Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DBVexDay Proof
Skia and Firefox - Integer Overflow in SkTDArray Leading to Out-of-Bounds Write
CVE-2018-5159dosmultiple25 May 2018
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks,
28RISK
open
Exploit-DBVexDay Proof
Oracle WebCenter Sites 11.1.1.8.0/12.2.1.x - Cross-Site Scripting
CVE-2018-2791webappsmultiple25 May 2018
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported
50RISK
open
Exploit-DBVexDay Proof
Samsung Galaxy S7 Edge - Overflow in OMACP WbXml String Extension Processing
CVE-2018-10751dosandroid23 May 2018
A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Ex
23RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Magic Value Type Confusion
CVE-2018-0953doswindows22 May 2018
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
35RISK
open
Exploit-DBVexDay Proof
Linux 4.4.0 < 4.4.0-53 - 'AF_PACKET chocobo_root' Local Privilege Escalation (Metasploit)
CVE-2016-8655locallinux22 May 2018
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cau
43RISK
open
Exploit-DBVexDay Proof
AMD / ARM / Intel - Speculative Execution Variant 4 Speculative Store Bypass
CVE-2018-3639MEDIUMdoshardware22 May 2018
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addres
45RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'POP/MOV SS' Privilege Escalation
CVE-2018-8897localwindows22 May 2018
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RISK
open
Exploit-DBVexDay Proof
Linux 2.6.30 < 2.6.36-rc8 - Reliable Datagram Sockets (RDS) Privilege Escalation (Metasploit)
CVE-2010-3904HIGHunder attacklocallinux21 May 2018
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the
91RISK
open
Exploit-DBVexDay Proof
DynoRoot DHCP Client - Command Injection
CVE-2018-1111HIGHlocallinux18 May 2018
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RISK
open
Exploit-DBVexDay Proof
Linux 4.8.0 < 4.8.0-46 - AF_PACKET packet_set_ring Privilege Escalation (Metasploit)
CVE-2017-7308locallinux18 May 2018
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate cer
43RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Bound Check Elimination Bug
CVE-2018-0980doswindows18 May 2018
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RISK
open
Exploit-DBVexDay Proof
Apache Struts 2 - Struts 1 Plugin Showcase OGNL Code Execution (Metasploit)
CVE-2017-9791CRITICALunder attackremotemultiple17 May 2018
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RISK
open
Exploit-DBVexDay Proof
Nanopool Claymore Dual Miner 7.3 - Remote Code Execution
CVE-2018-1000049remotewindows17 May 2018
Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner
60RISK
open
Exploit-DBVexDay Proof
Jenkins CLI - HTTP Java Deserialization (Metasploit)
CVE-2016-9299remotelinux17 May 2018
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a
60RISK
open
Exploit-DBVexDay Proof
Libuser - 'roothelper' Local Privilege Escalation (Metasploit)
CVE-2015-3245locallinux16 May 2018
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in t
38RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Token Process Trust SID Access Check Bypass Privilege Escalation
CVE-2018-8134localwindows16 May 2018
An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows
23RISK
open
Exploit-DBVexDay Proof
Libuser - 'roothelper' Local Privilege Escalation (Metasploit)
CVE-2015-3246MEDIUMunder attacklocallinux16 May 2018
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod
78RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 2003 SP2 - 'RRAS' SMB Remote Code Execution
CVE-2017-11885remotewindows13 May 2018
Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold,
35RISK
open
Exploit-DBVexDay Proof
Mantis Bug Tracker 1.1.3 - 'manage_proj_page' PHP Code Execution (Metasploit)
CVE-2008-4687remotephp10 May 2018
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RISK
open
Exploit-DBVexDay Proof
FTPShell Client 6.7 - Buffer Overflow
CVE-2018-7573remotewindows08 May 2018
An issue was discovered in FTPShell Client 6.7. A remote FTP server can send 400 characters of 'F' in conjunction with t
50RISK
open
Exploit-DBVexDay Proof
PlaySMS 1.4 - 'sendfromfile.php?Filename' (Authenticated) 'Code Execution (Metasploit)
CVE-2017-9080remotephp08 May 2018
PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile
50RISK
open
Exploit-DBVexDay Proof
PlaySMS - 'import.php' (Authenticated) CSV File Upload Code Execution (Metasploit)
CVE-2017-9101remotephp08 May 2018
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RISK
open
Exploit-DBVexDay Proof
Palo Alto Networks - 'readSessionVarsFromFile()' Session Corruption (Metasploit)
CVE-2017-15944CRITICALunder attackremoteunix08 May 2018
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RISK
open
Exploit-DBVexDay Proof
Google Chrome V8 - Object Allocation Size Integer Overflow
CVE-2018-6065HIGHunder attackremotemultiple04 May 2018
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch
83RISK
open
Exploit-DBVexDay Proof
Microsoft Windows WMI - Recieve Notification Exploit (Metasploit)
CVE-2016-0040HIGHunder attacklocalwindows_x86-6404 May 2018
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to g
91RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::jsElementScrollHeightGetter' Use-After-Free
CVE-2018-4200dosmultiple02 May 2018
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud
23RISK
open
Exploit-DBVexDay Proof
WordPress Plugin Form Maker 1.12.20 - CSV Injection
CVE-2018-10504webappsphp30 Apr 2018
The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.
23RISK
open
Exploit-DBVexDay Proof
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
CVE-2018-8733webappsphp30 Apr 2018
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an
43RISK
open
Exploit-DBVexDay Proof
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
CVE-2018-8734webappsphp30 Apr 2018
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker
50RISK
open
Exploit-DBVexDay Proof
Apple macOS/iOS - ReportCrash mach port Replacement due to Failure to Respect MIG Ownership Rules
CVE-2018-4206dosmultiple30 Apr 2018
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.