Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,497GitHub PoC 13,627VulnCheck XDB 8,198Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
4,217 exploits
Nucleihigh
WordPress Plugin WP Statistics <= 13.1.5 - SQL Injection
WP Statistics <= 13.1.5 Unauthenticated Blind SQL Injection via current_page_type
55RISK
open ↗Nucleimedium
Wordpress Profile Builder Plugin Cross-Site Scripting
Profile Builder – User Profile & User Registration Forms <= 3.6.1 Reflected Cross-Site Scripting
28RISK
open ↗Nucleihigh
uDraw <3.3.3 - Local File Inclusion
uDraw < 3.3.3 - Unauthenticated Arbitrary File Access
18RISK
open ↗Nucleicritical
CommonsBooking < 2.6.8 - SQL Injection
CommonsBooking < 2.6.8 - Unauthenticated SQL Injection
18RISK
open ↗Nucleihigh
Microweber <1.2.11 - Information Disclosure
Generation of Error Message Containing Sensitive Information in microweber/microweber
43RISK
open ↗Nucleihigh
Microweber < 1.2.11 - CRLF Injection
CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microweber
48RISK
open ↗Nucleimedium
Microweber <1.2.11 - Cross-Site Scripting
Cross-site Scripting (XSS) - Reflected in microweber/microweber
28RISK
open ↗Nucleicritical
WordPress Narnoo Distributor <=2.5.1 - Local File Inclusion
Narnoo Distributor <= 2.5.1 - Unauthenticated LFI to Arbitrary File Read / RCE
30RISK
open ↗Nucleimedium
Rudloff alltube prior to 3.0.1 - Open Redirect
Open Redirect on Rudloff/alltube in rudloff/alltube
28RISK
open ↗Nucleicritical
WordPress Master Elements <=8.0 - SQL Injection
Master Elements <= 8.0 - Unauthenticated SQLi
18RISK
open ↗Nucleicritical
GitLab CE/EE - Information Disclosure
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions star
48RISK
open ↗Nucleicritical
Infographic Maker iList < 4.3.8 - SQL Injection
Infographic Maker - iList < 4.3.8 - Unauthenticated SQL Injection
23RISK
open ↗Nucleicritical
WordPress Simple Link Directory <7.7.2 - SQL injection
Simple Link Directory < 7.7.2 - Unauthenticated SQL injection
23RISK
open ↗Nucleimedium
WordPress Loco Translate < 2.6.1 - Cross-Site Scripting
Loco Translate < 2.6.1 - Authenticated Stored Cross-Site Scripting
18RISK
open ↗Nucleicritical
Users Ultra <= 3.1.0 - SQL Injection
Users Ultra <= 3.1.0 - Unauthenticated SQL Injection
18RISK
open ↗Nucleicritical
Documentor <= 1.5.3 - Unauthenticated SQL Injection
Documentor <= 1.5.3 - Unauthenticated SQLi
30RISK
open ↗Nucleimedium
RevealJS postMessage <4.3.0 - Cross-Site Scripting
Cross-site Scripting (XSS) - DOM in hakimel/reveal.js
28RISK
open ↗Nucleicritical
WordPress Nirweb Support <2.8.2 - SQL Injection
Nirweb support < 2.8.2 - Unauthenticated SQLi
23RISK
open ↗Nucleihigh
Multiple Shipping Address Woocommerce < 2.0 - SQL Injection
Multiple Shipping Address Woocommerce < 2.0 - Unauthenticated SQLi
18RISK
open ↗Nucleicritical
WordPress Title Experiments Free <9.0.1 - SQL Injection
Title Experiments Free < 9.0.1 - Unauthenticated SQLi
23RISK
open ↗Nucleicritical
Oracle E-Business Suite 12.2.3 -12.2.11 - Remote Code Execution
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
100RISK
open ↗Nucleimedium
WordPress Download Manager < 3.2.44 - Authenticated Cross-Site Scripting
Download Manager < 3.2.44 - Reflected Cross-Site Scripting
18RISK
open ↗Nucleihigh
October CMS - Remote Code Execution
Authenticated remote code execution in octobercms
36RISK
open ↗Nucleimedium
microweber 1.2.18 - Cross-site Scripting
Cross-site Scripting (XSS) - Reflected in microweber/microweber
28RISK
open ↗Nucleihigh
GitLab CE/EE - Remote Code Execution
A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to
85RISK
open ↗Nucleimedium
WordPress Contact Form 7 Captcha <0.1.2 - Cross-Site Scripting
Contact Form 7 Captcha < 0.1.2 - Reflected Cross-Site Scripting
18RISK
open ↗Nucleihigh
Unyson < 2.7.27 - Cross Site Scripting
Unyson < 2.7.27 - Reflected Cross-Site Scripting
18RISK
open ↗Nucleimedium
Juniper Web Device Manager - Cross-Site Scripting
Junos OS: Cross-site Scripting (XSS) vulnerability in J-Web
48RISK
open ↗Nucleicritical
SAP Memory Pipes (MPI) Desynchronization
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.