Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
22,786 exploits
Exploit-DB
Dell EMC Isilon OneFS - Multiple Vulnerabilities
CVE-2018-120114 Feb 2018
Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and vers
23RISK
open
Exploit-DB
Dell EMC Isilon OneFS - Multiple Vulnerabilities
CVE-2018-121314 Feb 2018
Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, an
23RISK
open
Exploit-DB
TypeSetter CMS 5.1 - 'Host' Header Injection
CVE-2018-688913 Feb 2018
An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a m
23RISK
open
Exploit-DB
CloudMe Sync < 1.11.0 - Buffer Overflow
CVE-2018-689213 Feb 2018
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RISK
open
Exploit-DB
Advantech WebAccess 8.3.0 - Remote Code Execution
CVE-2018-691113 Feb 2018
The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS
28RISK
open
Exploit-DB
glibc - 'LD_AUDIT' Arbitrary DSO Load Privilege Escalation (Metasploit)
CVE-2010-385612 Feb 2018
ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use
43RISK
open
Exploit-DB
glibc - '$ORIGIN' Expansion Privilege Escalation (Metasploit)
CVE-2010-384712 Feb 2018
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not pro
38RISK
open
Exploit-DB
Juju-run Agent - Privilege Escalation (Metasploit)
CVE-2017-923212 Feb 2018
Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate pe
50RISK
open
Exploit-DB
glibc - 'LD_AUDIT' Arbitrary DSO Load Privilege Escalation (Metasploit)
CVE-2010-384712 Feb 2018
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not pro
38RISK
open
Exploit-DB
LibreOffice < 6.0.1 - '=WEBSERVICE' Remote Arbitrary File Disclosure
CVE-2018-687110 Feb 2018
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a
28RISK
open
Exploit-DB
macOS Kernel - Use-After-Free Due to Lack of Locking in 'AppleEmbeddedOSSupportHostClient::registerNotificationPort'
CVE-2018-408309 Feb 2018
An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Touch Bar S
23RISK
open
Exploit-DB
Cisco ASA - Crash (PoC)
CVE-2018-010107 Feb 2018
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Softw
45RISK
open
Exploit-DB
Asterisk 13.17.2 - 'chan_skinny' Remote Memory Corruption
CVE-2017-1709007 Feb 2018
An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and old
45RISK
open
Exploit-DB
Adobe Coldfusion 11.0.03.292866 - BlazeDS Java Object Deserialization Remote Code Execution
CVE-2017-3066CRITICALunder attack07 Feb 2018
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier hav
100RISK
open
Exploit-DB
MalwareFox AntiMalware 2.74.0.150 - Privilege Escalation
CVE-2018-660607 Feb 2018
An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows
23RISK
open
Exploit-DB
Joomla! Component Zh GoogleMap 8.4.0.0 - SQL Injection
CVE-2018-658205 Feb 2018
SQL Injection exists in the Zh GoogleMap 8.4.0.0 component for Joomla! via the id parameter in a getPlacemarkDetails, ge
23RISK
open
Exploit-DB
MalwareFox AntiMalware 2.74.0.150 - Local Privilege Escalation
CVE-2018-659305 Feb 2018
An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows
23RISK
open
Exploit-DB
Wonder CMS 2.3.1 - 'Host' Header Injection
CVE-2017-1452305 Feb 2018
WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NO
23RISK
open
Exploit-DB
Apport/ABRT - 'chroot' Local Privilege Escalation (Metasploit)
CVE-2015-131805 Feb 2018
The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a craf
38RISK
open
Exploit-DB
Microsoft Windows - 'EternalRomance'/'EternalSynergy'/'EternalChampion' SMB Remote Code Execution (Metasploit) (MS17-010)
CVE-2017-0147HIGHunder attackransomware05 Feb 2018
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Exploit-DB
Claymore Dual GPU Miner 10.5 - Format String
CVE-2018-631705 Feb 2018
The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format strin
50RISK
open
Exploit-DB
Wonder CMS 2.3.1 - Unrestricted File Upload
CVE-2017-1452105 Feb 2018
In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.
23RISK
open
Exploit-DB
Microsoft Windows - 'EternalRomance'/'EternalSynergy'/'EternalChampion' SMB Remote Code Execution (Metasploit) (MS17-010)
CVE-2017-0143HIGHunder attackransomware05 Feb 2018
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Exploit-DB
HPE iLO 4 < 2.53 - Add New Administrator User
CVE-2017-1254205 Feb 2018
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RISK
open
Exploit-DB
Microsoft Windows - 'EternalRomance'/'EternalSynergy'/'EternalChampion' SMB Remote Code Execution (Metasploit) (MS17-010)
CVE-2017-0146HIGHunder attackransomware05 Feb 2018
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Exploit-DB
Netis WF2419 Router - Cross-Site Scripting
CVE-2018-619005 Feb 2018
Netis WF2419 V3.2.41381 devices allow XSS via the Description field on the MAC Filtering page.
23RISK
open
Exploit-DB
Joomla! Component Zh BaiduMap 3.0.0.1 - SQL Injection
CVE-2018-660505 Feb 2018
SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, get
50RISK
open
Exploit-DB
WordPress Core - 'load-scripts.php' Denial of Service
CVE-2018-638905 Feb 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISK
open
Exploit-DB
Online Voting System - Authentication Bypass
CVE-2018-618005 Feb 2018
A flaw in the profile section of Online Voting System 1.0 allows an unauthenticated user to set an arbitrary password fo
23RISK
open
Exploit-DB
Joomla! Component Zh YandexMap 6.2.1.0 - 'id' SQL Injection
CVE-2018-660405 Feb 2018
SQL Injection exists in the Zh YandexMap 6.2.1.0 component for Joomla! via the id parameter in a task=getPlacemarkDetail
23RISK
open
previouspage 105 / 760next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.