Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,978GitHub PoC 13,282VulnCheck XDB 8,176Nuclei 4,202Metasploit 3,462✓ verified onlyrecentpopularrisk
4,201 exploits
Nucleicritical
OpenSMTPD 6.4.0-6.6.1 - Remote Code Execution
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open ↗Nucleicritical
SolarWinds Serv-U FTP - Remote Code Execution
Serv-U Remote Memory Escape Vulnerability
100RISK
open ↗Nucleicritical
RealTek AP Router SDK - Arbitrary Command Injection
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as
95RISK
open ↗Nucleihigh
PowerDNS Authoritative Server - Denial of Service
PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE
30RISK
open ↗Nucleihigh
Oracle WebLogic Server - Unauthorized Access
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISK
open ↗Nucleicritical
VMWare Aria Operations - Remote Code Execution
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key g
75RISK
open ↗Nucleicritical
Acronis Cyber Infrastructure - Default Password
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastruct
85RISK
open ↗Nucleicritical
Apache ActiveMQ - Remote Code Execution
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open ↗Nucleimedium
OpenSSH Terrapin Attack - Detection
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remot
50RISK
open ↗Nucleihigh
Jenkins < 2.441 - Arbitrary File Read
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open ↗Nucleicritical
Zimbra Collaboration Suite < 9.0.0 - Remote Code Execution
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISK
open ↗Nucleihigh
CUPS - Remote Code Execution
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open ↗Nucleimedium
Citrix NetScaler ADC & Gateway - Reflected XSS / Open Redirect
Cross-Site Scripting (XSS)
33RISK
open ↗Nucleihigh
MongoDB Server - Information Disclosure (MongoBleed)
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗Nucleihigh
D-Link DIR-823X set_prohibiting - Command Injection
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrar
88RISK
open ↗Nucleicritical
Redis < 8.2.1 lua script - Integer Overflow
Lua library commands may lead to integer overflow and potential RCE
36RISK
open ↗Nucleihigh
Redis Lua Sandbox < 8.2.2 - Cross-User Escape
Redis: Authenticated users can execute LUA scripts as a different user
28RISK
open ↗Nucleihigh
Redis < 8.2.1 Lua Long-String Delimiter - Out-of-Bounds Read
Redis is vulnerable to DoS via specially crafted LUA scripts
28RISK
open ↗Nucleicritical
Redis Lua Parser < 8.2.2 - Use After Free
Redis Lua Use-After-Free may lead to remote code execution
85RISK
open ↗Nucleicritical
Palo Alto Networks PAN-OS - Authentication Bypass
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
100RISK
open ↗Nucleicritical
SonicWall SMA1000 - Server-Side Request Forgery
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
93RISK
open ↗Nucleicritical
BeyondTrust Remote Support - Unauthenticated WebSocket RCE
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
100RISK
open ↗Nucleicritical
Apache Camel camel-coap - Remote Code Execution
Apache Camel: CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code Execution
63RISK
open ↗Nucleihigh
Vite Dev Server - Arbitrary File Read
Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket
36RISK
open ↗Nucleicritical
Marimo <= 0.20.4 - Pre-Auth Terminal WebSocket RCE
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISK
open ↗Nucleihigh
Next.js WebSocket Upgrade Handler - SSRF
Next.js: Server-side request forgery in applications using WebSocket upgrades
68RISK
open ↗Nucleicritical
WordPress Payeezy Pay <=2.97 - Local File Inclusion
The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay
18RISK
open ↗Nucleihigh
SAP Internet Graphics Server (IGS) - XML External Entity Injection
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML Exter
50RISK
open ↗Nucleicritical
osCommerce 2.3.4.1 - Remote Code Execution
osCommerce 2.3.4.1 Installer Unauthenticated Configuration File Injection PHP Code Execution
63RISK
open ↗Nucleihigh
Oracle Fusion Middleware WebCenter Sites - Cross-Site Scripting
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.