Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
3,477 exploits
Metasploit300
Nuuo Central Management Server User Session Token Bruteforce
CVE-2018-1788811 Oct 2018
NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers
23RISK
open
Metasploit300
Nuuo Central Management Authenticated SQL Server SQLi
CVE-2018-1898211 Oct 2018
NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can b
50RISK
open
Metasploit0
Nuuo Central Management Server Authenticated Arbitrary File Upload
CVE-2018-1793611 Oct 2018
NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite co
23RISK
open
Metasploit600
blueimp's jQuery (Arbitrary) File Upload
CVE-2018-920609 Oct 2018
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISK
open
Metasploit400
WebEx Local Service Permissions Exploit
CVE-2018-15442HIGH09 Oct 2018
Cisco Webex Meetings Desktop App Update Service Command Injection Vulnerability
61RISK
open
Metasploit0
Windows NtUserSetWindowFNID Win32k User Callback
CVE-2018-8453HIGHunder attackransomware09 Oct 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
Metasploit600
Imperva SecureSphere PWS Command Injection
CVE-2018-1666008 Oct 2018
A command injection vulnerability in PWS in Imperva SecureSphere 13.0.0.10 and 13.1.0.10 Gateway allows an attacker with
23RISK
open
Metasploit600
Malicious Git HTTP Server For CVE-2018-17456
CVE-2018-1745605 Oct 2018
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RISK
open
Metasploit600
Cisco Prime Infrastructure Unauthenticated Remote Code Execution
CVE-2018-1537904 Oct 2018
Cisco Prime Infrastructure Arbitrary File Upload and Command Execution Vulnerability
60RISK
open
Metasploit300
Zahir Enterprise Plus 6 Stack Buffer Overflow
CVE-2018-1740828 Sep 2018
Stack-based buffer overflows in Zahir Accounting Enterprise Plus 6 through build 10b allow remote attackers to execute a
43RISK
open
Metasploit600
Navigate CMS Unauthenticated Remote Code Execution
CVE-2018-1755326 Sep 2018
An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs N
60RISK
open
Metasploit600
Navigate CMS Unauthenticated Remote Code Execution
CVE-2018-1755226 Sep 2018
SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigat
60RISK
open
Metasploit0
Google Chrome 67, 68 and 69 Object.create exploit
CVE-2018-17463HIGHunder attack25 Sep 2018
Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbit
100RISK
open
Metasploit600
Adobe ColdFusion CKEditor unrestricted file upload
CVE-2018-15961CRITICALunder attack11 Sep 2018
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISK
open
Metasploit300
Cisco RV320 and RV325 Unauthenticated Remote Code Execution
CVE-2019-1652HIGHunder attack09 Sep 2018
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RISK
open
Metasploit300
Cisco RV320 and RV325 Unauthenticated Remote Code Execution
CVE-2019-1653HIGHunder attack09 Sep 2018
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open
Metasploit0
Snap Creek Duplicator WordPress plugin code injection
CVE-2018-1720729 Aug 2018
An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and
30RISK
open
Metasploit300
Microsoft Windows ALPC Task Scheduler Local Privilege Elevation
CVE-2018-8440HIGHunder attackransomware27 Aug 2018
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
91RISK
open
Metasploit600
Wordpress Plainview Activity Monitor RCE
CVE-2018-1587726 Aug 2018
The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell meta
60RISK
open
Metasploit600
Apache Struts 2 Namespace Redirect OGNL Injection
CVE-2018-11776HIGHunder attack22 Aug 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
Metasploit600
Ghostscript Failed Restore Command Execution
CVE-2018-1650921 Aug 2018
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RISK
open
Metasploit300
Pimcore Gather Credentials via SQL Injection
CVE-2018-1405813 Aug 2018
Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
43RISK
open
Metasploit600
PHP Laravel Framework token Unserialize Remote Command Execution
CVE-2017-1689407 Aug 2018
In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwo
60RISK
open
Metasploit600
PHP Laravel Framework token Unserialize Remote Command Execution
CVE-2018-15133HIGHunder attack07 Aug 2018
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
Metasploit300
Windows unmarshal post exploitation
CVE-2018-0824HIGHunder attack05 Aug 2018
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized
100RISK
open
Metasploit600
NUUO NVRmini upgrade_handle.php Remote Command Execution
CVE-2018-14933CRITICALunder attack04 Aug 2018
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir par
100RISK
open
Metasploit300
cgit Directory Traversal
CVE-2018-1491203 Aug 2018
cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned
60RISK
open
Metasploit300
Mikrotik Winbox Arbitrary File Read
CVE-2018-14847CRITICALunder attack02 Aug 2018
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open
Metasploit600
Network Manager VPNC Username Privilege Escalation
CVE-2018-10900HIGH26 Jul 2018
Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attac
56RISK
open
Metasploit300
Eaton Xpert Meter SSH Private Key Exposure Scanner
CVE-2018-1615818 Jul 2018
Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different cus
30RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.