Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,432cataloged exploits
34,424CVEs with public exploitation
24,695lab-tested
4,217 exploits
Nucleicritical
WebTareas 2.4p5 - SQL Injection
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.
43RISK
open
Nucleihigh
WAVLINK Quantum D4G (WL-WN531G3) - Information Disclosure
WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access contr
36RISK
open
Nucleicritical
WordPress Fontsy <=1.8.6 - SQL Injection
Fontsy <= 1.8.6 - Multiple Unauthenticated SQLi
63RISK
open
Nucleicritical
Cryptocurrency Widgets Pack <= 1.8.1 - SQL Injection
WordPress Cryptocurrency Widgets Pack Plugin <=1.8.1 is vulnerable to SQL Injection
43RISK
open
Nucleicritical
PrestaShop lgcookieslaw - SQL Injection
The EU Cookie Law GDPR (Banner + Blocker) module before 2.1.3 for PrestaShop allows SQL Injection via a cookie ( lgcooki
43RISK
open
Nucleicritical
CentOS Web Panel 7 <0.9.8.1147 - Remote Code Execution
CVE-2022-44877CRITICALunder attack
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISK
open
Nucleimedium
Rukovoditel <= 3.2.1 - Cross Site Scripting
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Announcement f
28RISK
open
Nucleimedium
Rukovoditel <= 3.2.1 - Cross-Site Scripting
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Page function
28RISK
open
Nucleimedium
Rukovoditel <= 3.2.1 - Cross Site Scripting
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Highlight Row feat
28RISK
open
Nucleimedium
Rukovoditel <= 3.2.1 - Cross-Site Scripting
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group fea
28RISK
open
Nucleimedium
Rukovoditel <= 3.2.1 - Cross Site Scripting
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field func
28RISK
open
Nucleimedium
Rukovoditel <= 3.2.1 - Cross Site Scripting
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field func
28RISK
open
Nucleimedium
Rukovoditel <= 3.2.1 - Cross Site Scripting
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Form tab f
28RISK
open
Nucleimedium
Rukovoditel <= 3.2.1 - Cross Site Scripting
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in /index.php?module=conf
28RISK
open
Nucleimedium
WebTareas 2.4p5 - Cross-Site Scripting
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /clients/listclien
28RISK
open
Nucleimedium
WBCE CMS v1.5.4 - Cross Site Scripting (Stored)
A cross-site scripting (XSS) vulnerability in /admin/users/index.php of WBCE CMS v1.5.4 allows attackers to execute arbi
28RISK
open
Nucleimedium
WBCE CMS v1.5.4 - Cross Site Scripting (Stored)
A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute ar
28RISK
open
Nucleihigh
Linx Sphere - Directory Traversal
A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attacke
36RISK
open
Nucleihigh
Download Monitor <= 4.7.60 - Sensitive Information Exposure
WordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data Exposure
60RISK
open
Nucleimedium
WordPress Paytm Payment Gateway <=2.7.0 - Server-Side Request Forgery
WordPress Paytm Payment Gateway Plugin <= 2.7.0 is vulnerable to Server Side Request Forgery (SSRF)
48RISK
open
Nucleimedium
Stock Ticker <= 3.23.2 - Cross-Site-Scripting
WordPress Stock Ticker Plugin <= 3.23.2 is vulnerable to Cross Site Scripting (XSS)
48RISK
open
Nucleicritical
APsystems ECU-R Firmware - Command Injection
Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attack
65RISK
open
Nucleicritical
WordPress Paytm Payment Gateway <=2.7.3 - SQL Injection
WordPress Paytm Payment Gateway Plugin <= 2.7.3 is vulnerable to SQL Injection
36RISK
open
Nucleicritical
LearnPress Plugin < 4.2.0 - Unauthenticated Time-Based Blind SQLi
WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL Injection
63RISK
open
Nucleihigh
WordPress PhonePe Payment Solutions <=1.0.15 - Server-Side Request Forgery
WordPress PhonePe Payment Solutions Plugin <= 1.0.15 is vulnerable to Server Side Request Forgery (SSRF)
40RISK
open
Nucleihigh
WordPress Download Manager <= 3.2.59 - Reflected XSS
WordPress Download Manager Plugin <= 3.2.59 is vulnerable to Cross Site Scripting (XSS)
36RISK
open
Nucleimedium
ILIAS eLearning <7.16 - Open Redirect
ILIAS before 7.16 has an Open Redirect.
28RISK
open
Nucleicritical
KubeView <=0.1.31 - Information Disclosure
KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does n
55RISK
open
Nucleicritical
WBCE CMS v1.5.4 - Remote Code Execution
WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.
55RISK
open
Nucleicritical
Helmet Store Showroom v1.0 - SQL Injection
There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to by
43RISK
open
previouspage 112 / 141next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.