Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
4,217 exploits
Nucleicritical
Adobe ColdFusion - RDS Arbitrary File Write
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
85RISK
open
Nucleihigh
ColdFusion - Path Traversal
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
43RISK
open
Nucleicritical
phpBB < 3.3.17 - Authentication Bypass
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or
63RISK
open
Nucleicritical
Starlette - Improper Validation of Unsafe Equivalence in Input
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
48RISK
open
Nucleicritical
Joomla! JCE extension < 2.9.99.5 unauthenticated RCE
CVE-2026-48907CRITICALunder attack
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open
Nucleicritical
WordPress Product Slider Pro for WooCommerce < 3.5.4 - Supply Chain Backdoor RCE
WordPress Product Slider Pro for WooCommerce plugin < 3.5.4 - Backdoor vulnerability
63RISK
open
Nucleimedium
Apache Tomcat - Cross-Site Scripting
Apache Tomcat: XSS in number guess example
48RISK
open
Nucleimedium
Lyrion Music Server <= 9.2.0 - Cross-Site Scripting
Lyrion Music Server 9.2.0 Reflected XSS via server.log
28RISK
open
Nucleihigh
Langflow <= 1.8.4 - Path Traversal to RCE via File Upload
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RISK
open
Nucleicritical
WordPress ARMember Premium <= 7.3.1 - Unauthenticated SQL Injection
ARMember Premium <= 7.3.1 - Unauthenticated SQL Injection via 'order' Parameter
36RISK
open
Nucleicritical
Check Point IKEv1 Remote-Access VPN - Certificate Authentication Bypass
CVE-2026-50751CRITICALunder attackransomware
User Authentication Bypass in VPN Remote Access and Mobile Access
100RISK
open
Nucleilow
Gogs < 0.14.3 - Unauthenticated Organization Teams Disclosure
Gogs: Unauthenticated Organization Teams Information Disclosure via API
28RISK
open
Nucleicritical
Magento 2 Amasty Order Attributes < 4.0.0 - Unauthenticated Arbitrary File Upload
Amasty Order Attributes for Magento 2 < 4.0.0 Unauthenticated Arbitrary File Upload
63RISK
open
Nucleihigh
SiYuan <= 3.6.5 - Unauthenticated Path Traversal
SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read)
36RISK
open
Nucleihigh
SiYuan Note <= 3.6.5 - Authentication Bypass
SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
43RISK
open
Nucleimedium
LobeHub LobeChat <= 2.1.56 - Server-Side Request Forgery
LobeHub: Unauthenticated SSRF in `/webapi/proxy`
43RISK
open
Nucleimedium
vLLM <= 0.23.0 - Anthropic Router Heap Address Information Leak
vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router
28RISK
open
Nucleicritical
YMC Filter - SQL Injection
WordPress Filter & Grids plugin <= 3.11.5 - SQL Injection vulnerability
43RISK
open
Nucleimedium
Dashy <= 4.3.6 - Reflected XSS via Workspace
Dashy: XSS in workspace url parameter
23RISK
open
Nucleimedium
VvvebJs <= 2.0.5 - Cross-Site Scripting
givanz Vvvebjs File Upload Endpoint upload.php cross site scripting
48RISK
open
Nucleicritical
Page Builder CK <= 3.5.10 - Unauthenticated Arbitrary File Upload
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
85RISK
open
Nucleicritical
Balbooa Forms < 2.4.1 - Unauthenticated Arbitrary File Upload
CVE-2026-56291CRITICALunder attack
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
100RISK
open
Nucleicritical
Gorse < 0.5.10 - Unauthenticated Database Dump
Gorse - Unauthenticated Database Dump and Restore via /api/dump and /api/restore Endpoints
63RISK
open
Nucleicritical
Drag and Drop Multiple File Upload - CF7 <= 1.3.9.6 - Remote Code Execution
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass
56RISK
open
Nucleicritical
Dockwatch <= 0.6.567 - OS Command Injection
Dockwatch 0.6.567 Unauthenticated OS Command Injection via ajax/compose.php
43RISK
open
Nucleicritical
9Router - Unauthenticated LLM Provider API Exposure
9Router 0.4.41 - Unauthenticated API Exposure via /api/providers
43RISK
open
Nucleihigh
AstrBot <= 4.22.1 - Command Injection
AstrBotDevs AstrBot MCP Endpoint tools.py add_mcp_server command injection
48RISK
open
Nucleimedium
User Registration & Membership WordPress plugin - Open Redirect
User Registration & Membership <= 5.1.4 - Unauthenticated Open Redirect via 'redirect_to_on_logout' Parameter
28RISK
open
Nucleicritical
WordPress Core 6.9-7.0.1 - Pre-Auth Batch-Route Confusion
CVE-2026-63030CRITICALunder attack
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
Nucleicritical
FlipperCode Custom CSS, JS & PHP <= 2.0.7 - Remote Code Execution
Custom CSS JS PHP <= 2.0.7 - Unauthenticated SQL Injection to RCE
56RISK
open
previouspage 139 / 141next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.