Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,852cataloged exploits
32,148CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,978GitHub PoC 13,268VulnCheck XDB 8,156Nuclei 4,202Metasploit 3,462✓ verified onlyrecentpopularrisk
4,202 exploits
Nucleimedium
wpForo Forum <= 2.1.8 - Cross-Site Scripting
wpForo Forum < 2.1.9 - Reflected Cross-Site Scripting
18RISK
open ↗Nucleimedium
Art Gallery Management System Project v1.0 - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to e
38RISK
open ↗Nucleicritical
SolarView Compact 6.00 - OS Command Injection
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RISK
open ↗Nucleicritical
WordPress Paid Memberships Pro <2.9.8 - Blind SQL Injection
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit
85RISK
open ↗Nucleicritical
WordPress Easy Digital Downloads 3.1.0.2/3.1.0.3 - SQL Injection
The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection
48RISK
open ↗Nucleimedium
Quick Event Manager < 9.7.5 - Cross-Site Scripting
The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability
28RISK
open ↗Nucleihigh
Login with Phone Number - Cross-Site Scripting
The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerabili
48RISK
open ↗Nucleimedium
Joomla! Webservice - Password Disclosure
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗Nucleimedium
Ozette Plugins - Cross-Site Request Forgery
WordPress Simple Mobile URL Redirect Plugin <= 1.7.2 is vulnerable to Cross Site Request Forgery (CSRF)
28RISK
open ↗Nucleicritical
WordPress GamiPress <= 2.5.7 - SQL Injection
WordPress GamiPress Plugin <= 2.5.7 is vulnerable to SQL Injection
36RISK
open ↗Nucleihigh
CData RSB Connect v22.0.8336 - Server Side Request Forgery
CData RSB Connect v22.0.8336 was discovered to contain a Server-Side Request Forgery (SSRF).
36RISK
open ↗Nucleimedium
Squidex <7.4.0 - Cross-Site Scripting
Squidex before 7.4.0 was discovered to contain a squid.svg cross-site scripting (XSS) vulnerability.
28RISK
open ↗Nucleimedium
mojoPortal 2.7.0.0 - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability in the FileDialog.aspx component of mojoPortal v2.7.0.0 allows atta
40RISK
open ↗Nucleicritical
UserPro <= 5.1.1 - Authentication Bypass
UserPro <= 5.1.1 - Authentication Bypass to Administrator
63RISK
open ↗Nucleicritical
Citrix ShareFile StorageZones Controller - Unauthenticated Remote Code Execution
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, coul
100RISK
open ↗Nucleimedium
phpIPAM - 1.6 - Cross-Site Scripting
phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter
48RISK
open ↗Nucleimedium
PMB 7.4.6 - Cross-Site Scripting
PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /ad
18RISK
open ↗Nucleimedium
PMB 7.4.6 - Open Redirect
PMB v7.4.6 was discovered to contain an open redirect vulnerability via the component /opac_css/pmb.php. This vulnerabil
18RISK
open ↗Nucleimedium
PMB v7.4.6 - Cross-Site Scripting
PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /ad
18RISK
open ↗Nucleicritical
Appium Desktop Server - Remote Code Execution
OS Command Injection in appium/appium-desktop
48RISK
open ↗Nucleicritical
vBulletin <= 5.6.9 - Pre-authentication Remote Code Execution
vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP reques
68RISK
open ↗Nucleicritical
GeoServer OGC Filter - SQL Injection
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISK
open ↗Nucleimedium
WordPress Easy Forms for Mailchimp Plugin < 6.8.9 - Cross-Site Scripting
Easy Forms for Mailchimp < 6.8.9 - Reflected XSS
28RISK
open ↗Nucleihigh
Apache Druid Kafka Connect - Remote Code Execution
Apache Kafka Connect API: Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration using Kafka Connect
78RISK
open ↗Nucleicritical
D-Link DIR820LA1_FW105B03 'ping_addr' - OS Command Injection
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a cr
95RISK
open ↗Nucleimedium
ChurchCRM 4.5.3 - Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web
28RISK
open ↗Nucleihigh
Metersphere - Arbitrary File Read
Improper access control to download file in metersphere
48RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.