihigh
Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints
WordPress Integrate Google Drive plugin <= 1.1.99 - Unauthenticated Broken Access Control vulnerability
63RISK
open
Nucleimedium
EventON Lite < 2.1.2 - Arbitrary File Download
EventON < 2.1.2 - Unauthenticated Post Access via IDOR
38RISK
open
Nucleihigh
Ghost CMS < 5.42.1 - Path Traversal
Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2
68RISK
open
Nucleicritical
WordPress Elementor Lite 5.7.1 - Arbitrary Password Reset
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISK
open
Nucleihigh
Openfire Administration Console - Authentication Bypass
CVE-2023-32315HIGHunder attack
Openfire administration console authentication bypass
100RISK
open
Nucleicritical
Ivanti Avalanche - Remote Code Execution
An unauthenticated attacker could achieve the code execution through a RemoteControl server.
58RISK
open
Nucleicritical
Subscribe to Category <= 2.7.4 - SQL Injection
WordPress Subscribe to Category Plugin <= 2.7.4 is vulnerable to SQL Injection
63RISK
open
Nucleicritical
MStore API <= 4.10.7 - Unauthorized Account Access and Privilege Escalation
MStore API <= 4.10.7 - Unauthorized Account Access and Privilege Escalation
43RISK
open
Nucleicritical
Emby Server - Authentication Bypass
Emby Server Proxy Header Spoofing Vulnerability
43RISK
open
Nucleicritical
MobileIron Core - Remote Unauthenticated API Access
CVE-2023-35082CRITICALunder attackransomware
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted fu
100RISK
open
Nucleimedium
XWiki - Cross-Site Scripting
XWiki Platform vulnerable to cross-site scripting in target parameter via share page by email
36RISK
open
Nucleimedium
XWiki >= 6.0-rc-1 - Cross-Site Scripting
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in delete template
43RISK
open
Nucleimedium
XWiki - Cross-Site Scripting
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in restore template
43RISK
open
Nucleimedium
XWiki >= 3.4-milestone-1 - Cross-Site Scripting
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in deletespace template
43RISK
open
Nucleimedium
XWiki >= 2.5-milestone-2 - Cross-Site Scripting
XWiki Platform vulnerable to reflected cross-site scripting via back and xcontinue parameters in resubmit template
43RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.