Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
72,041cataloged exploits
32,227CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,025GitHub PoC 13,352VulnCheck XDB 8,198Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
4,217 exploits
Nucleihigh
Oracle E-Business Suite <=12.2 - Authentication Bypass
Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Ea
58RISK
open ↗Nucleicritical
Oracle E-Business Suite 12.2.3 -12.2.11 - Remote Code Execution
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
100RISK
open ↗Nucleimedium
WordPress Download Manager < 3.2.44 - Authenticated Cross-Site Scripting
Download Manager < 3.2.44 - Reflected Cross-Site Scripting
18RISK
open ↗Nucleihigh
October CMS - Remote Code Execution
Authenticated remote code execution in octobercms
36RISK
open ↗Nucleimedium
microweber 1.2.18 - Cross-site Scripting
Cross-site Scripting (XSS) - Reflected in microweber/microweber
28RISK
open ↗Nucleihigh
GitLab CE/EE - Remote Code Execution
A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to
85RISK
open ↗Nucleimedium
WordPress Contact Form 7 Captcha <0.1.2 - Cross-Site Scripting
Contact Form 7 Captcha < 0.1.2 - Reflected Cross-Site Scripting
18RISK
open ↗Nucleihigh
Unyson < 2.7.27 - Cross Site Scripting
Unyson < 2.7.27 - Reflected Cross-Site Scripting
18RISK
open ↗Nucleimedium
Juniper Web Device Manager - Cross-Site Scripting
Junos OS: Cross-site Scripting (XSS) vulnerability in J-Web
48RISK
open ↗Nucleicritical
SAP Memory Pipes (MPI) Desynchronization
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RISK
open ↗Nucleimedium
Apache ShardingSphere ElasticJob-UI privilege escalation
Access-Token in ElasticJob UI causes password disclosure
30RISK
open ↗Nucleicritical
PrestaShop AP Pagebuilder <= 2.4.4 - SQL Injection
A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder
23RISK
open ↗Nucleimedium
Trilium <0.52.4 - Cross-Site Scripting
Cross-site Scripting (XSS) - Reflected in zadam/trilium
28RISK
open ↗Nucleicritical
Spring Cloud Gateway Code Injection
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open ↗Nucleicritical
VMware Workspace ONE Access - Server-Side Template Injection
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open ↗Nucleicritical
Open Web Analytics 1.7.3 - Remote Code Execution
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISK
open ↗Nucleicritical
Garage Management System 1.0 - SQL Injection
SourceCodester Garage Management System login.php sql injection
36RISK
open ↗Nucleimedium
ManageEngine ADSelfService Plus <6121 - Stored Cross-Site Scripting
Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock
18RISK
open ↗Nucleimedium
Zimbra Collaboration Suite < 8.8.15 - Improper Encoding
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), a
70RISK
open ↗Nucleicritical
GeoServer <1.2.2 - Remote Code Execution
Improper Control of Generation of Code in jai-ext
100RISK
open ↗Nucleimedium
XWiki < 12.10.11, 13.4.4 & 13.9-rc-1 - Information Disclosure
Unauthenticated user can retrieve the list of users through uorgsuggest.vm
28RISK
open ↗Nucleihigh
Flyte Console <0.52.0 - Server-Side Request Forgery
Server-Side Request Forgery in FlyteConsole
48RISK
open ↗Nucleicritical
Wavlink WN535K2/WN535K3 - OS Command Injection
WAVLINK WN535K2/WN535K3 os command injection
41RISK
open ↗Nucleicritical
Wavlink WN535K2/WN535K3 - OS Command Injection
WAVLINK WN535K2/WN535K3 nightled.cgi os command injection
58RISK
open ↗Nucleicritical
Wavlink WN535K2/WN535K3 - OS Command Injection
WAVLINK WN535K2/WN535K3 touchlist_sync.cgi os command injection
48RISK
open ↗Nucleihigh
Piano LED Visualizer 1.3 - Local File Inclusion
Absolute Path Traversal due to incorrect use of `send_file` call in Piano LED Visualizer
43RISK
open ↗Nucleihigh
TerraMaster TOS < 4.2.30 Server Information Disclosure
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agen
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.