Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
4,202 exploits
Nucleicritical
Likeshop < 2.5.7.20210311 - Arbitrary File Upload
Likeshop HTTP POST Request File.php userFormImage unrestricted upload
78RISK
open
Nucleimedium
WordPress Simple Job Board - Unauthorized Data Access
Simple Job Board <= 2.10.8 - Missing Authorization to Unauthenticated Information Disclosure
28RISK
open
Nucleihigh
Give WP Plugin < 3.19.0 - Cross-Site Scripting
Give < 3.19.0 - Reflected XSS
28RISK
open
Nucleicritical
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RISK
open
Nucleimedium
W3 Total Cache < 2.8.2 - Log File Exposure
W3 Total Cache <= 2.8.1 Information Exposure via Log Files
28RISK
open
Nucleihigh
WordPress Collapsing Categories <= 3.0.8 - SQL Injection
Collapsing Categories <= 3.0.8 - Unauthenticated SQL Injection
56RISK
open
Nucleimedium
LearnDash LMS < 4.10.3 - Sensitive Information Exposure
LearnDash LMS <= 4.10.2 - Sensitive Information Exposure via API
28RISK
open
Nucleimedium
LearnDash LMS < 4.10.2 - Sensitive Information Exposure via assignments
LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via assignments
28RISK
open
Nucleimedium
LearnDash LMS < 4.10.2 - Sensitive Information Exposure
LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via API
28RISK
open
Nucleicritical
Progress Kemp LoadMaster - Command Injection
CVE-2024-1212CRITICALunder attack
LoadMaster Pre-Authenticated OS Command Injection
100RISK
open
Nucleicritical
WP Umbrella Update Backup Restore & Monitoring <= 2.17.0 - Local File Inclusion
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion
68RISK
open
Nucleimedium
PropertyHive < 2.1.1 - Cross-Site Scripting
PropertyHive < 2.1.1 - Reflected XSS
28RISK
open
Nucleihigh
Bulk Me Now! Plugin <= 2.0 - Cross-Site Scripting
Bulk Me Now <= 2.0 - Reflected XSS
36RISK
open
Nucleimedium
WP DeskLite - Reflected XSS
WP DeskLite <= 1.0.0 - Reflected XSS
28RISK
open
Nucleimedium
AffiliateImporterEb <= 1.0.6 - Reflected XSS
AffiliateImporterEb <= 1.0.6 - Reflected XSS
28RISK
open
Nucleimedium
Advance Post Prefix WordPress plugin - Reflected XSS
Advance Post Prefix <= 1.1.1 - Reflected XSS
28RISK
open
Nucleimedium
WP BASE Booking - Reflected XSS
WP BASE Booking of Appointments, Services and Events < 5.0.0 - Reflected XSS
28RISK
open
Nucleihigh
WordPress Competition Form Plugin <= 2.0 - Cross-Site Scripting
Competition Form <= 2.0 - Reflected XSS
36RISK
open
Nucleimedium
BentoML v1.3.9 - Open Redirect
15RISK
open
Nucleicritical
Nokri – Job Board WordPress Theme <= 1.6.2 - Unauthenticated Arbitrary Password Change
Nokri – Job Board WordPress Theme <= 1.6.2 - Unauthenticated Arbitrary Password Change
43RISK
open
Nucleihigh
Error Log Viewer By WP Guru <= 1.0.1.3 - Missing Authorization to Arbitrary File Read
Error Log Viewer By WP Guru <= 1.0.1.3 - Missing Authorization to Unauthenticated Arbitrary File Read
48RISK
open
Nucleimedium
Custom Field Manager WordPress - Cross-Site Scripting
Custom Field Manager <= 1.0 - Reflected XSS Vulnerability
28RISK
open
Nucleimedium
Lazy Blocks <= 3.8.2 - Cross-Site Scripting
Custom Block Builder – Lazy Blocks < 3.8.3 - Reflected XSS
36RISK
open
Nucleicritical
DrayTek Vigor - Command Injection
CVE-2024-12987MEDIUMunder attack
DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection
100RISK
open
Nucleihigh
Dyn Business Panel Plugin <= 1.0.0 - Cross-Site Scripting
Dyn Business Panel <= 1.0.0 - Reflected XSS
36RISK
open
Nucleihigh
WP Triggers Lite - Cross-Site Scripting
WP Triggers Lite <= 2.5.3 - Reflected XSS
36RISK
open
Nucleimedium
WP Finance Plugin <= 1.3.6 - Cross-Site Scripting
WP Finance <= 1.3.6 - Reflected XSS
28RISK
open
Nucleimedium
WordPress Email Newsletter - Reflected XSS
WP Email Newsletter <= 1.1 - Reflected XSS
28RISK
open
Nucleimedium
Widget4Call WordPress - Cross-Site Scripting
Widget4call <= 1.0.7 - Reflected XSS
28RISK
open
Nucleimedium
WP MediaTagger <= 4.1.1 - Cross-Site Scripting
WP MediaTagger <= 4.1.1 - Reflected XSS
28RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.