Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
4,217 exploits
Nucleimedium
MyCryptoCheckout < 2.124 - Cross-Site Scripting
MyCryptoCheckout < 2.124 - Reflected XSS
28RISK
open
Nucleicritical
Sophos Web Appliance - Remote Code Execution
CVE-2023-1671CRITICALunder attack
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISK
open
Nucleicritical
WAGO - Remote Command Execution
WAGO: WBM Command Injection in multiple products
85RISK
open
Nucleicritical
Bitrix Component - Cross-Site Scripting
Bitrix24 Insecure Global Variable Extraction
36RISK
open
Nucleicritical
SupportCandy < 3.1.5 - Unauthenticated SQL Injection
SupportCandy < 3.1.5 - Unauthenticated SQLi
75RISK
open
Nucleimedium
Companion Sitemap Generator < 4.5.3 - Cross-Site Scripting
Companion Sitemap Generator < 4.5.3 - Reflected XSS
18RISK
open
Nucleimedium
Ninja Forms < 3.6.22 - Cross-Site Scripting
Ninja Forms < 3.6.22 - Reflected XSS
28RISK
open
Nucleimedium
Phpmyfaq v3.1.11 - Cross-Site Scripting
Cross-site Scripting (XSS) - Reflected in thorsten/phpmyfaq
36RISK
open
Nucleicritical
WordPress Easy Digital Downloads 3.1.0.2/3.1.0.3 - SQL Injection
The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection
48RISK
open
Nucleimedium
Quick Event Manager < 9.7.5 - Cross-Site Scripting
The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability
28RISK
open
Nucleihigh
Login with Phone Number - Cross-Site Scripting
The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerabili
48RISK
open
Nucleihigh
Mlflow <2.3.0 - Local File Inclusion
Relative Path Traversal in mlflow/mlflow
43RISK
open
Nucleimedium
Joomla! Webservice - Password Disclosure
CVE-2023-23752MEDIUMunder attack
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
Nucleimedium
Ozette Plugins - Cross-Site Request Forgery
WordPress Simple Mobile URL Redirect Plugin <= 1.7.2 is vulnerable to Cross Site Request Forgery (CSRF)
28RISK
open
Nucleicritical
WordPress GamiPress <= 2.5.7 - SQL Injection
WordPress GamiPress Plugin <= 2.5.7 is vulnerable to SQL Injection
36RISK
open
Nucleihigh
CData RSB Connect v22.0.8336 - Server Side Request Forgery
CData RSB Connect v22.0.8336 was discovered to contain a Server-Side Request Forgery (SSRF).
36RISK
open
Nucleimedium
Squidex <7.4.0 - Cross-Site Scripting
Squidex before 7.4.0 was discovered to contain a squid.svg cross-site scripting (XSS) vulnerability.
28RISK
open
Nucleimedium
mojoPortal 2.7.0.0 - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability in the FileDialog.aspx component of mojoPortal v2.7.0.0 allows atta
40RISK
open
Nucleimedium
Temenos T24 R20 - Cross-Site Scripting
15RISK
open
Nucleicritical
UserPro <= 5.1.1 - Authentication Bypass
UserPro <= 5.1.1 - Authentication Bypass to Administrator
63RISK
open
Nucleimedium
Citrix Gateway and Citrix ADC - Cross-Site Scripting
Cross site scripting
70RISK
open
Nucleicritical
Citrix ShareFile StorageZones Controller - Unauthenticated Remote Code Execution
CVE-2023-24489CRITICALunder attack
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, coul
100RISK
open
Nucleimedium
phpIPAM - 1.6 - Cross-Site Scripting
phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter
48RISK
open
Nucleimedium
PMB 7.4.6 - Cross-Site Scripting
PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /ad
18RISK
open
Nucleimedium
PMB 7.4.6 - Open Redirect
PMB v7.4.6 was discovered to contain an open redirect vulnerability via the component /opac_css/pmb.php. This vulnerabil
18RISK
open
Nucleimedium
PMB v7.4.6 - Cross-Site Scripting
PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /ad
18RISK
open
Nucleicritical
Appium Desktop Server - Remote Code Execution
OS Command Injection in appium/appium-desktop
48RISK
open
Nucleicritical
vBulletin <= 5.6.9 - Pre-authentication Remote Code Execution
vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP reques
68RISK
open
Nucleicritical
GeoServer OGC Filter - SQL Injection
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISK
open
Nucleimedium
WordPress Easy Forms for Mailchimp Plugin < 6.8.9 - Cross-Site Scripting
Easy Forms for Mailchimp < 6.8.9 - Reflected XSS
28RISK
open
previouspage 127 / 141next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.