Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,432cataloged exploits
34,424CVEs with public exploitation
24,695lab-tested
4,217 exploits
Nucleicritical
Adobe Commerce (Magento) - Remote Code Execution
CVE-2022-24086CRITICALunder attack
Adobe Commerce checkout improper input validation leads to remote code execution
100RISK
open
Nucleicritical
Apache APISIX - Remote Code Execution
CVE-2022-24112CRITICALunder attack
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RISK
open
Nucleihigh
Casdoor 1.13.0 - Unauthenticated SQL Injection
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as d
50RISK
open
Nucleihigh
Shibboleth OIDC OP <3.0.4 - Server-Side Request Forgery
The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insuff
18RISK
open
Nucleihigh
FreeIPA - XML Entity Injection
Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a
60RISK
open
Nucleimedium
PKP Open Journal Systems 2.4.8-3.3 - Cross-Site Scripting
Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to
38RISK
open
Nucleicritical
Atom CMS v2.0 - SQL Injection
AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.
50RISK
open
Nucleicritical
VoipMonitor - Pre-Auth SQL Injection
A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administra
30RISK
open
Nucleihigh
Cuppa CMS v1.0 - SQL injection
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via t
18RISK
open
Nucleihigh
Cuppa CMS v1.0 - SQL injection
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=c
18RISK
open
Nucleihigh
Cuppa CMS v1.0 - SQL injection
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via t
18RISK
open
Nucleihigh
Apache Airflow OS Command Injection
Apache Airflow: RCE in example DAGs
40RISK
open
Nucleimedium
SmarterTools SmarterTrack - Cross-Site Scripting
Reflective XSS on SmarterTrack v100.0.8019.14010
36RISK
open
Nucleimedium
Transposh WordPress Translation <= 1.0.8 - Unauthenticated Settings Change
Transposh WordPress Translation <= 1.0.9.6 - Unauthorized Settings Change
28RISK
open
Nucleimedium
WordPress Transposh <=1.0.8.1 - Information Disclosure
Transposh WordPress Translation <= 1.0.9.6 - Sensitive Information Disclosure
28RISK
open
Nucleicritical
AudioCodes Device Manager Express - SQL Injection
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injec
68RISK
open
Nucleimedium
Custom Product Tabs for WooCommerce < 1.7.8 - Unauthenticated Toggle Content Setting Update
WordPress Custom Product Tabs for WooCommerce plugin <= 1.7.7 - Broken Access Control vulnerability
28RISK
open
Nucleimedium
Caddy 2.4.6 - Open Redirect
Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phi
28RISK
open
Nucleihigh
D-Link DIR-816L - Improper Access Control
An access control issue in D-Link DIR816L_FW206b01 allows unauthenticated attackers to access folders folder_view.php an
30RISK
open
Nucleimedium
Zoho ManageEngine ADSelfService Plus 6121 - Username Enumeration
Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST req
18RISK
open
Nucleimedium
Diary Management System 1.0 - Cross-Site Scripting
Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter
18RISK
open
Nucleimedium
Online Birth Certificate System 1.2 - Stored Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate
18RISK
open
Nucleicritical
Directory Management System 1.0 - SQL Injection
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Manageme
23RISK
open
Nucleicritical
Dairy Farm Shop Management System 1.0 - SQL Injection
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Ma
23RISK
open
Nucleicritical
Cyber Cafe Management System 1.0 - SQL Injection
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Managem
23RISK
open
Nucleicritical
Razer Sila Gaming Router - Remote Code Execution
A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execut
40RISK
open
Nucleihigh
Razer Sila Gaming Router 2.0.441_api-2.0.418 - Local File Inclusion
A local file inclusion vulnerability in Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to read arbitrary
23RISK
open
Nucleicritical
Node.js Embedded JavaScript 3.1.6 - Template Injection
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[
50RISK
open
Nucleicritical
Zoho ManageEngine - Access Control Bypass
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnera
40RISK
open
Nucleihigh
HashiCorp Consul/Consul Enterprise - Server-Side Request Forgery
HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the C
18RISK
open
previouspage 110 / 141next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.