Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
4,217 exploits
Nucleicritical
PSW Front-end Login & Registration 1.13 - Weak Password Recovery
WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerability
68RISK
open
Nucleimedium
Label Studio < 1.18.0 - Reflected XSS
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
36RISK
open
Nucleicritical
Wing FTP Server <= 7.4.3 - Remote Code Execution
CVE-2025-47812CRITICALunder attack
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
Nucleimedium
Wing FTP Server <= 7.4.3 - Path Disclosure via Overlong UID Cookie
CVE-2025-47813MEDIUMunder attack
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a
70RISK
open
Nucleicritical
Invision Community <=5.0.6 Unauthenticated RCE via Template Injection
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The
85RISK
open
Nucleicritical
WordPress Formality Plugin <= 1.5.9 - Local File Inclusion
WordPress Formality <= 1.5.9 - Local File Inclusion Vulnerability
36RISK
open
Nucleicritical
MyStyle Custom Product Designer <= 3.21.1 - SQL Injection
WordPress MyStyle Custom Product Designer plugin <= 3.21.1 - SQL Injection Vulnerability
43RISK
open
Nucleicritical
CWP (Control Web Panel) < 0.9.8.1205 - Remote Code Execution
CVE-2025-48703CRITICALunder attack
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
100RISK
open
Nucleicritical
vBulletin 5.0.0-6.0.3 - Authentication Bypass
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RISK
open
Nucleicritical
vBulletin replaceAdTemplate - Remote Code Execution
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the t
75RISK
open
Nucleihigh
Discourse OAuth Social Login - Cross-site Scripting
Discourse vulnerable to XSS via user-provided query parameter in oauth failure flow
36RISK
open
Nucleicritical
DataEase < 2.10.10 - JWT Authentication Bypass
Dataease Authentication Bypass Vulnerability
41RISK
open
Nucleihigh
DataEase - Remote Code Execution
Dataease H2 Database Remote Code Execution (RCE) Bypass Vulnerability
48RISK
open
Nucleihigh
WordPress Custom Login And Signup Widget Plugin <= 1.0 - Arbitrary Code Execution
WordPress Custom Login And Signup Widget plugin <= 1.0 - Arbitrary Code Execution vulnerability
63RISK
open
Nucleicritical
Roundcube Webmail - Remote Code Execution
CVE-2025-49113CRITICALunder attack
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
Nucleicritical
Pterodactyl Panel - Remote Code Execution
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open
Nucleicritical
Akamai CloudTest < 60 2025.06.02 - XML External Entity (XXE)
Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.
48RISK
open
Nucleicritical
Adobe Experience Manager Forms - Insecure Deserialization
Adobe Experience Manager (MS) | Deserialization of Untrusted Data (CWE-502)
55RISK
open
Nucleicritical
MCP Inspector < 0.14.0 UnauthenticatedRemote Code Execution
MCP Inspector proxy server lacks authentication between the Inspector client and proxy
75RISK
open
Nucleimedium
Astro SSR - Open Redirect
Astro: Duplicate trailing slash feature can lead to Open Redirects
28RISK
open
Nucleihigh
Stirling-PDF < 1.1.0 - Server-Side Request Forgery
Stirling-PDF SSRF vulnerability on /api/v1/convert/html/pdf
36RISK
open
Nucleihigh
Stirling-PDF SSRF via Markdown
Stirling-PDF SSRF vulnerability on /api/v1/convert/markdown/pdf
36RISK
open
Nucleicritical
WeGIA - Directory Traversal
WeGIA Path Traversal at endpoint 'html/socio/sistema/download_remessa.php' via parameter 'file'
43RISK
open
Nucleicritical
React Server Components - Remote Code Execution
CVE-2025-55182CRITICALunder attackransomware
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
Nucleihigh
React Server Components - Denial of Service
A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 1
68RISK
open
Nucleicritical
ArgoCD Project API Token Repository Credentials Exposure
Argo CD: Project API Token Exposes Repository Credentials
43RISK
open
Nucleimedium
Astro - Unauthorized Third-Party Image Access
Unauthorized third-party images in Astro’s _image endpoint
28RISK
open
Nucleihigh
Agent-Zero 0.8.0 - 0.9.4 - Arbitrary File Download
An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to execute a directory tr
23RISK
open
Nucleicritical
IdeaCMS <= 1.7 - SQL Injection
IdeaCMS getList.html Goods sql injection
28RISK
open
Nucleicritical
Directus - Unauthenticated File Modification
Directus allows unauthenticated file upload and file modification due to lacking input sanitization
43RISK
open
previouspage 137 / 141next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.