Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
4,217 exploits
Nucleihigh
Lightdash v0.1024.6 - Server-Side Request Forgery
Lightdash version 0.1024.6 allows users with the necessary permissions, such as Administrator or Editor, to create and s
36RISK
open
Nucleihigh
LiteLLM - Server-Side Request Forgery
SSRF in berriai/litellm
48RISK
open
Nucleimedium
Netgear-WN604 downloadFile.php - Information Disclosure
Netgear WN604 Web Interface downloadFile.php information disclosure
40RISK
open
Nucleihigh
WordPress File Upload Plugin < 4.24.8 - Cross-Site Scripting
WordPress File Upload < 4.24.8 - Reflected XSS
33RISK
open
Nucleicritical
WhatsUp Gold HasErrors SQL Injection - Authentication Bypass
CVE-2024-6670CRITICALunder attackransomware
WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability
100RISK
open
Nucleicritical
WhatsUp Gold GetStatisticalMonitorList SQL Injection - Authentication Bypass
WhatsUp Gold GetStatisticalMonitorList SQL Injection Authentication Bypass Vulnerability
48RISK
open
Nucleimedium
WP Content Copy Protection & No Right Click - Open Redirect
WP Content Copy Protection & No Right Click (premium) < 15.3 - Open Redirect
28RISK
open
Nucleimedium
EasySpider 0.6.2 - Arbitrary File Read
NaiboWang EasySpider HTTP GET Request server.js path traversal
28RISK
open
Nucleihigh
Social Auto Poster <= 5.3.14 - Stored Cross-Site Scripting
Social Auto Poster <= 5.3.14 - Unauthenticated Stored Cross-Site Scripting
36RISK
open
Nucleihigh
Calibre <= 7.14.0 Arbitrary File Read
Calibre Arbitrary File Read
48RISK
open
Nucleicritical
Calibre <= 7.14.0 Remote Code Execution
Calibre Remote Code Execution
85RISK
open
Nucleihigh
AnythingLLM - Information Disclosure
Exposure of Sensitive Information in mintplex-labs/anything-llm
48RISK
open
Nucleimedium
SmartSearchWP < 2.4.6 - OpenAI Key Disclosure
SmartSearchWP < 2.4.6 - Unauthenticated OpenAI Key Disclosure
28RISK
open
Nucleimedium
SmartSearchWP <= 2.4.4 - Unauthenticated Log Purge
SmartSearchWP <= 2.4.4 - Unauthenticated Log Purge
28RISK
open
Nucleimedium
Gitea 1.22.0 - Cross-Site Scripting
Inproper Sanitation of field leading to stored XSS
55RISK
open
Nucleimedium
Journyx 11.5.4 - Reflected Cross Site Scripting
Journyx Reflected Cross Site Scripting
28RISK
open
Nucleihigh
Journyx - XML External Entities Injection (XXE)
Journyx Unauthenticated XML External Entities Injection
48RISK
open
Nucleihigh
PerkinElmer ProcessPlus <= 1.11.6507.0 - Local File Inclusion
Unauthenticated Local File Inclusion
36RISK
open
Nucleihigh
Automation Anywhere Automation 360 - Server-Side Request Forgery
Server-Side Request Forgery in Automation 360
40RISK
open
Nucleihigh
TrueBooker <= 1.0.2 - SQL Injection
TrueBooker < 1.0.3 - Multiple Unauthenticated SQLi
63RISK
open
Nucleicritical
Viral Signup <= 2.1 - SQL Injection
Viral Signup <= 2.1 - Unauthenticated SQLi
63RISK
open
Nucleihigh
Opti Marketing <= 2.0.9 - SQL Injection
Opti Marketing <= 2.0.9 - Unauthenticated SQLi
63RISK
open
Nucleimedium
Calibre <= 7.15.0 - Reflected Cross-Site Scripting (XSS)
Calibre Reflected Cross-Site Scripting (XSS)
33RISK
open
Nucleihigh
AVTECH IP Camera - Command Injection
Command Injection in AVTech AVM1203 (IP Camera)
68RISK
open
Nucleimedium
WSO2 User Registration - Arbitrary Account Creation
Incorrect Authorization in Multiple WSO2 Products via SOAP Admin Service Allowing Unauthorized User Signup
28RISK
open
Nucleimedium
Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90 - Command Injection
Raisecom MSG1200/MSG2100E/MSG2200/MSG2300 Web Interface list_base_config.php os command injection
70RISK
open
Nucleihigh
Bylancer Quicklancer 2.4 G - SQL Injection
Bylancer Quicklancer GET Parameter listing sql injection
28RISK
open
Nucleimedium
Shield Security Plugin < 20.0.6 - Cross-Site Scripting
Shield Security < 20.0.6 - Reflected XSS
28RISK
open
Nucleicritical
AJ-Report < 1.4.1 - Remote Code Execution
anji-plus AJ-Report Authentication Bypass
75RISK
open
Nucleicritical
TOTOLINK CP450 v4.1.0cu.747_B20191224 - Hard-Coded Password Vulnerability
TOTOLINK CP450 Telnet Service product.ini hard-coded password
68RISK
open
previouspage 134 / 141next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.