Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
22,786 exploits
Exploit-DB
Microsoft Windows Subsystem for Linux - 'execve()' Local Privilege Escalation
CVE-2018-074302 Feb 2018
Windows Subsystem for Linux in Windows 10 version 1703, Windows 10 version 1709, and Windows Server, version 1709 allows
23RISK
open
Exploit-DB
Oracle Hospitality Simphony (MICROS) 2.7 < 2.9 - Directory Traversal
CVE-2018-263602 Feb 2018
Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Security).
28RISK
open
Exploit-DB
BMC Server Automation RSCD Agent - NSH Remote Command Execution (Metasploit)
CVE-2016-154301 Feb 2018
The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux a
60RISK
open
Exploit-DB
BMC Server Automation RSCD Agent - NSH Remote Command Execution (Metasploit)
CVE-2016-154201 Feb 2018
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and U
60RISK
open
Exploit-DB
WebKit - 'detachWrapper' Use-After-Free
CVE-2018-408901 Feb 2018
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. Safa
23RISK
open
Exploit-DB
Joomla! Component CP Event Calendar 3.0.1 - 'id' SQL Injection
CVE-2018-639830 Jan 2018
SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action.
23RISK
open
Exploit-DB
HPE iMC 7.3 - RMI Java Deserialization
CVE-2017-579230 Jan 2018
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
35RISK
open
Exploit-DB
BMC BladeLogic RSCD Agent 8.3.00.64 - Windows Users Disclosure
CVE-2016-506330 Jan 2018
The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote atta
23RISK
open
Exploit-DB
Hotspot Shield - Information Disclosure
CVE-2018-646030 Jan 2018
Hotspot Shield runs a webserver with a static IP address 127.0.0.1 and port 895. The web server uses JSONP and hosts sen
28RISK
open
Exploit-DB
System Shield 5.0.0.136 - Privilege Escalation
CVE-2018-570130 Jan 2018
In Iolo System Shield AntiVirus and AntiSpyware 5.0.0.136, the amp.sys driver file contains an Arbitrary Write vulnerabi
28RISK
open
Exploit-DB
Joomla! Component Visual Calendar 3.1.3 - 'id' SQL Injection
CVE-2018-639530 Jan 2018
SQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! via the id parameter in a view=load action.
23RISK
open
Exploit-DB
Joomla! Component Picture Calendar for Joomla! 3.1.4 - Directory Traversal
CVE-2018-639730 Jan 2018
Directory Traversal exists in the Picture Calendar 3.1.4 component for Joomla! via the list.php folder parameter.
28RISK
open
Exploit-DB
Advantech WebAccess < 8.3 - SQL Injection
CVE-2017-1671630 Jan 2018
A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs
23RISK
open
Exploit-DB
iBall WRA150N - Multiple Vulnerabilities
CVE-2018-638829 Jan 2018
iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands
23RISK
open
Exploit-DB
systemd (systemd-tmpfiles) < 236 - 'fs.protected_hardlinks=0' Local Privilege Escalation
CVE-2017-1807829 Jan 2018
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the
23RISK
open
Exploit-DB
Arq 5.10 - Local Privilege Escalation (2)
CVE-2017-1694529 Jan 2018
The standardrestorer binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequen
23RISK
open
Exploit-DB
Oracle WebLogic - wls-wsat Component Deserialization Remote Code Execution (Metasploit)
CVE-2017-10271HIGHunder attackransomware29 Jan 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
Exploit-DB
Arq 5.10 - Local Privilege Escalation (1)
CVE-2017-1692829 Jan 2018
The arq_updater binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently g
23RISK
open
Exploit-DB
macOS - 'sysctl_vfs_generic_conf' Stack Leak Through Struct Padding
CVE-2018-409029 Jan 2018
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS
23RISK
open
Exploit-DB
Multilanguage Real Estate MLM Script 3.0 - 'srch' SQL Injection
CVE-2018-636428 Jan 2018
SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter.
23RISK
open
Exploit-DB
Joomla! Component Jtag Members Directory 5.3.7 - Arbitrary File Download
CVE-2018-600828 Jan 2018
Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter
50RISK
open
Exploit-DB
TSiteBuilder 1.0 - SQL Injection
CVE-2018-636528 Jan 2018
SQL Injection exists in TSiteBuilder 1.0 via the id parameter to /site.php, /pagelist.php, or /page_new.php.
23RISK
open
Exploit-DB
Buddy Zone 2.9.9 - SQL Injection
CVE-2018-636728 Jan 2018
SQL Injection exists in Vastal I-Tech Buddy Zone Facebook Clone 2.9.9 via the /chat_im/chat_window.php request_id parame
23RISK
open
Exploit-DB
Nexpose < 6.4.66 - Cross-Site Request Forgery
CVE-2017-526428 Jan 2018
Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated A
23RISK
open
Exploit-DB
Artifex MuJS 1.0.2 - Denial of Service
CVE-2018-619128 Jan 2018
The js_strtod function in jsdtoa.c in Artifex MuJS through 1.0.2 has an integer overflow because of incorrect exponent v
23RISK
open
Exploit-DB
Hot Scripts Clone - 'subctid' SQL Injection
CVE-2017-1761228 Jan 2018
Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.
23RISK
open
Exploit-DB
Artifex MuJS 1.0.2 - Integer Overflow
CVE-2018-575928 Jan 2018
jsparse.c in Artifex MuJS through 1.0.2 does not properly maintain the AST depth for binary expressions, which allows re
23RISK
open
Exploit-DB
Joomla! Component JS Support Ticket 1.1.0 - Cross-Site Request Forgery
CVE-2018-600728 Jan 2018
CSRF exists in the JS Support Ticket 1.1.0 component for Joomla! and allows attackers to inject HTML or edit a ticket.
23RISK
open
Exploit-DB
Task Rabbit Clone 1.0 - 'id' SQL Injection
CVE-2018-636328 Jan 2018
SQL Injection exists in Task Rabbit Clone 1.0 via the single_blog.php id parameter.
23RISK
open
Exploit-DB
KeystoneJS < 4.0.0-beta.7 - Cross-Site Request Forgery
CVE-2017-1657028 Jan 2018
KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureL
23RISK
open
previouspage 106 / 760next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.