Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
22,786 exploits
Exploit-DB
AsusWRT LAN - Remote Code Execution (Metasploit)
CVE-2018-600026 Feb 2018
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpn
60RISK
open
Exploit-DB
AsusWRT LAN - Remote Code Execution (Metasploit)
CVE-2018-599926 Feb 2018
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, pro
60RISK
open
Exploit-DB
CloudMe Sync 1.10.9 - Stack-Based Buffer Overflow (Metasploit)
CVE-2018-689226 Feb 2018
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RISK
open
Exploit-DB
Joomla! Component Alexandria Book Library 3.1.2 - 'letter' SQL Injection
CVE-2018-731222 Feb 2018
SQL Injection exists in the Alexandria Book Library 3.1.2 component for Joomla! via the letter parameter.
23RISK
open
Exploit-DB
Joomla! Component Proclaim 9.1.1 - Arbitrary File Upload
CVE-2018-731622 Feb 2018
Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action.
23RISK
open
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-622422 Feb 2018
A lack of cross-site request forgery (CSRF) protection vulnerability in Trend Micro Email Encryption Gateway 5.5 could a
23RISK
open
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-621922 Feb 2018
An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdr
23RISK
open
Exploit-DB
Joomla! Component CheckList 1.1.1 - SQL Injection
CVE-2018-731822 Feb 2018
SQL Injection exists in the CheckList 1.1.1 component for Joomla! via the title_search, tag_search, name_search, descrip
23RISK
open
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-622122 Feb 2018
An unvalidated software update vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a man-in-the-middle
23RISK
open
Exploit-DB
Joomla! Component PrayerCenter 3.0.2 - 'sessionid' SQL Injection
CVE-2018-731422 Feb 2018
SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerabil
50RISK
open
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-623022 Feb 2018
A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 search configuration script could allow an
23RISK
open
Exploit-DB
Joomla! Component CW Tags 2.0.6 - SQL Injection
CVE-2018-731322 Feb 2018
SQL Injection exists in the CW Tags 2.0.6 component for Joomla! via the searchtext array parameter.
28RISK
open
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-622022 Feb 2018
An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbi
28RISK
open
Exploit-DB
NoMachine < 6.0.80 (x64) - 'nxfuse' Privilege Escalation
CVE-2018-694722 Feb 2018
An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoM
23RISK
open
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-622622 Feb 2018
Reflected cross-site scripting (XSS) vulnerabilities in two Trend Micro Email Encryption Gateway 5.5 configuration files
23RISK
open
Exploit-DB
NoMachine < 6.0.80 (x86) - 'nxfuse' Privilege Escalation
CVE-2018-694722 Feb 2018
An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoM
23RISK
open
Exploit-DB
Joomla! Component Ek Rishta 2.9 - SQL Injection
CVE-2018-731522 Feb 2018
SQL Injection exists in the Ek Rishta 2.9 component for Joomla! via the gender, age1, age2, religion, mothertounge, cast
23RISK
open
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-622522 Feb 2018
An XML external entity injection (XXE) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an authenti
23RISK
open
Exploit-DB
Joomla! Component Proclaim 9.1.1 - Backup File Download
CVE-2018-731722 Feb 2018
Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/.
23RISK
open
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-622822 Feb 2018
A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to exe
28RISK
open
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-622922 Feb 2018
A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 edit policy script could allow an attacker
28RISK
open
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-622322 Feb 2018
A missing authentication for appliance registration vulnerability in Trend Micro Email Encryption Gateway 5.5 could allo
28RISK
open
Exploit-DB
Armadito Antivirus 0.12.7.2 - Detection Bypass
CVE-2018-728922 Feb 2018
An issue was discovered in armadito-windows-driver/src/communication.c in Armadito 0.12.7.2. Malware with filenames cont
23RISK
open
Exploit-DB
Joomla! Component OS Property Real Estate 3.12.7 - SQL Injection
CVE-2018-731922 Feb 2018
SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla! via the cooling_system1, heating_system
23RISK
open
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-622722 Feb 2018
A stored cross-site scripting (XSS) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to
23RISK
open
Exploit-DB
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-622222 Feb 2018
Arbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log fi
23RISK
open
Exploit-DB
Disk Savvy Enterprise 10.4.18 - Buffer Overflow (SEH)
CVE-2018-648121 Feb 2018
A buffer overflow vulnerability in the control protocol of Disk Savvy Enterprise v10.4.18 allows remote attackers to exe
28RISK
open
Exploit-DB
Wavpack 5.1.0 - Denial of Service
CVE-2018-725421 Feb 2018
The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of
23RISK
open
Exploit-DB
Disk Pulse Enterprise 10.4.18 - 'Import Command' Buffer Overflow (SEH)
CVE-2017-731021 Feb 2018
A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9
50RISK
open
Exploit-DB
Microsoft Windows - StorSvc SvcMoveFileInheritSecurity Arbitrary File Creation Privilege Escalation
CVE-2018-082620 Feb 2018
Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, versi
23RISK
open
previouspage 102 / 760next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.