Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,980cataloged exploits
36,899CVEs with public exploitation
24,695lab-tested
24,476 exploits
Exploit-DBVexDay Proof
HPE iMC - dbman 'RestoreDBase' Remote Command Execution (Metasploit)
CVE-2017-5817remotewindows10 Jan 2018
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RISK
open
Exploit-DB
Parity Browser < 1.6.10 - Bypass Same Origin Policy
CVE-2017-18016localmultiple10 Jan 2018
Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive informat
23RISK
open
Exploit-DB
SAP NetWeaver J2EE Engine 7.40 - SQL Injection
CVE-2016-2386CRITICALunder attackwebappsmultiple10 Jan 2018
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbi
100RISK
open
Exploit-DBVexDay Proof
Joomla! Component Easydiscuss < 4.0.21 - Cross-Site Scripting
CVE-2018-5263webappsphp10 Jan 2018
The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS.
23RISK
open
Exploit-DB
SAP NetWeaver J2EE Engine 7.40 - SQL Injection
CVE-2016-2388MEDIUMunder attackwebappsmultiple10 Jan 2018
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user infor
75RISK
open
Exploit-DBVexDay Proof
HPE iMC - dbman 'RestartDB' Remote Command Execution (Metasploit)
CVE-2017-5816remotewindows10 Jan 2018
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - 'Lowerer::LowerSetConcatStrMultiItem' Missing Integer Overflow Check
CVE-2018-0758doswindows10 Jan 2018
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitra
45RISK
open
Exploit-DB
SAP NetWeaver J2EE Engine 7.40 - SQL Injection
CVE-2016-1910webappsmultiple10 Jan 2018
The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors,
23RISK
open
Exploit-DB
WordPress Plugin Events Calendar - 'event_id' SQL Injection
CVE-2018-5315webappsphp10 Jan 2018
The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php.
23RISK
open
Exploit-DB
Muviko 1.1 - SQL Injection
CVE-2017-17970webappsphp10 Jan 2018
Multiple SQL injection vulnerabilities in Muviko 1.1 allow remote attackers to execute arbitrary SQL commands via the (1
23RISK
open
Exploit-DB
Jungo Windriver 12.5.1 - Local Privilege Escalation
CVE-2018-5189localwindows10 Jan 2018
Race condition in Jungo Windriver 12.5.1 allows local users to cause a denial of service (buffer overflow) or gain syste
23RISK
open
Exploit-DB
DiskBoss Enterprise 8.8.16 - Remote Buffer Overflow
CVE-2018-5262remotewindows10 Jan 2018
A stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'nt!NtQuerySystemInformation (information class 138_ QueryMemoryTopologyInformation)' Kernel Pool Memory Disclosure
CVE-2018-0746doswindows09 Jan 2018
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Wi
23RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Escape Analysis Bug
CVE-2017-11918doswindows09 Jan 2018
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'nt!NtQueryInformationProcess (information class 76_ QueryProcessEnergyValues)' Kernel Stack Memory Disclosure
CVE-2018-0745doswindows09 Jan 2018
The Windows kernel in Windows 10 version 1703. Windows 10 version 1709, and Windows Server, version 1709 allows an infor
23RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Op_MaxInAnArray and Op_MinInAnArray can Explicitly call User-Defined JavaScript Functions
CVE-2017-11893doswindows09 Jan 2018
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execut
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'asm.js' Out-of-Bounds Read
CVE-2017-11911doswindows09 Jan 2018
ChakraCore and Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - BackwardPass::RemoveEmptyLoopAfterMemOp Does not Insert Branches
CVE-2017-11909doswindows09 Jan 2018
ChakraCore and Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i
35RISK
open
Exploit-DB
Microsoft Office - 'Composite Moniker Remote Code Execution
CVE-2017-8570HIGHunder attacklocalwindows09 Jan 2018
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RISK
open
Exploit-DB
FiberHome LM53Q1 - Multiple Vulnerabilities
CVE-2017-16886webappshardware08 Jan 2018
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact
23RISK
open
Exploit-DBVexDay Proof
Vanilla < 2.1.5 - Cross-Site Request Forgery
CVE-2017-1000432webappsphp08 Jan 2018
Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access
23RISK
open
Exploit-DB
Synology DiskStation Manager (DSM) < 6.1.3-15152 - 'forget_passwd.cgi' User Enumeration
CVE-2017-9554webappscgi08 Jan 2018
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allo
60RISK
open
Exploit-DBVexDay Proof
VX Search Enterprise 10.1.12 - Denial of Service
CVE-2017-15662doswindows08 Jan 2018
In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. The atta
23RISK
open
Exploit-DB
FiberHome LM53Q1 - Multiple Vulnerabilities
CVE-2017-16887webappshardware08 Jan 2018
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact
35RISK
open
Exploit-DB
DiskBoss Enterprise 8.5.12 - Denial of Service
CVE-2017-15665doswindows08 Jan 2018
In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack
23RISK
open
Exploit-DBVexDay Proof
Android - Inter-Process munmap due to Race Condition in ashmem
CVE-2017-13216dosandroid08 Jan 2018
In ashmem_ioctl of ashmem.c, there is an out-of-bounds write due to insufficient locking when accessing asma. This could
23RISK
open
Exploit-DB
Disk Pulse Enterprise 10.1.18 - Denial of Service
CVE-2017-15663doswindows08 Jan 2018
In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The att
28RISK
open
Exploit-DB
FiberHome LM53Q1 - Multiple Vulnerabilities
CVE-2017-16885webappshardware08 Jan 2018
Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining informati
35RISK
open
Exploit-DB
Sync Breeze Enterprise 10.1.16 - Denial of Service
CVE-2017-15664doswindows08 Jan 2018
In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability. The at
23RISK
open
Exploit-DB
gps-server.net GPS Tracking Software < 3.1 - Multiple Vulnerabilities
CVE-2017-17097webappsphp05 Jan 2018
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords
23RISK
open
previouspage 115 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.