Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
4,217 exploits
Nucleicritical
WordPress WPB Show Core <= 2.2 - Server-Side Request Forgery
WPB Show Core <= 2.2 - Unauthenticated Server Side Request Forgery
18RISK
open
Nucleicritical
Hotel Booking Lite < 4.8.5 - Arbitrary File Download & Deletion
Hotel Booking Lite < 4.8.5 - Unauthenticated Arbitrary File Download & Deletion
18RISK
open
Nucleimedium
WordPress Popup Builder <= 4.2.3 - Unauthenticated Stored XSS
Popup Builder < 4.2.3 - Unauthenticated Stored XSS
48RISK
open
Nucleicritical
Mlflow - Arbitrary File Write
MLflow Arbitrary File Write
55RISK
open
Nucleihigh
Ray Static File - Local File Inclusion
Ray Static File Local File Include
41RISK
open
Nucleihigh
Ray API - Local File Inclusion
Ray Log File Local File Include
48RISK
open
Nucleihigh
VertaAI ModelDB - Path Traversal
ModelDB Local File Include
36RISK
open
Nucleicritical
LogDash Activity Log <= 1.1.3 - SQL Injection
LogDash Activity Log < 1.1.4 - Unauthenticated SQLi
28RISK
open
Nucleihigh
H2O ImportFiles - Local File Inclusion
Local File Inclusion in h2oai/h2o-3
43RISK
open
Nucleihigh
WP Fastest Cache 1.2.2 - SQL Injection
WP Fastest Cache < 1.2.2 - Unauthenticated SQL Injection
40RISK
open
Nucleimedium
Quttera Web Malware Scanner <= 3.4.1.48 - Sensitive Data Exposure
Quttera Web Malware Scanner < 3.4.2.1 - Directory Listing to Sensitive Data Exposure
23RISK
open
Nucleihigh
Duplicator < 1.5.7.1; Duplicator Pro < 4.5.14.2 - Unauthenticated Sensitive Data Exposure
Duplicator < 1.5.7.1; Duplicator Pro < 4.5.14.2 - Unauthenticated Sensitive Data Exposure
30RISK
open
Nucleihigh
WordPress Backup Migration <= 1.3.6 - Path Traversal
Backup Migration <= 1.3.6 - Unauthenticated Arbitrary Backup Download to Sensitive Information Exposure
36RISK
open
Nucleimedium
TOTVS Fluig Platform - Cross-Site Scripting
TOTVS Fluig Platform mobileredir openApp.jsp cross site scripting
23RISK
open
Nucleicritical
Control iD iDSecure - Authentication Bypass
Control iD iDSecure passwordCustom Authentication Bypass
75RISK
open
Nucleicritical
WordPress My Calendar <3.4.22 - SQL Injection
The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in th
48RISK
open
Nucleimedium
OpenCMS 14 & 15 - Cross Site Scripting
Cross-site Scripting in Alkacon Software OpenCms
28RISK
open
Nucleimedium
Travelpayouts <= 1.1.16 - Open Redirect
Travelpayouts <= 1.1.15 - Open Redirect
28RISK
open
Nucleicritical
Likeshop < 2.5.7.20210311 - Arbitrary File Upload
Likeshop HTTP POST Request File.php userFormImage unrestricted upload
78RISK
open
Nucleimedium
WordPress Simple Job Board - Unauthorized Data Access
Simple Job Board <= 2.10.8 - Missing Authorization to Unauthenticated Information Disclosure
28RISK
open
Nucleihigh
SolarWinds Security Event Manager - Unauthenticated RCE
SolarWinds Security Event Manager Deserialization of Untrusted Data Remote Code Execution Vulnerability
78RISK
open
Nucleicritical
Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection
Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection
43RISK
open
Nucleihigh
Monitorr Services Configuration - Arbitrary File Upload
15RISK
open
Nucleicritical
Arcserve Unified Data Protection - Authentication Bypass
Authentication Bypass via wizardLogin in Arcserve Unified Data Protection
43RISK
open
Nucleihigh
Arcserve Unified Data Protection - Unauthenticated DoS in ASNative.dll
Unauthenticated DoS in Arcserve Unified Data Protection
48RISK
open
Nucleimedium
Combo Blocks < 2.2.76 - Improper Access Control
Combo Blocks < 2.2.76 - Unauthenticated Password Protected Posts Access
33RISK
open
Nucleicritical
Smart S210 Management Platform - Arbitary File Upload
Byzoro Smart S210 Management Platform uploadfile.php unrestricted upload
40RISK
open
Nucleimedium
Issabel Authenticated - Remote Code Execution
Issabel PBX Asterisk-Cli os command injection
40RISK
open
Nucleicritical
CodeChecker <= 6.24.1 - Authentication Bypass
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
55RISK
open
Nucleimedium
Simple File List < 6.1.13 - Reflected Cross-Site Scripting
Simple File List < 6.1.13 - Reflected Cross-Site Scripting
28RISK
open
previouspage 135 / 141next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.