Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,432cataloged exploits
34,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,493GitHub PoC 13,618VulnCheck XDB 8,198Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
4,217 exploits
Nucleihigh
Spring Cloud Netflix Hystrix Dashboard <2.2.10 - Remote Code Execution
Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to exe
23RISK
open ↗Nucleihigh
VMWare Workspace ONE UEM - Server-Side Request Forgery
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and
100RISK
open ↗Nucleimedium
FortiWeb - Cross Site Scripting
An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version
23RISK
open ↗Nucleimedium
Elasticsearch 7.10.0-7.13.3 - Information Disclosure
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the abil
60RISK
open ↗Nucleihigh
GitLab CI Lint API - Server-Side Request Forgery
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab af
70RISK
open ↗Nucleicritical
GitLab CE/EE - Remote Code Execution
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open ↗Nucleihigh
Gitlab CE/EE 10.5 - Server-Side Request Forgery
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE
53RISK
open ↗Nucleicritical
Micro Focus Operations Bridge Reporter - Remote Code Execution
Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The
100RISK
open ↗Nucleicritical
EVlink City < R8 V3.4.0.1 - Authentication Bypass
A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to
30RISK
open ↗Nucleimedium
Revive Adserver <5.1.0 - Open Redirect
Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg
50RISK
open ↗Nucleimedium
Ruby on Rails - Open Redirect via Host Header Injection
The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Sp
40RISK
open ↗Nucleicritical
Rocket.Chat <=3.13 - NoSQL Injection
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open ↗Nucleicritical
F5 iControl REST - Remote Command Execution
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open ↗Nucleimedium
MERCUSYS Mercury X18G 1.0.5 Router - Local File Inclusion
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (
23RISK
open ↗Nucleicritical
10Web Photo Gallery < 1.5.55 - SQL Injection
Photo Gallery by 10Web < 1.5.55 - Unauthenticated SQL Injection
18RISK
open ↗Nucleihigh
WordPress Modern Events Calendar Lite <5.16.5 - Authenticated Arbitrary File Upload
Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE
60RISK
open ↗Nucleihigh
WordPress Modern Events Calendar Lite <5.16.5 - Sensitive Information Disclosure
Modern Events Calendar Lite < 5.16.5 - Unauthenticated Events Export
50RISK
open ↗Nucleihigh
WordPress Like Button Rating <2.6.32 - Server-Side Request Forgery
Like Button Rating < 2.6.32 - Unauthenticated Full-Read SSRF
18RISK
open ↗Nucleihigh
WordPress BackupGuard <1.6.0 - Authenticated Arbitrary File Upload
Backup Guard < 1.6.0 - Authenticated Arbitrary File Upload
60RISK
open ↗Nucleimedium
WordPress Ninja Forms <3.4.34 - Open Redirect
Ninja Forms < 3.4.34 - Administrator Open Redirect
18RISK
open ↗Nucleimedium
WordPress Advanced Order Export For WooCommerce <3.1.8 - Authenticated Cross-Site Scripting
Advanced Order Export For WooCommerce < 3.1.8 - Reflected Cross-Site Scripting (XSS)
43RISK
open ↗Nucleihigh
User Profile Picture < 2.5.0 - Sensitive Information Disclosure
User Profile Picture < 2.5.0 - Sensitive Information Disclosure
18RISK
open ↗Nucleicritical
The Plus Addons for Elementor Page Builder < 4.1.7 - Authentication Bypass
The Plus Addons for Elementor Page Builder < 4.1.7 - Authentication Bypass
23RISK
open ↗Nucleimedium
WordPress JH 404 Logger <=1.1 - Cross-Site Scripting
JH 404 Logger <= 1.1 - Unauthenticated Stored Cross-Site Scripting (XSS)
18RISK
open ↗Nucleimedium
WordPress PhastPress <1.111 - Open Redirect
PhastPress < 1.111 - Open Redirect
18RISK
open ↗Nucleicritical
WooCommerce Help Scout - Arbitrary File Upload
WooCommerce Help Scout < 2.9.1 - Unauthenticated Arbitrary File Upload leading to RCE
18RISK
open ↗Nucleimedium
GiveWP <= 2.9.7 - Cross-Site Scripting
GiveWP < 2.10.0 - Reflected Cross Site Scripting (XSS)
18RISK
open ↗Nucleimedium
WordPress OpenID Connect Generic Client 3.8.0-3.8.1 - Cross-Site Scripting
OpenID Connect Generic Client 3.8.0-3.8.1 - Reflected Cross Site Scripting (XSS) via Login Error
18RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.