Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,497GitHub PoC 13,627VulnCheck XDB 8,198Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
4,217 exploits
Nucleicritical
NotificationX Dropshipping < 4.4 - SQL Injection
WooCommerce Dropshipping < 4.4 - Unauthenticated SQLi
63RISK
open ↗Nucleimedium
WordPress WPB Show Core - Cross-Site Scripting
WPB Show Core - Reflected Cross-Site Scripting
28RISK
open ↗Nucleimedium
WordPress Related Posts <2.1.3 - Stored Cross-Site Scripting
Cross-site Scripting (XSS) - Stored in barrykooij/related-posts-for-wp
28RISK
open ↗Nucleimedium
kkFileView 4.1.0 - Cross-Site Scripting
kkFileView v4.1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the urls and current
18RISK
open ↗Nucleicritical
Zoho ManageEngine - Remote Code Execution
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code
100RISK
open ↗Nucleicritical
WAPPLES Web Application Firewall <=6.0 - Hardcoded Credentials
WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configur
23RISK
open ↗Nucleimedium
H3C SSL VPN <=2022-07-10 - Cross-Site Scripting
H3C SSL VPN through 2022-07-10 allows wnm/login/login.json svpnlang cookie XSS.
18RISK
open ↗Nucleimedium
eShop 3.0.4 - Cross-Site Scripting
A Cross-site scripting (XSS) vulnerability in json search parse and the json response in wrteam.in, eShop - Multipurpose
28RISK
open ↗Nucleihigh
Proxmox - CRLF Injection
A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) w
28RISK
open ↗Nucleimedium
Moodle LTI module Reflected - Cross-Site Scripting
A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitizat
18RISK
open ↗Nucleimedium
WordPress ProfileGrid <5.1.1 - Cross-Site Scripting
ProfileGrid < 5.1.1 - Reflected Cross-Site Scripting
28RISK
open ↗Nucleimedium
WordPress <= 6.2 - Server Side Request Forgery
WP <= 6.1.1 - Unauthenticated Blind SSRF via DNS Rebinding
48RISK
open ↗Nucleicritical
GLPI <=10.0.2 - Remote Command Execution
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISK
open ↗Nucleicritical
Webmin <1.997 - Authenticated Remote Code Execution
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
60RISK
open ↗Nucleihigh
ZK Framework - Information Disclosure
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafte
100RISK
open ↗Nucleicritical
Hytec Inter HWL-2511-SS - Remote Command Execution
Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /w
60RISK
open ↗Nucleicritical
Omnia MPX 1.5.0+r1 - Local File Inclusion
A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 all
18RISK
open ↗Nucleihigh
Atlassian Bitbucket - Remote Command Injection
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open ↗Nucleihigh
Jenkins Git <=4.11.3 - Missing Authorization
A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds o
18RISK
open ↗Nucleihigh
Zoho ManageEngine - getUserAPIKey Authentication Bypass
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall An
28RISK
open ↗Nucleicritical
Zimbra Collaboration Suite 8.8.15/9.0 - Remote Code Execution
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts fi
100RISK
open ↗Nucleicritical
FLIR AX8 1.46.16 - Remote Command Injection
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This
60RISK
open ↗Nucleihigh
Carel pCOWeb HVAC BACnet Gateway 2.1.0 - Path Traversal
Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 s
23RISK
open ↗Nucleimedium
Artica Proxy 4.30.000000 - Cross-Site Scripting
An issue was discovered in Artica Proxy 4.30.000000. There is a XSS vulnerability via the password parameter in /fw.logi
18RISK
open ↗Nucleihigh
Cuppa CMS v1.0 - Remote Code Execution
CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and
30RISK
open ↗Nucleimedium
Cuppa CMS v1.0 - Authenticated Local File Inclusion
The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files v
18RISK
open ↗Nucleimedium
Shirne CMS 1.2.0 - Local File Inclusion
An issue was discovered in Shirne CMS 1.2.0. There is a Path Traversal vulnerability which could cause arbitrary file re
18RISK
open ↗Nucleimedium
phpMyFAQ < 3.1.8 - Cross-Site Scripting
Cross-site Scripting (XSS) - Reflected in thorsten/phpmyfaq
56RISK
open ↗Nucleihigh
WordPress WPSmartContracts <1.3.12 - SQL Injection
WPSmartContracts < 1.3.12 - Author+ SQLi
36RISK
open ↗Nucleihigh
HP Switch - Authentication Bypass
A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S
56RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.