Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,497GitHub PoC 13,627VulnCheck XDB 8,198Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
4,217 exploits
Nucleimedium
Sunshine Photo Cart <= 3.1.1 - Reflected Cross-Site Scripting
WordPress Sunshine Photo Cart plugin <= 3.1.1 - Reflected Cross Site Scripting (XSS) vulnerability
36RISK
open ↗Nucleimedium
DataEase <= 2.4.1 - Sensitive Information Exposure
DataEase has database configuration information exposure vulnerability
53RISK
open ↗Nucleimedium
WordPress Themify Builder < 7.5.8 - Open Redirect
Themify Builder < 7.5.8 - Open Redirect
28RISK
open ↗Nucleimedium
WPZOOM Social Icons Widget <= 4.2.15 - Missing Authorization
WordPress Social Icons Widget & Block by WPZOOM plugin <= 4.2.15 - Broken Access Control vulnerability
28RISK
open ↗Nucleicritical
ProfileGrid <= 5.7.8 - SQL Injection
WordPress ProfileGrid plugin <= 5.7.8 - SQL Injection vulnerability
43RISK
open ↗Nucleicritical
CRM Perks Forms <= 1.1.4 - SQL Injection
WordPress CRM Perks Forms plugin <= 1.1.4 - Unauthenticated SQL Injection vulnerability
43RISK
open ↗Nucleicritical
WP Travel Engine <= 5.7.9 - SQL Injection
WordPress WP Travel Engine plugin <= 5.7.9 - Unauth. Blind SQL Injection vulnerability
43RISK
open ↗Nucleicritical
Netgear R6850 V1.1.0.88 - Command Injection
Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter.
55RISK
open ↗Nucleihigh
Netgear R6850 - Information Disclosure
An information leak in currentsetting.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information wi
36RISK
open ↗Nucleimedium
Netgear R6850 - Information Disclosure
An information leak in debuginfo.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without
28RISK
open ↗Nucleicritical
ASUS DSL-AC88U - Authentication Bypass
ASUS Router - Improper Authentication
55RISK
open ↗Nucleimedium
NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosure
WordPress Gallery Plugin – NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosure
40RISK
open ↗Nucleimedium
Fides Privacy Center ≤ 2.39.1 - Server-Side URL Disclosure
Fides Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL
28RISK
open ↗Nucleicritical
MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template
MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template
43RISK
open ↗Nucleihigh
Flowise 1.6.5 - Authentication Bypass
An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted sc
68RISK
open ↗Nucleihigh
F-logic DataCube3 - SQL Injection
SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the
48RISK
open ↗Nucleimedium
CHAOS 5.0.1 'sendCommandHandler' - Cross-Site Scripting
Cross Site Scripting vulnerability in tiagorlampert CHAOS v.5.0.1 allows a remote attacker to escalate privileges via th
28RISK
open ↗← previouspage 141 / 141
We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.