Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,978GitHub PoC 13,282VulnCheck XDB 8,176Nuclei 4,202Metasploit 3,462✓ verified onlyrecentpopularrisk
4,202 exploits
Nucleihigh
reNgine 2.2.0 - Command Injection
reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacha
41RISK
open ↗Nucleimedium
Apache Solr - Host Environment Variables Leak via Metrics API
Apache Solr: Host environment variables are published via the Metrics API
40RISK
open ↗Nucleicritical
Mingsoft MCMS 5.2.9 - SQL Injection
Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/
43RISK
open ↗Nucleihigh
XWiki < 4.10.15 - Sensitive Information Disclosure
XWiki Platform Solr search discloses password hashes of all users
58RISK
open ↗Nucleimedium
XWiki < 4.10.15 - Email Disclosure
XWiki Platform Solr search discloses email addresses of users
40RISK
open ↗Nucleicritical
D-Link D-View 8 v2.0.1.28 - Authentication Bypass
Authentication Bypass in D-Link D-View 8
55RISK
open ↗Nucleicritical
JS Help Desk <= 2.8.1 - SQL Injection
WordPress JS Help Desk – Best Help Desk & Support Plugin <= 2.8.1 is vulnerable to SQL Injection
63RISK
open ↗Nucleimedium
Defender Security < 4.1.0 - Protection Bypass (Hidden Login Page)
Defender Security < 4.1.0 - Protection Bypass (Hidden Login Page)
28RISK
open ↗Nucleicritical
MajorDoMo thumb.php - OS Command Injection
MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE:
50RISK
open ↗Nucleihigh
Apache OFBiz < 18.12.11 - Server Side Request Forgery
Apache OFBiz: Arbitrary file properties reading and SSRF attack
30RISK
open ↗Nucleicritical
Jordy Meow AI Engine - Unrestricted File Upload
WordPress AI Engine plugin <= 1.9.98 - Unauthenticated Arbitrary File Upload vulnerability
75RISK
open ↗Nucleihigh
Gradio Hugging Face - Local File Inclusion
Make the `/file` secure against file traversal attacks
28RISK
open ↗Nucleicritical
Apache OFBiz < 18.12.11 - Remote Code Execution
Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability
60RISK
open ↗Nucleicritical
WP Sessions Time Monitoring Full Automatic <= 1.0.8 - SQL Injection
WP Sessions Time Monitoring Full Automatic < 1.0.9 - Unauthenticated SQL injection
36RISK
open ↗Nucleicritical
WordPress AI ChatBot (WPBot) <= 4.8.9 - SQL Injection
AI ChatBot <= 4.8.9 - Unauthenticated SQL Injection via qc_wpbo_search_response
63RISK
open ↗Nucleimedium
Winter CMS Local File Inclusion - (LFI)
Winter CMS Local File Inclusion through Server Side Template Injection
35RISK
open ↗Nucleihigh
Digiever DS-2105 Pro - Command Injection
Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects
88RISK
open ↗Nucleicritical
Viessmann Vitogate 300 - Hardcoded Password
Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded password
70RISK
open ↗Nucleihigh
Kafka UI 0.7.1 Command Injection
An issue discovered in provectus kafka-ui 0.4.0 through 0.7.1 allows remote attackers to execute arbitrary code via the
78RISK
open ↗Nucleimedium
Microweber < V.2.0 - Cross-Site Scripting
Cross-site Scripting (XSS) - Reflected in microweber/microweber
28RISK
open ↗Nucleicritical
WordPress Royal Elementor Addons Plugin <= 1.3.78 - Arbitrary File Upload
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISK
open ↗Nucleimedium
Structurizr on-premises - Cross Site Scripting
Cross-site Scripting (XSS) - Reflected in structurizr/onpremises
28RISK
open ↗Nucleimedium
LearnPress < 4.2.5.5 - Cross-Site Scripting
LearnPress < 4.2.5.5 - Reflected Cross-Site Scripting
28RISK
open ↗Nucleicritical
10Web Booster < 2.24.18 - Unauthenticated Arbitrary Option Deletion
10Web Booster < 2.24.18 - Unauthenticated Arbitrary Option Deletion
18RISK
open ↗Nucleimedium
WordPress Core - Post Author Email Disclosure
WordPress < 6.3.2 - Unauthenticated Post Author Email Disclosure
28RISK
open ↗Nucleicritical
WP Hotel Booking <= 2.0.7 - SQL Injection
WP Hotel Booking < 2.0.8 - Unauthenticated SQLi
30RISK
open ↗Nucleihigh
News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Local File Inclusion
News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Remote Code Execution via Local File Inclusion
36RISK
open ↗Nucleicritical
ColumbiaSoft DocumentLocator - Improper Authentication
ColumbiaSoft Document Locator WebTools login improper authentication
48RISK
open ↗Nucleimedium
phpMyFAQ < 3.2.0 - Cross-site Scripting
Cross-site Scripting (XSS) - Reflected in thorsten/phpmyfaq
36RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.