Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
4,202 exploits
Nucleicritical
Limit Login Attempts (Spam Protection) < 5.1 - SQL Injection
Limit Login Attempts (Spam Protection) < 5.1 - Unauthenticated SQLi
18RISK
open
Nucleicritical
WordPress WP Fundraising Donation and Crowdfunding Platform <1.5.0 - SQL Injection
WP Fundraising Donation and Crowdfunding Platform < 1.5.0 - Unauthenticated SQLi
18RISK
open
Nucleicritical
Ubigeo de Peru < 3.6.4 - SQL Injection
Ubigeo de Peru < 3.6.4 - Unauthenticated SQLi
18RISK
open
Nucleicritical
WordPress BadgeOS <=3.7.0 - SQL Injection
BadgeOS <= 3.7.0 - Unauthenticated SQLi
23RISK
open
Nucleihigh
Webmin <1.990 - Improper Access Control
Improper Access Control to Remote Code Execution in webmin/webmin
78RISK
open
Nucleicritical
WordPress WP Video Gallery <=1.7.1 - SQL Injection
WP Video Gallery <= 1.7.1 - Unauthenticated SQLi
18RISK
open
Nucleicritical
WordPress Best Books <=2.6.3 - SQL Injection
Bestbooks <= 2.6.3 - Unauthenticated SQLi
18RISK
open
Nucleicritical
SpeakOut Email Petitions < 2.14.15.1 - SQL Injection
SpeakOut! Email Petitions < 2.14.15.1 - Unauthenticated SQLi
18RISK
open
Nucleimedium
UpdraftPlus < 1.22.9 - Cross-Site Scripting
UpdraftPlus < 1.22.9 - Reflected Cross-Site Scripting
18RISK
open
Nucleicritical
WordPress ARPrice <3.6.1 - SQL Injection
ARPrice Lite < 3.6.1 - Unauthenticated SQLi
23RISK
open
Nucleimedium
nitely/spirit 0.12.3 - Open Redirect
Multiple Open Redirect in nitely/spirit
28RISK
open
Nucleimedium
Gogs <0.12.5 - Server-Side Request Forgery
Server-Side Request Forgery (SSRF) in gogs/gogs
28RISK
open
Nucleimedium
WordPress Gmedia Photo Gallery Plugin < 1.20.0 - Cross-Site Scripting
Gmedia Photo Gallery < 1.20.0 - Admin+ Stored Cross-Site Scripting
18RISK
open
Nucleimedium
Caldera Forms < 1.9.7 - Reflected Cross-Site Scripting
Caldera Forms < 1.9.7 - Reflected Cross-Site Scripting
18RISK
open
Nucleicritical
Member Hero <=1.0.9 - Remote Code Execution
Member Hero <= 1.0.9 - Unauthenticated RCE
18RISK
open
Nucleimedium
Header Footer Code Manager < 1.1.24 - Cross-Site Scripting
Header Footer Code Manager < 1.1.24 - Reflected Cross-Site Scripting
18RISK
open
Nucleimedium
Microweber < 1.2.12 - Stored Cross-Site Scripting
Cross-site Scripting (XSS) - Stored in microweber/microweber
28RISK
open
Nucleicritical
WordPress Order Listener for WooCommerce <3.2.2 - SQL Injection
Order Listener for WooCommerce < 3.2.2 - Unauthenticated SQLi
18RISK
open
Nucleicritical
WordPress Stop Bad Bots <6.930 - SQL Injection
WP Block and Stop Bad Bots < 6.930 - Unauthenticated SQLi
18RISK
open
Nucleihigh
WordPress Sitemap by click5 <1.0.36 - Missing Authorization
Sitemap by click5 < 1.0.36 - Unauthenticated Arbitrary Options Update
43RISK
open
Nucleimedium
Microweber <1.2.11 - Stored Cross-Site Scripting
Multiple Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Other Settings, Shop's Autorespond E-mail Settings and Shops' Payments Methods in microweber/microweber
28RISK
open
Nucleimedium
Microweber <1.2.12 - Stored Cross-Site Scripting
Unrestricted XML Files Leads to Stored XSS in microweber/microweber
28RISK
open
Nucleimedium
Microweber <1.2.12 - Integer Overflow
The microweber application allows large characters to insert in the input field "fist & last name" which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request. in microweber/microweber in microweber/microweber
36RISK
open
Nucleimedium
WordPress Advanced Booking Calendar <1.7.1 - Cross-Site Scripting
Advanced Booking Calendar < 1.7.1 - Reflected Cross-Site Scripting
18RISK
open
Nucleicritical
WordPress Personal Dictionary <1.3.4 - Blind SQL Injection
Personal Dictionary < 1.3.4 - Unauthenticated SQLi
18RISK
open
Nucleicritical
WordPress WooCommerce <3.1.2 - Arbitrary Function Call
Woo Product Table < 3.1.2 - Unauthenticated Arbitrary Function Call
23RISK
open
Nucleihigh
Kyocera Net View Address Book Exposure
Kyocera Net View Address Book Exposure
61RISK
open
Nucleimedium
Limit Login Attempts - Stored Cross-Site Scripting
Limit Login Attempts < 4.0.72 - Admin+ Stored Cross-Site Scripting
18RISK
open
Nucleicritical
Sophos Firewall <=18.5 MR3 - Remote Code Execution
CVE-2022-1040CRITICALunder attack
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISK
open
Nucleimedium
WordPress RSVP and Event Management <2.7.8 - Missing Authorization
RSVP and Event Management < 2.7.8 - Unauthenticated Entries Export
18RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.