Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,432cataloged exploits
34,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,493GitHub PoC 13,618VulnCheck XDB 8,198Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
4,217 exploits
Nucleicritical
elFinder 2.1.58 - Remote Code Execution
Multiple vulnerabilities leading to RCE
75RISK
open ↗Nucleihigh
WooCommerce Blocks 2.5 to 5.5 - Unauthenticated SQL Injection
Arbitrary SQL (SQL injection) possible via the Store API component.
61RISK
open ↗Nucleihigh
Express-handlebars - Local File Inclusion
File disclosure in Express Handlebars
23RISK
open ↗Nucleicritical
Erxes <0.23.0 - Cross-Site Scripting
Erxes vulnerable to Cross-site Scripting
28RISK
open ↗Nucleicritical
Zoho ManageEngine OpManager < 12.5.329 - Remote Code Execution
Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the
30RISK
open ↗Nucleimedium
Custom Product Tabs for WooCommerce < 1.7.8 - Unauthenticated Toggle Content Setting Update
WordPress Custom Product Tabs for WooCommerce plugin <= 1.7.7 - Broken Access Control vulnerability
28RISK
open ↗Nucleimedium
Caddy 2.4.6 - Open Redirect
Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phi
28RISK
open ↗Nucleihigh
D-Link DIR-816L - Improper Access Control
An access control issue in D-Link DIR816L_FW206b01 allows unauthenticated attackers to access folders folder_view.php an
30RISK
open ↗Nucleimedium
Zoho ManageEngine ADSelfService Plus 6121 - Username Enumeration
Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST req
18RISK
open ↗Nucleimedium
Diary Management System 1.0 - Cross-Site Scripting
Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter
18RISK
open ↗Nucleimedium
Online Birth Certificate System 1.2 - Stored Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate
18RISK
open ↗Nucleicritical
Directory Management System 1.0 - SQL Injection
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Manageme
23RISK
open ↗Nucleicritical
Dairy Farm Shop Management System 1.0 - SQL Injection
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Ma
23RISK
open ↗Nucleicritical
Cyber Cafe Management System 1.0 - SQL Injection
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Managem
23RISK
open ↗Nucleicritical
Razer Sila Gaming Router - Remote Code Execution
A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execut
40RISK
open ↗Nucleihigh
Razer Sila Gaming Router 2.0.441_api-2.0.418 - Local File Inclusion
A local file inclusion vulnerability in Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to read arbitrary
23RISK
open ↗Nucleicritical
Node.js Embedded JavaScript 3.1.6 - Template Injection
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[
50RISK
open ↗Nucleicritical
Zoho ManageEngine - Access Control Bypass
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnera
40RISK
open ↗Nucleihigh
HashiCorp Consul/Consul Enterprise - Server-Side Request Forgery
HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the C
18RISK
open ↗Nucleimedium
Nagios XI <5.8.5 - Open Redirect
In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.
18RISK
open ↗Nucleihigh
SolarView Compact 6.00 - Local File Inclusion
SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.
50RISK
open ↗Nucleicritical
SolarView Compact 6.00 - OS Command Injection
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
100RISK
open ↗Nucleihigh
Complete Online Job Search System 1.0 - Cross-Site Scripting
Complete Online Job Search System v1.0 was discovered to contain a SQL injection vulnerability via /eris/index.php?q=res
18RISK
open ↗Nucleimedium
kkFileView 4.0.0 - Cross-Site Scripting
kkFileView v4.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /control
18RISK
open ↗Nucleicritical
NETGEAR ProSafe SSL VPN firmware - SQL Injection
NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USE
50RISK
open ↗Nucleimedium
WordPress Elementor Website Builder <= 3.5.5 - DOM Cross-Site Scripting
WordPress Elementor plugin <= 3.5.5 - Unauthenticated DOM-based Reflected Cross-Site Scripting (XSS) vulnerability
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.