Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,497GitHub PoC 13,627VulnCheck XDB 8,198Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
4,217 exploits
Nucleihigh
SEH utnserver Pro/ProMAX/INU-100 20.1.22 - File Exposure
Authenticated Command Injection
36RISK
open ↗Nucleihigh
Hurrakify <= 2.4 - Server-Side Request Forgery
WordPress Hurrakify plugin <= 2.4 - Server Side Request Forgery (SSRF) vulnerability
36RISK
open ↗Nucleihigh
Radio Player <= 2.0.82 - Server-Side Request Forgery
WordPress Radio Player plugin <= 2.0.83 - Server Side Request Forgery (SSRF) vulnerability
36RISK
open ↗Nucleimedium
ipTIME A2004 - Unauthorized Access
An access control issue in the component /login/hostinfo.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensiti
28RISK
open ↗Nucleimedium
ipTIME A2004 - Unauthorized Access
An access control issue in the component /login/hostinfo2.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensit
28RISK
open ↗Nucleihigh
AVM FRITZ!Box 7530 AX - Unauthorized Access
An access control issue in the component /juis_boxinfo.xml of AVM FRITZ!Box 7530 AX v7.59 allows attackers to obtain sen
36RISK
open ↗Nucleimedium
LearnPress < 4.2.6.8.1 - Information Disclosure
LearnPress – WordPress LMS Plugin <= 4.2.6.8 - Basic Information Disclosure via JSON API
28RISK
open ↗Nucleicritical
SEOPress < 7.9 - Authentication Bypass
SEOPress < 7.9 - Unauthenticated Object Injection
63RISK
open ↗Nucleimedium
IceWarp Server 10.2.1 - Cross-Site Scripting
IceWarp Server 10.2.1 is vulnerable to Cross Site Scripting (XSS) via the meta parameter.
28RISK
open ↗Nucleicritical
WordPress HTML5 Video Player < 2.5.27 - SQL Injection
HTML5 Video Player < 2.5.27 - Unauthenticated SQLi
28RISK
open ↗Nucleihigh
DevDojo Voyager <=1.8.0 - Arbitrary File Read
DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.
33RISK
open ↗Nucleilow
DevDojo Voyager <=1.8.0 - Cross-Site Scripting
DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticate
28RISK
open ↗Nucleihigh
DevDojo Voyager <= 1.8.0 - Arbitrary File Write vulnerability
DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user u
33RISK
open ↗Nucleimedium
AI Assistant with ChatGPT by AYS <= 2.0.9 - Unauthenticated AJAX Calls
AI Assistant with ChatGPT by AYS <= 2.0.9 - Unauthenticated AJAX Calls
28RISK
open ↗Nucleihigh
Sensei LMS < 4.24.2 - Email Template Leak
Sensei LMS < 4.24.2 - Unauthenticated Email Template Leak
36RISK
open ↗Nucleicritical
Woo Inquiry <= 0.1 - SQL Injection
Woo Inquiry <= 0.1 - Unauthenticated SQL Injection
63RISK
open ↗Nucleicritical
SPIP Porte Plume Plugin - Remote Code Execution
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISK
open ↗Nucleihigh
WordPress Clean Login <= 1.14.5 Authenticated (Contributor+) - Local File Inclusion
Clean Login <= 1.14.5 - Authenticated (Contributor+) Local File Inclusion
36RISK
open ↗Nucleicritical
GiveWP Donation Plugin <= 3.16.1 - Unauthenticated PHP Object Injection
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
68RISK
open ↗Nucleicritical
WooCommerce Ultimate Gift Card ≤ 2.6.0 - Arbitrary File Upload
WooCommerce Ultimate Gift Card <= 2.9.2 - Unauthenticated Arbitrary File Upload
63RISK
open ↗Nucleihigh
REST API TO MiniProgram <= 4.7.1 - SQL Injection
REST API TO MiniProgram <= 4.7.1 - Unauthenticated SQL Injection
36RISK
open ↗Nucleicritical
SPIP BigUp Plugin - Remote Code Execution
SPIP Bigup Multipart File Upload OS Command Injection
85RISK
open ↗Nucleicritical
LearnPress < 4.2.7.1 - SQL Injection
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'
75RISK
open ↗Nucleicritical
LearnPress < 4.2.7.1 - SQL Injection
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'
68RISK
open ↗Nucleihigh
WordPress TS Poll < 2.4.0 - SQL Injection
TS Poll – Survey, Versus Poll, Image Poll, Video Poll < 2.4.0 - Admin+ SQL Injection
36RISK
open ↗Nucleilow
Z-Downloads < 1.11.7 - Cross-Site Scripting
Z-Downloads < 1.11.7 - Admin+ Stored XSS via SVG Upload
63RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.