Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
4,217 exploits
Nucleicritical
The School Management < 9.9.7 - Remote Code Execution
The School Management < 9.9.7 - Unauthenticated RCE via REST api
75RISK
open
Nucleicritical
CP Image Store with Slideshow <= 1.0.67 - SQL Injection
CP Image Store with Slideshow < 1.0.68 - Unauthenticated SQLi
23RISK
open
Nucleihigh
draw.io < 18.0.5 - Server Side Request Forgery (SSRF)
Server-Side Request Forgery (SSRF) in jgraph/drawio
36RISK
open
Nucleihigh
Drawio <18.0.4 - Server-Side Request Forgery
SSRF on /proxy in jgraph/drawio
36RISK
open
Nucleimedium
WordPress Simple Membership <4.1.1 - Cross-Site Scripting
Simple Membership < 4.1.1 - Reflected Cross-Site Scripting
18RISK
open
Nucleimedium
Newsletter < 7.4.5 - Cross-Site Scripting
Newsletter < 7.4.5 - Reflected Cross-Site Scripting
18RISK
open
Nucleihigh
WordPress RSVPMaker <=9.3.2 - SQL Injection
RSVPMaker <= 9.3.2 - Unauthenticated SQL Injection
68RISK
open
Nucleihigh
Drawio <18.1.2 - Server-Side Request Forgery
Exposure of Sensitive Information to an Unauthorized Actor in jgraph/drawio
28RISK
open
Nucleihigh
Terraboard <2.2.0 - SQL Injection
SQL Injection in camptocamp/terraboard
43RISK
open
Nucleihigh
ARMember < 3.4.8 - Unauthenticated Admin Account Takeover
ARMember < 3.4.8 - Unauthenticated Admin Account Takeover
18RISK
open
Nucleimedium
WordPress Easy Pricing Tables <3.2.1 - Cross-Site Scripting
Easy Pricing Tables < 3.2.1 - Reflected Cross-Site-Scripting
18RISK
open
Nucleimedium
WordPress Copyright Proof <=4.16 - Cross-Site-Scripting
Copyright Proof <= 4.16 - Reflected Cross-Site-Scripting
18RISK
open
Nucleimedium
WordPress Shortcodes and Extra Features for Phlox <2.9.8 - Cross-Site Scripting
Shortcodes and extra features for Phlox theme < 2.9.8 - Reflected Cross-Site-Scripting
18RISK
open
Nucleimedium
WordPress Active Products Tables for WooCommerce <1.0.5 - Cross-Site Scripting
Active Products Tables for WooCommerce < 1.0.5 - Reflected Cross-Site-Scripting
18RISK
open
Nucleimedium
WordPress CDI <5.1.9 - Cross Site Scripting
CDI < 5.1.9 - Reflected Cross-Site-Scripting
18RISK
open
Nucleimedium
WordPress Awin Data Feed <=1.6 - Cross-Site Scripting
Awin Data Feed < 1.8 - Reflected Cross-Site Scripting
18RISK
open
Nucleimedium
WordPress Gallery <2.0.0 - Cross-Site Scripting
Gallery < 2.0.0 - Reflected Cross-Site Scripting
18RISK
open
Nucleicritical
Youzify < 1.2.0 - Unauthenticated SQLi
Youzify < 1.2.0 - Unauthenticated SQLi
18RISK
open
Nucleicritical
WordPress eaSYNC Booking <1.1.16 - Arbitrary File Upload
eaSYNC < 1.1.16 - Unauthenticated Arbitrary File Upload
23RISK
open
Nucleimedium
WordPress Sensei LMS <4.5.0 - Information Disclosure
Sensei LMS < 4.5.0 - Unauthenticated Private Messages Disclosure via Rest API
18RISK
open
Nucleimedium
Microweber < 1.2.17 - Cross-Site Scripting
Cross-site Scripting (XSS) - Reflected in microweber/microweber
28RISK
open
Nucleihigh
Oracle WebLogic Server Local File Inclusion
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
78RISK
open
Nucleihigh
Oracle E-Business Suite <=12.2 - Authentication Bypass
Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Ea
58RISK
open
Nucleimedium
SearchWP Live Ajax Search < 1.6.2 - Unauthenticated Arbitrary Post Title Disclosure
SearchWP Live Ajax Search < 1.6.2 - Unauthenticated Arbitrary Post Title Disclosure
18RISK
open
Nucleimedium
Alt-n/MDaemon Security Gateway <=8.5.0 - XML Injection
Alt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=login XML Injection.
28RISK
open
Nucleicritical
Dynamicweb 9.5.0 - 9.12.7 Unauthenticated Admin User Creation
An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication
55RISK
open
Nucleihigh
WordPress Ninja Job Board < 1.3.3 - Direct Request
Ninja Job Board < 1.3.3 - Resume Disclosure via Directory Listing
18RISK
open
Nucleimedium
WordPress All-in-One WP Migration <=7.62 - Cross-Site Scripting
All-in-One WP Migration < 7.63 - Unauthenticated Reflected XSS
28RISK
open
Nucleihigh
ThinkPHP 5.0.24 - Information Disclosure
ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to acce
28RISK
open
Nucleihigh
Cuppa CMS v1.0 - Local File Inclusion
CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php.
18RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.