Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
3,477 exploits
Metasploit300
Dicoogle PACS Web Server Directory Traversal
CVE-2018-25113HIGH11 Jul 2018
Dicoogle PACS Web Server 2.5.0 Unauthenticated Path Traversal
36RISK
open
Metasploit600
QNAP Q'Center change_passwd Command Execution
CVE-2018-070611 Jul 2018
Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticate
50RISK
open
Metasploit600
QNAP Q'Center change_passwd Command Execution
CVE-2018-070711 Jul 2018
Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could
50RISK
open
Metasploit600
CMS Made Simple Authenticated RCE via File Upload/Copy
CVE-2018-100009403 Jul 2018
CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows a
50RISK
open
Metasploit300
Delta Electronics Delta Industrial Automation COMMGR 1.08 Stack Buffer Overflow
CVE-2018-1059402 Jul 2018
Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPS
50RISK
open
Metasploit300
Wordpress Arbitrary File Deletion
CVE-2018-1289526 Jun 2018
WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/
30RISK
open
Metasploit600
PRTG Network Monitor Authenticated RCE
CVE-2018-9276HIGHunder attack25 Jun 2018
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISK
open
Metasploit400
phpMyAdmin Authenticated Remote Code Execution
CVE-2018-1261319 Jun 2018
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open
Metasploit600
MicroFocus Secure Messaging Gateway Remote Code Execution
CVE-2018-12465CRITICAL19 Jun 2018
Remote Code Execution in Micro Focus Secure Messaging Gateway
85RISK
open
Metasploit600
MicroFocus Secure Messaging Gateway Remote Code Execution
CVE-2018-12464CRITICAL19 Jun 2018
Unauthenticated SQL injection in Micro Focus Secure Messaging Gateway
85RISK
open
Metasploit600
Axis Network Camera .srv-to-parhand RCE
CVE-2018-1066018 Jun 2018
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
60RISK
open
Metasploit600
Axis Network Camera .srv-to-parhand RCE
CVE-2018-1066218 Jun 2018
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
60RISK
open
Metasploit600
Axis Network Camera .srv-to-parhand RCE
CVE-2018-1066118 Jun 2018
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
60RISK
open
Metasploit300
Splunk __raw Server Info Disclosure
CVE-2018-1140908 Jun 2018
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json
60RISK
open
Metasploit300
Cisco ASA Directory Traversal
CVE-2018-0296HIGHunder attack06 Jun 2018
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RISK
open
Metasploit300
WebKitGTK+ WebKitFaviconDatabase DoS
CVE-2018-1164603 Jun 2018
webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFavicon
50RISK
open
Metasploit600
Quest KACE Systems Management Command Injection
CVE-2018-11138CRITICALunder attackransomware31 May 2018
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by
100RISK
open
Metasploit300
Dolibarr Gather Credentials via SQL Injection
CVE-2018-1009430 May 2018
SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vecto
60RISK
open
Metasploit600
IBM QRadar SIEM Unauthenticated Remote Code Execution
CVE-2018-1612MEDIUM28 May 2018
IBM QRadar Incident Forensics (IBM QRadar SIEM 7.2, and 7.3) could allow a remote attacker to bypass authentication and
60RISK
open
Metasploit600
IBM QRadar SIEM Unauthenticated Remote Code Execution
CVE-2018-141828 May 2018
IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM
50RISK
open
Metasploit600
IBM QRadar SIEM Unauthenticated Remote Code Execution
CVE-2016-972228 May 2018
IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be r
43RISK
open
Metasploit500
VLC Media Player MKV Use After Free
CVE-2018-1152924 May 2018
VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arb
50RISK
open
Metasploit600
Windscribe WindscribeService Named Pipe Privilege Escalation
CVE-2018-1147924 May 2018
The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe s
38RISK
open
Metasploit300
MimiPenguin
CVE-2018-2078123 May 2018
In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned f
18RISK
open
Metasploit600
DHCP Client Command Injection (DynoRoot)
CVE-2018-1111HIGH15 May 2018
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RISK
open
Metasploit400
Windows SetImeInfoEx Win32k NULL Pointer Dereference
CVE-2018-8120HIGHunder attackransomware09 May 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
Metasploit600
Microsoft Windows POP/MOV SS Local Privilege Elevation Vulnerability
CVE-2018-889708 May 2018
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RISK
open
Metasploit300
LibreOffice 6.03 /Apache OpenOffice 4.1.5 Malicious ODT File Generator
CVE-2018-1058301 May 2018
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically p
60RISK
open
Metasploit600
osCommerce Installer Unauthenticated Code Execution
CVE-2018-25114CRITICAL30 Apr 2018
osCommerce 2.3.4.1 Installer Unauthenticated Configuration File Injection PHP Code Execution
63RISK
open
Metasploit600
GitList v0.6.0 Argument Injection Vulnerability
CVE-2018-100053326 Apr 2018
klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in
40RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.