Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,978GitHub PoC 13,282VulnCheck XDB 8,176Nuclei 4,202Metasploit 3,462✓ verified onlyrecentpopularrisk
4,201 exploits
Nucleimedium
kkFileView 4.1.0 - Cross-Site Scripting
kkFileView v4.1.0 is vulnerable to Cross Site Scripting (XSS) via the parameter 'errorMsg.'
28RISK
open ↗Nucleicritical
SolarView 6.00 - Remote Command Execution
SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php
68RISK
open ↗Nucleicritical
WordPress IWS Geo Form Fields <=1.0 - SQL Injection
IWS - Geo Form Fields <= 1.0 - Unauthenticated SQLi
63RISK
open ↗Nucleicritical
Zimbra Collaboration - Unrestricted File Upload
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through ama
100RISK
open ↗Nucleihigh
WordPress Welcart e-Commerce <2.8.5 - Arbitrary File Access
Welcart e-Commerce < 2.8.5 - Unauthenticated Arbitrary File Access
36RISK
open ↗Nucleihigh
perfSONAR 4.x <= 4.4.4 - Server-Side Request Forgery
An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and exec
56RISK
open ↗Nucleimedium
ReQlogic v11.3 - Cross Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in ReQlogic v11.3 allow attackers to execute arbitrary web scripts o
48RISK
open ↗Nucleihigh
Hitachi Pentaho Business Analytics Server - Remote Code Execution
Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
100RISK
open ↗Nucleihigh
Hitachi Pentaho Business Analytics Server - Bypass Authorization
Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions
100RISK
open ↗Nucleicritical
WebTareas 2.4p5 - SQL Injection
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php
43RISK
open ↗Nucleicritical
WebTareas 2.4p5 - SQL Injection
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.
43RISK
open ↗Nucleihigh
WAVLINK Quantum D4G (WL-WN531G3) - Information Disclosure
WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access contr
36RISK
open ↗Nucleicritical
WordPress Fontsy <=1.8.6 - SQL Injection
Fontsy <= 1.8.6 - Multiple Unauthenticated SQLi
63RISK
open ↗Nucleicritical
Cryptocurrency Widgets Pack <= 1.8.1 - SQL Injection
WordPress Cryptocurrency Widgets Pack Plugin <=1.8.1 is vulnerable to SQL Injection
43RISK
open ↗Nucleicritical
PrestaShop lgcookieslaw - SQL Injection
The EU Cookie Law GDPR (Banner + Blocker) module before 2.1.3 for PrestaShop allows SQL Injection via a cookie ( lgcooki
43RISK
open ↗Nucleicritical
CentOS Web Panel 7 <0.9.8.1147 - Remote Code Execution
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISK
open ↗Nucleimedium
Rukovoditel <= 3.2.1 - Cross Site Scripting
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Announcement f
28RISK
open ↗Nucleimedium
Rukovoditel <= 3.2.1 - Cross-Site Scripting
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Page function
28RISK
open ↗Nucleimedium
Rukovoditel <= 3.2.1 - Cross Site Scripting
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Highlight Row feat
28RISK
open ↗Nucleimedium
Rukovoditel <= 3.2.1 - Cross-Site Scripting
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group fea
28RISK
open ↗Nucleimedium
Rukovoditel <= 3.2.1 - Cross Site Scripting
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field func
28RISK
open ↗Nucleimedium
Rukovoditel <= 3.2.1 - Cross Site Scripting
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field func
28RISK
open ↗Nucleimedium
Rukovoditel <= 3.2.1 - Cross Site Scripting
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Form tab f
28RISK
open ↗Nucleimedium
Rukovoditel <= 3.2.1 - Cross Site Scripting
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in /index.php?module=conf
28RISK
open ↗Nucleimedium
WebTareas 2.4p5 - Cross-Site Scripting
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /clients/listclien
28RISK
open ↗Nucleimedium
WBCE CMS v1.5.4 - Cross Site Scripting (Stored)
A cross-site scripting (XSS) vulnerability in /admin/users/index.php of WBCE CMS v1.5.4 allows attackers to execute arbi
28RISK
open ↗Nucleimedium
WBCE CMS v1.5.4 - Cross Site Scripting (Stored)
A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute ar
28RISK
open ↗Nucleihigh
Linx Sphere - Directory Traversal
A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attacke
36RISK
open ↗Nucleihigh
Download Monitor <= 4.7.60 - Sensitive Information Exposure
WordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data Exposure
60RISK
open ↗Nucleimedium
WordPress Paytm Payment Gateway <=2.7.0 - Server-Side Request Forgery
WordPress Paytm Payment Gateway Plugin <= 2.7.0 is vulnerable to Server Side Request Forgery (SSRF)
48RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.