Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DBVexDay Proof
phpMyAdmin - (Authenticated) Remote Code Execution (Metasploit)
CVE-2018-12613remotephp13 Jul 2018
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open
Exploit-DBVexDay Proof
WAGO e!DISPLAY 7300T - Multiple Vulnerabilities
CVE-2018-12980webappsphp13 Jul 2018
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerabilit
35RISK
open
Exploit-DBVexDay Proof
Apache CouchDB - Arbitrary Command Execution (Metasploit)
CVE-2017-12636remotelinux13 Jul 2018
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RISK
open
Exploit-DBVexDay Proof
WAGO e!DISPLAY 7300T - Multiple Vulnerabilities
CVE-2018-12979webappsphp13 Jul 2018
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions
23RISK
open
Exploit-DBVexDay Proof
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-0706webappshardware13 Jul 2018
Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticate
50RISK
open
Exploit-DBVexDay Proof
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-0710webappshardware13 Jul 2018
Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authe
28RISK
open
Exploit-DBVexDay Proof
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-0709webappshardware13 Jul 2018
Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow auth
28RISK
open
Exploit-DBVexDay Proof
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-0708webappshardware13 Jul 2018
Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allo
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - POP/MOV SS Local Privilege Elevation (Metasploit)
CVE-2018-8897localwindows13 Jul 2018
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RISK
open
Exploit-DBVexDay Proof
WAGO e!DISPLAY 7300T - Multiple Vulnerabilities
CVE-2018-12981webappsphp13 Jul 2018
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerabilit
23RISK
open
Exploit-DBVexDay Proof
Apache CouchDB - Arbitrary Command Execution (Metasploit)
CVE-2017-12635remotelinux13 Jul 2018
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RISK
open
Exploit-DBVexDay Proof
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-0707webappshardware13 Jul 2018
Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could
50RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - BoundFunction::NewInstance Out-of-Bounds Read
CVE-2018-8139doswindows12 Jul 2018
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Out-of-Bounds Reads/Writes
CVE-2018-8145doswindows12 Jul 2018
An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Type Confusion with Hoisted SetConcatStrMultiItemBE Instructions
CVE-2018-8229doswindows12 Jul 2018
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISK
open
Exploit-DBVexDay Proof
IBM QRadar SIEM - Remote Code Execution (Metasploit)
CVE-2018-1612MEDIUMremoteunix11 Jul 2018
IBM QRadar Incident Forensics (IBM QRadar SIEM 7.2, and 7.3) could allow a remote attacker to bypass authentication and
60RISK
open
Exploit-DBVexDay Proof
IBM QRadar SIEM - Remote Code Execution (Metasploit)
CVE-2018-1418remoteunix11 Jul 2018
IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM
50RISK
open
Exploit-DBVexDay Proof
IBM QRadar SIEM - Remote Code Execution (Metasploit)
CVE-2016-9722remoteunix11 Jul 2018
IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be r
43RISK
open
Exploit-DBVexDay Proof
Linux Kernel < 4.13.9 (Ubuntu 16.04 / Fedora 27) - Local Privilege Escalation
CVE-2017-16995locallinux10 Jul 2018
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
Exploit-DBVexDay Proof
CMS Made Simple 2.2.5 - (Authenticated) Remote Code Execution
CVE-2018-1000094webappsphp04 Jul 2018
CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows a
50RISK
open
Exploit-DBVexDay Proof
Boxoft WAV to MP3 Converter 1.1 - Buffer Overflow (Metasploit)
CVE-2015-7243localwindows03 Jul 2018
Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly
50RISK
open
Exploit-DBVexDay Proof
VMware NSX SD-WAN Edge < 3.1.2 - Command Injection
CVE-2018-6961HIGHunder attackwebappshardware02 Jul 2018
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web U
100RISK
open
Exploit-DBVexDay Proof
FTPShell Client 6.70 (Enterprise Edition) - Stack Buffer Overflow (Metasploit)
CVE-2018-7573remotewindows02 Jul 2018
An issue was discovered in FTPShell Client 6.7. A remote FTP server can send 400 characters of 'F' in conjunction with t
50RISK
open
Exploit-DBVexDay Proof
Nagios XI 5.2.6-5.4.12 - Chained Remote Code Execution (Metasploit)
CVE-2018-8733remotelinux02 Jul 2018
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an
43RISK
open
Exploit-DBVexDay Proof
Nagios XI 5.2.6-5.4.12 - Chained Remote Code Execution (Metasploit)
CVE-2018-8736remotelinux02 Jul 2018
A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RC
50RISK
open
Exploit-DBVexDay Proof
Nagios XI 5.2.6-5.4.12 - Chained Remote Code Execution (Metasploit)
CVE-2018-8734remotelinux02 Jul 2018
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker
50RISK
open
Exploit-DBVexDay Proof
Nagios XI 5.2.6-5.4.12 - Chained Remote Code Execution (Metasploit)
CVE-2018-8735remotelinux02 Jul 2018
Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execut
50RISK
open
Exploit-DBVexDay Proof
HongCMS 3.0.0 - (Authenticated) SQL Injection
CVE-2018-12912webappsphp28 Jun 2018
An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via a
23RISK
open
Exploit-DBVexDay Proof
Quest KACE Systems Management - Command Injection (Metasploit)
CVE-2018-11138CRITICALunder attackransomwareremoteunix27 Jun 2018
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by
100RISK
open
Exploit-DBVexDay Proof
Foxit Reader 9.0.1.1049 - Remote Code Execution
CVE-2018-9958remotewindows25 Jun 2018
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1
50RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.