Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,432cataloged exploits
34,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,493GitHub PoC 13,618VulnCheck XDB 8,198Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
4,217 exploits
Nucleihigh
Kubernetes API Server - YAML Parsing DoS (Billion Laughs)
Kubernetes API Server JSON/YAML parsing vulnerable to resource exhaustion attack
41RISK
open ↗Nucleimedium
Carel pCOWeb <B1.2.4 - Cross-Site Scripting
Stored XSS was discovered in Carel pCOWeb prior to B1.2.4, as demonstrated by the config/pw_snmp.html "System contact" f
38RISK
open ↗Nucleimedium
Pulse Secure Pulse Connect Secure - Cross-Site Scripting (Reflected)
In Pulse Secure Pulse Connect Secure (PCS) 8.3.x before 8.3R7.1 and 9.0.x before 9.0R3, an XSS issue has been found on t
28RISK
open ↗Nucleicritical
Pulse Connect Secure SSL VPN Arbitrary File Read
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISK
open ↗Nucleicritical
Atlassian Crowd and Crowd Data Center - Unauthenticated Remote Code Execution
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attac
100RISK
open ↗Nucleicritical
Atlassian Jira Server-Side Template Injection
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators an
100RISK
open ↗Nucleimedium
WordPress Yuzo <5.12.94 - Cross-Site Scripting
The Yuzo Related Posts plugin 5.12.94 for WordPress has XSS because it mistakenly expects that is_admin() verifies that
18RISK
open ↗Nucleihigh
Yellow Pencil Visual Theme Customizer < 7.2.1 - Privilege Escalation
The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress all
18RISK
open ↗Nucleihigh
GrandNode 4.40 - Local File Inclusion
A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows
50RISK
open ↗Nucleicritical
Deltek Maconomy 2.2.5 - Local File Inclusion
Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as
60RISK
open ↗Nucleimedium
WordPress <= 5.2.4 - Unauthenticated View Private/Draft Posts
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is m
50RISK
open ↗Nucleicritical
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager - Remote Code Execution
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
78RISK
open ↗Nucleihigh
Xiaomi Mi WiFi R3G Routers - Local file Inclusion
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerabilit
50RISK
open ↗Nucleimedium
Ignite Realtime Openfire <4.42 - Local File Inclusion
PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the
23RISK
open ↗Nucleicritical
Ignite Realtime Openfire <=4.4.2 - Server-Side Request Forgery
A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allo
30RISK
open ↗Nucleihigh
DOMOS 5.5 - Local File Inclusion
The Log module in SECUDOS DOMOS before 5.6 allows local file inclusion.
23RISK
open ↗Nucleicritical
strapi CMS <3.0.0-beta.17.5 - Admin Password Reset
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open ↗Nucleihigh
Allied Telesis AT-GS950/8 - Local File Inclusion
A Directory Traversal in the Web interface of the Allied Telesis AT-GS950/8 until Firmware AT-S107 V.1.1.3 [1.00.047] al
23RISK
open ↗Nucleicritical
Xfilesharing 2.5.1 - Arbitrary File Upload
SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951
30RISK
open ↗Nucleimedium
MicroStrategy Library <11.1.3 - Cross-Site Scripting
Microstrategy Library in MicroStrategy before 2019 before 11.1.3 has reflected XSS.
18RISK
open ↗Nucleimedium
Cisco RV110W RV130W RV215W Router - Information leakage
Cisco RV110W, RV130W, and RV215W Routers Unauthenticated syslog File Access Vulnerability
40RISK
open ↗Nucleimedium
WordPress Hero Maps Premium <=2.2.1 - Cross-Site Scripting
The Hero Maps Premium plugin 2.2.1 and prior for WordPress is prone to unauthenticated XSS via the views/dashboard/index
18RISK
open ↗Nucleimedium
Rumpus FTP Web File Manager 8.2.9.1 - Cross-Site Scripting
A Reflected Cross Site Scripting was discovered in the Login page of Rumpus FTP Web File Manager 8.2.9.1. An attacker ca
43RISK
open ↗Nucleilow
Huawei Firewall - Local File Inclusion
USG9500 with versions of V500R001C30SPC100, V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100,
18RISK
open ↗Nucleimedium
Cisco Small Business 200,300 and 500 Series Switches - Open Redirect
Cisco Small Business Series Switches Open Redirect Vulnerability
53RISK
open ↗Nucleicritical
Citrix ADC and Gateway - Directory Traversal
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open ↗Nucleihigh
TOTOLINK/Realtek Routers - Information Disclosure
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attacker
18RISK
open ↗Nucleihigh
TOTOLINK/Realtek Routers - Information Disclosure
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext admin
18RISK
open ↗Nucleihigh
TOTOLINK Realtek SD Routers - Remote Command Injection
On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCm
23RISK
open ↗Nucleicritical
TOTOLINK/Realtek Routers - CAPTCHA Bypass
On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"}
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.