Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
4,202 exploits
Nucleimedium
WSO2 - Server Side Request Forgery
SSRF and Reflected XSS Vulnerability in Deprecated Try-It Feature of Multiple WSO2 Products
28RISK
open
Nucleimedium
Pi-hole Reflected XSS in 404-Error Page
Pi-hole Admin Interface vulnerable to cross-site scripting via malformed URL path on 404 error page
28RISK
open
Nucleihigh
ZTE ZXHN-F660T/F660A - Default Credentials
ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge o
56RISK
open
Nucleihigh
Docusaurus Gists Plugin < 4.0.0 - GitHub Personal Access Token Exposure
docusaurus-plugin-content-gists Exposes GitHub Personal Access Token
43RISK
open
Nucleicritical
Microsoft SharePoint Server - Remote Code Execution (ToolShell)
CVE-2025-53770CRITICALunder attackransomware
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
Nucleimedium
Microsoft SharePoint Server - Authentication Bypass (ToolShell)
Microsoft SharePoint Server Spoofing Vulnerability
50RISK
open
Nucleicritical
LaRecipe < 2.8.1 Remote Code Execution via SSTI
LaRecipe is vulnerable to Server-Side Template Injection attacks
63RISK
open
Nucleicritical
Unauthenticated Arbitrary Plugin Upload in Alone Theme
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
75RISK
open
Nucleicritical
Laravel Livewire v3 - Remote Command Execution
CVE-2025-54068CRITICALunder attack
Livewire vulnerable to remote command execution during property update hydration
100RISK
open
Nucleicritical
Hoverfly <= 1.11.3 - Remote Code Execution
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RISK
open
Nucleihigh
XWiki XML View - Sensitive Information Exposure
XWiki Platform: Password and email exposure in xml.vm fields
36RISK
open
Nucleicritical
Adobe Commerce - Authentication Bypass
CVE-2025-54236CRITICALunder attack
Adobe Commerce | Improper Input Validation (CWE-20)
100RISK
open
Nucleimedium
Adobe Experience Manager ≤ 6.5.23.0 – SSRF
Adobe Experience Manager | Server-Side Request Forgery (SSRF) (CWE-918)
28RISK
open
Nucleimedium
Adobe Experience Manager ≤ 6.5.23.0 - XML Injection
Adobe Experience Manager | XML Injection (aka Blind XPath Injection) (CWE-91)
28RISK
open
Nucleimedium
Copyparty <=1.18.6 - Cross-Site Scripting
copyparty Reflected XSS via Filter Parameter
48RISK
open
Nucleimedium
Heimdall Application Dashboard < 2.7.3 - Reflected XSS
LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter.
36RISK
open
Nucleihigh
WordPress JS Archive List <= 6.1.5 - SQL Injection
WordPress JS Archive List Plugin < 6.1.6 - SQL Injection Vulnerability
63RISK
open
Nucleicritical
NestJS DevTools Integration - Remote Code Execution
@nestjs/devtools-integration's CSRF to Sandbox Escape Allows for RCE against JS Developers
75RISK
open
Nucleimedium
Astro SSR - Open Redirect
Astro: Duplicate trailing slash feature can lead to Open Redirects
28RISK
open
Nucleihigh
Stirling-PDF < 1.1.0 - Server-Side Request Forgery
Stirling-PDF SSRF vulnerability on /api/v1/convert/html/pdf
36RISK
open
Nucleihigh
Stirling-PDF SSRF via Markdown
Stirling-PDF SSRF vulnerability on /api/v1/convert/markdown/pdf
36RISK
open
Nucleicritical
WeGIA - Directory Traversal
WeGIA Path Traversal at endpoint 'html/socio/sistema/download_remessa.php' via parameter 'file'
43RISK
open
Nucleicritical
React Server Components - Remote Code Execution
CVE-2025-55182CRITICALunder attackransomware
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
Nucleicritical
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
63RISK
open
Nucleimedium
DokuWiki <= 2025-05-14a Librarian - Reflected Cross-Site Scripting
Cross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[56.1] allows a remote attacker to execute arbitra
28RISK
open
Nucleihigh
Traccar(Windows) 6.1- 6.8.1 - Local File Inclusion
Traccar Unauthenticated Local File Inclusion on Windows - Leakage of Traccar Config File
36RISK
open
Nucleimedium
WordPress Qwizcards < 3.95 - Cross-Site Scripting (Reflected)
WordPress Qwizcards <= 3.9.4 - Reflected XSS
28RISK
open
Nucleicritical
Oracle Identity Manager REST WebServices - Authentication Bypass
CVE-2025-61757CRITICALunder attack
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers
100RISK
open
Nucleicritical
Oracle E-Business Suite 12.2.3–12.2.14 – Remote Code Execution
CVE-2025-61882CRITICALunder attackransomware
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RISK
open
Nucleihigh
Oracle E-Business Suite - Server-Side Request Forgery
CVE-2025-61884HIGHunder attackransomware
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.