Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,497GitHub PoC 13,627VulnCheck XDB 8,198Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
4,217 exploits
Nucleihigh
Linksys E2000 1.0.06 position.js Improper Authentication
Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.
41RISK
open ↗Nucleihigh
ChatGPT个人专用版 - Server Side Request Forgery
pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references sec
60RISK
open ↗Nucleicritical
Contact Form Plugin by Fluent Forms < 5.1.17 - Unauthenticated Limited Privilege Escalation
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Settings Update and Limited Privilege Escalation
63RISK
open ↗Nucleihigh
Smart s200 Management Platform v.S200 - SQL Injection
SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain s
36RISK
open ↗Nucleihigh
WordPress FluentForms <= 5.1.16 - Broken Access Control
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Setting Manipulation
56RISK
open ↗Nucleicritical
WordPress Automatic Plugin <3.92.1 - Arbitrary File Download and SSRF
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
85RISK
open ↗Nucleicritical
WordPress Automatic Plugin <= 3.92.0 - SQL Injection
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open ↗Nucleicritical
WordPress LiteSpeed Cache - Unauthenticated Privilege Escalation to Admin
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISK
open ↗Nucleicritical
N-able N-central < 2024.2 - Authentication Bypass Detection
N-central Authentication Bypass
43RISK
open ↗Nucleicritical
OpenMetaData - SpEL Injection in PUT /api/v1/policies
SpEL Injection in `PUT /api/v1/policies` in OpenMetadata
48RISK
open ↗Nucleimedium
pyload-ng js2py - Remote Code Execution
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISK
open ↗Nucleihigh
LG LED Assistant - Unauthenticated Password Reset
Password reset vulnerability without authorization on LG LED Assistant
55RISK
open ↗Nucleimedium
RiteCMS 3.0.0 - Cross-site Scripting
RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_sec
48RISK
open ↗Nucleihigh
LG LED Assistant - Thumbnail Path Traversal File Upload
Path traversal via file upload on LG LED Assistant
40RISK
open ↗Nucleimedium
Coda v.2024Q1 - Cross-Site Scripting
Cross Site Scripting vulnerability in Unit4 Financials by Coda prior to 2023Q4 allows a remote attacker to run arbitrary
28RISK
open ↗Nucleihigh
Apache CXF < 4.0.4 - Aegis DataBinding SSRF / Local File Read
Apache CXF SSRF Vulnerability using the Aegis databinding
63RISK
open ↗Nucleicritical
Wordpress Email Subscribers by Icegram Express - SQL Injection
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RISK
open ↗Nucleihigh
WordPress Plugin LayerSlider 7.9.11-7.10.0 - SQL Injection
The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.1
68RISK
open ↗Nucleicritical
SolarWinds Web Help Desk < 12.8.3 - Insecure Deserialization
SolarWinds Web Help Desk Java Deserialization Remote Code Execution Vulnerability
95RISK
open ↗Nucleicritical
SolarWinds Web Help Desk - Hardcoded Credential
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RISK
open ↗Nucleimedium
Changedetection.io <=v0.45.21 - Cross-Site Scripting
Reflected cross site scripting in changedetection.io
28RISK
open ↗Nucleicritical
D-Tale 3.10.0 - 3.15.1 - Authentication Bypass & Remote Code Execution
Authentication Bypass and RCE in man-group/dtale
85RISK
open ↗Nucleicritical
Adobe Commerce & Magento - CosmicSting
XXE can expose crypt key and other secrets granting full admin access
100RISK
open ↗Nucleihigh
TOTOLINK EX1800T TOTOLINK EX1800T - Command Injection
TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized e
43RISK
open ↗Nucleihigh
Next.js - Server Side Request Forgery (SSRF)
Next.js Server-Side Request Forgery in Server Actions
36RISK
open ↗Nucleihigh
HSC Mailinspector 5.2.17-3 through 5.2.18 - Local File Inclusion
An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability
36RISK
open ↗Nucleimedium
GP Premium <= 2.4.0 - Cross-Site Scripting
GP Premium <= 2.4.0 - Reflected Cross-Site Scripting
28RISK
open ↗Nucleicritical
Wordpress Country State City Dropdown <=2.7.2 - SQL Injection
Country State City Dropdown CF7 <= 2.7.2 - Unauthenticated SQL Injection
68RISK
open ↗Nucleihigh
LyLme-Spage - Arbitary File Upload
An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to exec
43RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.