Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,497GitHub PoC 13,627VulnCheck XDB 8,198Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
4,217 exploits
Nucleicritical
WordPress WPB Show Core <= 2.2 - Server-Side Request Forgery
WPB Show Core <= 2.2 - Unauthenticated Server Side Request Forgery
18RISK
open ↗Nucleicritical
Hotel Booking Lite < 4.8.5 - Arbitrary File Download & Deletion
Hotel Booking Lite < 4.8.5 - Unauthenticated Arbitrary File Download & Deletion
18RISK
open ↗Nucleimedium
WordPress Popup Builder <= 4.2.3 - Unauthenticated Stored XSS
Popup Builder < 4.2.3 - Unauthenticated Stored XSS
48RISK
open ↗Nucleicritical
LogDash Activity Log <= 1.1.3 - SQL Injection
LogDash Activity Log < 1.1.4 - Unauthenticated SQLi
28RISK
open ↗Nucleihigh
WP Fastest Cache 1.2.2 - SQL Injection
WP Fastest Cache < 1.2.2 - Unauthenticated SQL Injection
40RISK
open ↗Nucleimedium
Quttera Web Malware Scanner <= 3.4.1.48 - Sensitive Data Exposure
Quttera Web Malware Scanner < 3.4.2.1 - Directory Listing to Sensitive Data Exposure
23RISK
open ↗Nucleihigh
Duplicator < 1.5.7.1; Duplicator Pro < 4.5.14.2 - Unauthenticated Sensitive Data Exposure
Duplicator < 1.5.7.1; Duplicator Pro < 4.5.14.2 - Unauthenticated Sensitive Data Exposure
30RISK
open ↗Nucleihigh
WordPress Backup Migration <= 1.3.6 - Path Traversal
Backup Migration <= 1.3.6 - Unauthenticated Arbitrary Backup Download to Sensitive Information Exposure
36RISK
open ↗Nucleimedium
TOTVS Fluig Platform - Cross-Site Scripting
TOTVS Fluig Platform mobileredir openApp.jsp cross site scripting
23RISK
open ↗Nucleicritical
Control iD iDSecure - Authentication Bypass
Control iD iDSecure passwordCustom Authentication Bypass
75RISK
open ↗Nucleicritical
WordPress My Calendar <3.4.22 - SQL Injection
The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in th
48RISK
open ↗Nucleimedium
OpenCMS 14 & 15 - Cross Site Scripting
Cross-site Scripting in Alkacon Software OpenCms
28RISK
open ↗Nucleimedium
Travelpayouts <= 1.1.16 - Open Redirect
Travelpayouts <= 1.1.15 - Open Redirect
28RISK
open ↗Nucleicritical
Likeshop < 2.5.7.20210311 - Arbitrary File Upload
Likeshop HTTP POST Request File.php userFormImage unrestricted upload
78RISK
open ↗Nucleimedium
WordPress Simple Job Board - Unauthorized Data Access
Simple Job Board <= 2.10.8 - Missing Authorization to Unauthenticated Information Disclosure
28RISK
open ↗Nucleihigh
SolarWinds Security Event Manager - Unauthenticated RCE
SolarWinds Security Event Manager Deserialization of Untrusted Data Remote Code Execution Vulnerability
78RISK
open ↗Nucleicritical
Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection
Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection
43RISK
open ↗Nucleicritical
Arcserve Unified Data Protection - Authentication Bypass
Authentication Bypass via wizardLogin in Arcserve Unified Data Protection
43RISK
open ↗Nucleihigh
Arcserve Unified Data Protection - Unauthenticated DoS in ASNative.dll
Unauthenticated DoS in Arcserve Unified Data Protection
48RISK
open ↗Nucleimedium
Combo Blocks < 2.2.76 - Improper Access Control
Combo Blocks < 2.2.76 - Unauthenticated Password Protected Posts Access
33RISK
open ↗Nucleicritical
Smart S210 Management Platform - Arbitary File Upload
Byzoro Smart S210 Management Platform uploadfile.php unrestricted upload
40RISK
open ↗Nucleimedium
Issabel Authenticated - Remote Code Execution
Issabel PBX Asterisk-Cli os command injection
40RISK
open ↗Nucleicritical
CodeChecker <= 6.24.1 - Authentication Bypass
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
55RISK
open ↗Nucleimedium
Simple File List < 6.1.13 - Reflected Cross-Site Scripting
Simple File List < 6.1.13 - Reflected Cross-Site Scripting
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.