Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,978GitHub PoC 13,282VulnCheck XDB 8,176Nuclei 4,202Metasploit 3,462✓ verified onlyrecentpopularrisk
4,202 exploits
Nucleicritical
Better Search Replace < 1.4.5 - PHP Object Injection
Better Search Replace <= 1.4.4 - Unauthenticated PHP Object Injection
68RISK
open ↗Nucleimedium
WP Recipe Maker <= 9.1.0 - Reflected XSS via Referer Header
WP Recipe Maker <= 9.1.0 - Reflected Cross-Site Scripting via Referer
28RISK
open ↗Nucleicritical
Shield Security WP Plugin <= 18.5.9 - Local File Inclusion
Shield Security – Smart Bot Blocking & Intrusion Prevention Security <= 18.5.9 - Unauthenticated Local File Inclusion
55RISK
open ↗Nucleihigh
GitLab - Account Takeover via Password Reset
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open ↗Nucleimedium
WeiYe-Jing datax-web <= 2.1.2 - OS Command Injection
WeiYe-Jing datax-web HTTP POST Request killJob os command injection
28RISK
open ↗Nucleihigh
WordPress BackWPup < 4.0.4 - Backup File Disclosure
BackWPup < 4.0.4 - Unauthenticated Backup Download
36RISK
open ↗Nucleihigh
JetBackup <= 2.0.9.7 - Sensitive Information Exposure via Directory Listing
JetBackup < 2.0.9.9 - Directory Listing Exposing Backups
36RISK
open ↗Nucleimedium
System Dashboard < 2.8.10 - Cross-Site Scripting
System Dashboard < 2.8.10 - XSS via Header Injection
28RISK
open ↗Nucleihigh
Ozeki 10 SMS Gateway 10.3.208 - Arbitrary File Read
Ozeki SMS Gateway <= 10.3.208 Unauthenticated Arbitrary File Read
36RISK
open ↗Nucleicritical
JS Help Desk <= 2.8.2 - SQL Injection
JS Help Desk – AI-Powered Support & Ticketing System 2.8.2 - Unauthenticated SQL Injection via 'js-support-ticket-token-tkstatus' Cookie
36RISK
open ↗Nucleicritical
PAN-OS Management Web Interface - Authentication Bypass
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open ↗Nucleicritical
SpiderFlow Crawler Platform - Remote Code Execution
spider-flow FunctionController.java FunctionService.saveFunction code injection
33RISK
open ↗Nucleicritical
Github Enterprise Authenticated Remote Code Execution
Unsafe Reflection in Github Enterprise Server leading to Command Injection
58RISK
open ↗Nucleicritical
Fortra GoAnywhere MFT - Authentication Bypass
Authentication Bypass in GoAnywhere MFT
85RISK
open ↗Nucleimedium
EventON (Free < 2.2.8, Premium < 4.5.5) - Information Disclosure
EventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Email Address Disclosure
60RISK
open ↗Nucleimedium
Analytics Insights for Google Analytics 4 < 6.3 - Open Redirect
Analytics Insights for Google Analytics 4 < 6.3 - Open Redirect
28RISK
open ↗Nucleihigh
Ncast busiFacade - Remote Command Execution
Guangzhou Yingke Electronic Technology Ncast Guest Login IPSetup.php information disclosure
60RISK
open ↗Nucleimedium
Travelpayouts <= 1.1.16 - Open Redirect
Travelpayouts <= 1.1.15 - Open Redirect
28RISK
open ↗Nucleicritical
Likeshop < 2.5.7.20210311 - Arbitrary File Upload
Likeshop HTTP POST Request File.php userFormImage unrestricted upload
78RISK
open ↗Nucleimedium
WordPress Simple Job Board - Unauthorized Data Access
Simple Job Board <= 2.10.8 - Missing Authorization to Unauthenticated Information Disclosure
28RISK
open ↗Nucleicritical
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RISK
open ↗Nucleimedium
W3 Total Cache < 2.8.2 - Log File Exposure
W3 Total Cache <= 2.8.1 Information Exposure via Log Files
28RISK
open ↗Nucleihigh
WordPress Collapsing Categories <= 3.0.8 - SQL Injection
Collapsing Categories <= 3.0.8 - Unauthenticated SQL Injection
56RISK
open ↗Nucleimedium
LearnDash LMS < 4.10.3 - Sensitive Information Exposure
LearnDash LMS <= 4.10.2 - Sensitive Information Exposure via API
28RISK
open ↗Nucleimedium
LearnDash LMS < 4.10.2 - Sensitive Information Exposure via assignments
LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via assignments
28RISK
open ↗Nucleimedium
LearnDash LMS < 4.10.2 - Sensitive Information Exposure
LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via API
28RISK
open ↗Nucleicritical
Progress Kemp LoadMaster - Command Injection
LoadMaster Pre-Authenticated OS Command Injection
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.