Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,444cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,497GitHub PoC 13,626VulnCheck XDB 8,198Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
4,217 exploits
Nucleihigh
Pre-Auth Takeover of Build Pipelines in GoCD
An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default,
43RISK
open ↗Nucleicritical
Studio-42 elFinder <2.1.60 - Arbitrary File Upload
A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remot
30RISK
open ↗Nucleihigh
AlquistManager Local File Inclusion
AlquistManager branch as of commit 280d99f43b11378212652e75f6f3159cde9c1d36 is affected by a directory traversal vulnera
18RISK
open ↗Nucleihigh
Clustering Local File Inclusion
Clustering master branch as of commit 53e663e259bcfc8cdecb56c0bb255bd70bfcaa70 is affected by a directory traversal vuln
23RISK
open ↗Nucleicritical
Sourcecodester Simple Client Management System 1.0 - SQL Injection
SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login
18RISK
open ↗Nucleimedium
Atmail 6.5.0 - Cross-Site Scripting
WebAdmin Control Panel in Atmail 6.5.0 (a version released in 2012) allows XSS via the format parameter to the default U
18RISK
open ↗Nucleimedium
Spotweb <= 1.5.1 - Cross Site Scripting (Reflected)
There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remot
18RISK
open ↗Nucleihigh
kkFileview v4.0.0 - Local File Inclusion
kkFileview v4.0.0 has arbitrary file read through a directory traversal vulnerability which may lead to sensitive file l
23RISK
open ↗Nucleicritical
WordPress Automatic Plugin - Unauthenticated Options Change
WordPress Automatic Plugin <= 3.53.2 - Unauthenticated Arbitrary Options Update
48RISK
open ↗Nucleihigh
GLPI plugin Barcode < 2.6.1 - Path Traversal Vulnerability.
Path traversal in GLPI barcode plugin
75RISK
open ↗Nucleicritical
Pinterest Automatic < 4.14.4 - Unauthenticated Arbitrary Options Update
Pinterest Automatic <= 4.14.3 - Unuathenticated Arbitrary Options Update
43RISK
open ↗Nucleimedium
Admidio - Cross-Site Scripting
Cross-site Scripting (XSS) when redirect an url
36RISK
open ↗Nucleihigh
Gradio < 2.5.0 - Arbitrary File Read
Files on the host computer can be accessed from the Gradio interface
36RISK
open ↗Nucleicritical
Zoho ManageEngine ServiceDesk Plus - Remote Code Execution
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014
100RISK
open ↗Nucleihigh
Caucho Resin >=4.0.52 <=4.0.56 - Directory traversal
There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remo
23RISK
open ↗Nucleihigh
Alibaba Sentinel - Server-side request forgery (SSRF)
Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF).
18RISK
open ↗Nucleicritical
Reprise License Manager 14.2 - Authentication Bypass
An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or a
30RISK
open ↗Nucleimedium
WordPress White Label CMS <2.2.9 - Cross-Site Scripting
White Label MS < 2.2.9 - Reflected Cross-Site Scripting
18RISK
open ↗Nucleimedium
Popup by Supsystic < 1.10.9 - Subscriber Email Addresses Disclosure
Popup by Supsystic < 1.10.9 - Unauthenticated Subscriber Email Addresses Disclosure
18RISK
open ↗Nucleimedium
WP Cerber Security, Anti-spam & Malware Scan < 8.9.6 - Cross-Site Scripting
WP Cerber Security, Anti-spam & Malware Scan < 8.9.6 - Unauthenticated Stored Cross-Site Scripting
18RISK
open ↗Nucleimedium
Mastodon Prototype Pollution Vulnerability
Prototype Pollution in mastodon/mastodon
36RISK
open ↗Nucleicritical
WordPress Page Views Count <2.4.15 - SQL Injection
Page Views Count < 2.4.15 - Unauthenticated SQL Injection
23RISK
open ↗Nucleimedium
karma-runner DOM-based Cross-Site Scripting
Cross-site Scripting (XSS) - DOM in karma-runner/karma
33RISK
open ↗Nucleihigh
Email Subscribers & Newsletters <= 5.3.1 - Authenticated SQL Injection
Email Subscribers & Newsletters < 5.3.2 - Subscriber+ Blind SQL injection
18RISK
open ↗Nucleicritical
MasterStudy LMS <2.7.6 - Improper Access Control
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
60RISK
open ↗Nucleicritical
Popup Builder Plugin - SQL Injection and Cross-Site Scripting
Popup Builder < 4.1.1 - SQL Injection to Reflected Cross-Site Scripting
30RISK
open ↗Nucleicritical
Easy!Appointments <1.4.3 - Broken Access Control
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
75RISK
open ↗Nucleimedium
Ditty (formerly Ditty News Ticker) < 3.0.15 - Cross-Site Scripting
Ditty (formerly Ditty News Ticker) < 3.0.15 - Reflected Cross-Site Scripting (XSS)
18RISK
open ↗Nucleimedium
WordPress E2Pdf <1.16.45 - Cross-Site Scripting
E2Pdf < 1.16.45 - Admin+ Stored Cross-Site Scripting (XSS)
18RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.