Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,497GitHub PoC 13,627VulnCheck XDB 8,198Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
4,217 exploits
Nucleicritical
Home Assistant Supervisor - Authentication Bypass
homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for
65RISK
open ↗Nucleicritical
Apache Superset - Authentication Bypass
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open ↗Nucleicritical
Dragonfly2 < 2.1.0-beta.1 - Hardcoded JWT Secret
Dragonfly2 vulnerable to hard coded cyptographic key
55RISK
open ↗Nucleimedium
ReadToMyShoe - Generation of Error Message Containing Sensitive Information
ReadtoMyShoe, a web app that lets users upload articles and listen to them later, generates an error message containing
36RISK
open ↗Nucleimedium
WordPress Redirect After Login <= 0.1.9 - Admin Stored XSS
WordPress Redirect After Login Plugin <= 0.1.9 is vulnerable to Cross Site Scripting (XSS)
28RISK
open ↗Nucleicritical
PrestaShop `tshirtecommerce` Module - SQL Injection
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP req
43RISK
open ↗Nucleihigh
tshirtecommerce PrestaShop Module - SQL Injection
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP req
43RISK
open ↗Nucleihigh
PrestaShop TshirteCommerce - Directory Traversal
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP req
36RISK
open ↗Nucleihigh
PrestaShop tshirtecommerce - Directory Traversal
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP req
36RISK
open ↗Nucleimedium
L-Soft LISTSERV 16.5 - Cross-Site Scripting
The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XS
18RISK
open ↗Nucleimedium
Super Socializer < 7.13.52 - Cross-Site Scripting
Super Socializer < 7.13.52 - Reflected XSS
48RISK
open ↗Nucleicritical
Mlflow <2.3.1 - Local File Inclusion Bypass
Path Traversal: '\..\filename' in mlflow/mlflow
43RISK
open ↗Nucleicritical
PrestaShop xipblog - SQL Injection
SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges vi
18RISK
open ↗Nucleimedium
Newsletter < 7.6.9 - Cross-Site Scripting
Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inj
18RISK
open ↗Nucleimedium
EventON <= 2.1 - Missing Authorization
EventON < 2.1.2 - Unauthenticated Event Access
50RISK
open ↗Nucleicritical
WooCommerce Payments - Unauthorized Admin Access
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to s
60RISK
open ↗Nucleimedium
Wordpress Multiple Themes - Reflected Cross-Site Scripting
Multiple Themes - Reflected XSS
18RISK
open ↗Nucleimedium
Ellucian Ethos Identity CAS - Cross-Site Scripting
Ellucian Ethos Identity logout cross site scripting
28RISK
open ↗Nucleihigh
GitLab 16.0.0 - Path Traversal
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RISK
open ↗Nucleicritical
Altenergy Power Control Software C1.2.5 - Remote Command Injection
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RISK
open ↗Nucleihigh
MinIO Cluster Deployment - Information Disclosure
Minio Information Disclosure in Cluster Deployment
100RISK
open ↗Nucleicritical
Wordpress Gift Cards <= 4.3.1 - SQL Injection
The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL in
55RISK
open ↗Nucleimedium
Woo Bulk Price Update <2.2.2 - Cross-Site Scripting
The Woo Bulk Price Update WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnera
28RISK
open ↗Nucleicritical
Quiz and Survey Master <= 8.1.4 - SQL Injection
WordPress Quiz And Survey Master plugin <= 8.1.4 - Unauthenticated SQL Injection vulnerability
43RISK
open ↗Nucleihigh
tagDiv Composer < 4.2 - Stored Cross-Site Scripting
tagDiv Composer < 4.2 - Unauthenticated Stored XSS
28RISK
open ↗Nucleimedium
Owncast - Server Side Request Forgery
Server-Side Request Forgery (SSRF) in owncast/owncast
36RISK
open ↗Nucleicritical
WordPress MStore API <= 4.0.1 - Unauthenticated SQL Injection
MStore API <= 4.0.1 - Unauthenticated SQL Injection
43RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.