Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
4,202 exploits
Nucleihigh
reNgine 2.2.0 - Command Injection
reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacha
41RISK
open
Nucleimedium
Apache Solr - Host Environment Variables Leak via Metrics API
Apache Solr: Host environment variables are published via the Metrics API
40RISK
open
Nucleicritical
Mingsoft MCMS 5.2.9 - SQL Injection
Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/
43RISK
open
Nucleihigh
XWiki < 4.10.15 - Sensitive Information Disclosure
XWiki Platform Solr search discloses password hashes of all users
58RISK
open
Nucleimedium
XWiki < 4.10.15 - Email Disclosure
XWiki Platform Solr search discloses email addresses of users
40RISK
open
Nucleicritical
D-Link D-View 8 v2.0.1.28 - Authentication Bypass
Authentication Bypass in D-Link D-View 8
55RISK
open
Nucleicritical
JS Help Desk <= 2.8.1 - SQL Injection
WordPress JS Help Desk – Best Help Desk & Support Plugin <= 2.8.1 is vulnerable to SQL Injection
63RISK
open
Nucleimedium
Defender Security < 4.1.0 - Protection Bypass (Hidden Login Page)
Defender Security < 4.1.0 - Protection Bypass (Hidden Login Page)
28RISK
open
Nucleicritical
MajorDoMo thumb.php - OS Command Injection
MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE:
50RISK
open
Nucleihigh
Apache OFBiz < 18.12.11 - Server Side Request Forgery
Apache OFBiz: Arbitrary file properties reading and SSRF attack
30RISK
open
Nucleicritical
Jordy Meow AI Engine - Unrestricted File Upload
WordPress AI Engine plugin <= 1.9.98 - Unauthenticated Arbitrary File Upload vulnerability
75RISK
open
Nucleihigh
Gradio Hugging Face - Local File Inclusion
Make the `/file` secure against file traversal attacks
28RISK
open
Nucleicritical
Apache OFBiz < 18.12.11 - Remote Code Execution
Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability
60RISK
open
Nucleicritical
WP Sessions Time Monitoring Full Automatic <= 1.0.8 - SQL Injection
WP Sessions Time Monitoring Full Automatic < 1.0.9 - Unauthenticated SQL injection
36RISK
open
Nucleicritical
WordPress AI ChatBot (WPBot) <= 4.8.9 - SQL Injection
AI ChatBot <= 4.8.9 - Unauthenticated SQL Injection via qc_wpbo_search_response
63RISK
open
Nucleimedium
Winter CMS Local File Inclusion - (LFI)
Winter CMS Local File Inclusion through Server Side Template Injection
35RISK
open
Nucleihigh
Digiever DS-2105 Pro - Command Injection
CVE-2023-52163HIGHunder attack
Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects
88RISK
open
Nucleicritical
Viessmann Vitogate 300 - Hardcoded Password
Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded password
70RISK
open
Nucleihigh
Kafka UI 0.7.1 Command Injection
An issue discovered in provectus kafka-ui 0.4.0 through 0.7.1 allows remote attackers to execute arbitrary code via the
78RISK
open
Nucleimedium
Microweber < V.2.0 - Cross-Site Scripting
Cross-site Scripting (XSS) - Reflected in microweber/microweber
28RISK
open
Nucleicritical
WordPress Royal Elementor Addons Plugin <= 1.3.78 - Arbitrary File Upload
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISK
open
Nucleimedium
Mosparo < 1.0.2 - Open Redirect
Open Redirect in mosparo/mosparo
40RISK
open
Nucleimedium
Structurizr on-premises - Cross Site Scripting
Cross-site Scripting (XSS) - Reflected in structurizr/onpremises
28RISK
open
Nucleimedium
LearnPress < 4.2.5.5 - Cross-Site Scripting
LearnPress < 4.2.5.5 - Reflected Cross-Site Scripting
28RISK
open
Nucleicritical
10Web Booster < 2.24.18 - Unauthenticated Arbitrary Option Deletion
10Web Booster < 2.24.18 - Unauthenticated Arbitrary Option Deletion
18RISK
open
Nucleimedium
WordPress Core - Post Author Email Disclosure
WordPress < 6.3.2 - Unauthenticated Post Author Email Disclosure
28RISK
open
Nucleicritical
WP Hotel Booking <= 2.0.7 - SQL Injection
WP Hotel Booking < 2.0.8 - Unauthenticated SQLi
30RISK
open
Nucleihigh
News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Local File Inclusion
News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Remote Code Execution via Local File Inclusion
36RISK
open
Nucleicritical
ColumbiaSoft DocumentLocator - Improper Authentication
ColumbiaSoft Document Locator WebTools login improper authentication
48RISK
open
Nucleimedium
phpMyFAQ < 3.2.0 - Cross-site Scripting
Cross-site Scripting (XSS) - Reflected in thorsten/phpmyfaq
36RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.