Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
4,201 exploits
Nucleihigh
GitLab - Account Takeover via Password Reset
CVE-2023-7028CRITICALunder attack
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open
Nucleimedium
WeiYe-Jing datax-web <= 2.1.2 - OS Command Injection
WeiYe-Jing datax-web HTTP POST Request killJob os command injection
28RISK
open
Nucleihigh
WordPress BackWPup < 4.0.4 - Backup File Disclosure
BackWPup < 4.0.4 - Unauthenticated Backup Download
36RISK
open
Nucleihigh
JetBackup <= 2.0.9.7 - Sensitive Information Exposure via Directory Listing
JetBackup < 2.0.9.9 - Directory Listing Exposing Backups
36RISK
open
Nucleimedium
System Dashboard < 2.8.10 - Cross-Site Scripting
System Dashboard < 2.8.10 - XSS via Header Injection
28RISK
open
Nucleihigh
Ozeki 10 SMS Gateway 10.3.208 - Arbitrary File Read
Ozeki SMS Gateway <= 10.3.208 Unauthenticated Arbitrary File Read
36RISK
open
Nucleicritical
JS Help Desk <= 2.8.2 - SQL Injection
JS Help Desk – AI-Powered Support & Ticketing System 2.8.2 - Unauthenticated SQL Injection via 'js-support-ticket-token-tkstatus' Cookie
36RISK
open
Nucleicritical
PAN-OS Management Web Interface - Authentication Bypass
CVE-2024-0012CRITICALunder attackransomware
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
Nucleicritical
SpiderFlow Crawler Platform - Remote Code Execution
spider-flow FunctionController.java FunctionService.saveFunction code injection
33RISK
open
Nucleicritical
Github Enterprise Authenticated Remote Code Execution
Unsafe Reflection in Github Enterprise Server leading to Command Injection
58RISK
open
Nucleicritical
Fortra GoAnywhere MFT - Authentication Bypass
Authentication Bypass in GoAnywhere MFT
85RISK
open
Nucleimedium
EventON (Free < 2.2.8, Premium < 4.5.5) - Information Disclosure
EventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Email Address Disclosure
60RISK
open
Nucleimedium
Analytics Insights for Google Analytics 4 < 6.3 - Open Redirect
Analytics Insights for Google Analytics 4 < 6.3 - Open Redirect
28RISK
open
Nucleihigh
Ncast busiFacade - Remote Command Execution
Guangzhou Yingke Electronic Technology Ncast Guest Login IPSetup.php information disclosure
60RISK
open
Nucleimedium
Travelpayouts <= 1.1.16 - Open Redirect
Travelpayouts <= 1.1.15 - Open Redirect
28RISK
open
Nucleicritical
Likeshop < 2.5.7.20210311 - Arbitrary File Upload
Likeshop HTTP POST Request File.php userFormImage unrestricted upload
78RISK
open
Nucleimedium
WordPress Simple Job Board - Unauthorized Data Access
Simple Job Board <= 2.10.8 - Missing Authorization to Unauthenticated Information Disclosure
28RISK
open
Nucleihigh
SolarWinds Security Event Manager - Unauthenticated RCE
SolarWinds Security Event Manager Deserialization of Untrusted Data Remote Code Execution Vulnerability
78RISK
open
Nucleicritical
Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection
Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection
43RISK
open
Nucleihigh
Monitorr Services Configuration - Arbitrary File Upload
15RISK
open
Nucleicritical
Arcserve Unified Data Protection - Authentication Bypass
Authentication Bypass via wizardLogin in Arcserve Unified Data Protection
43RISK
open
Nucleihigh
Arcserve Unified Data Protection - Unauthenticated DoS in ASNative.dll
Unauthenticated DoS in Arcserve Unified Data Protection
48RISK
open
Nucleimedium
Combo Blocks < 2.2.76 - Improper Access Control
Combo Blocks < 2.2.76 - Unauthenticated Password Protected Posts Access
33RISK
open
Nucleicritical
Smart S210 Management Platform - Arbitary File Upload
Byzoro Smart S210 Management Platform uploadfile.php unrestricted upload
40RISK
open
Nucleimedium
Issabel Authenticated - Remote Code Execution
Issabel PBX Asterisk-Cli os command injection
40RISK
open
Nucleicritical
CodeChecker <= 6.24.1 - Authentication Bypass
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
55RISK
open
Nucleimedium
Trilium <0.52.4 - Cross-Site Scripting
Cross-site Scripting (XSS) - Reflected in zadam/trilium
28RISK
open
Nucleicritical
Spring Cloud Gateway Code Injection
CVE-2022-22947CRITICALunder attack
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
Nucleicritical
VMware Workspace ONE Access - Server-Side Template Injection
CVE-2022-22954CRITICALunder attackransomware
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open
Nucleicritical
VMware Workspace ONE Access - Authentication Bypass
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth
30RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.