Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
3,477 exploits
Metasploit600
Apache Tika Header Command Injection
CVE-2018-133525 Apr 2018
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISK
open
Metasploit300
Foxit PDF Reader Pointer Overwrite UAF
CVE-2018-995820 Apr 2018
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1
50RISK
open
Metasploit300
Foxit PDF Reader Pointer Overwrite UAF
CVE-2018-994820 Apr 2018
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RISK
open
Metasploit0
Oracle Weblogic Server Deserialization RCE
CVE-2018-2628CRITICALunder attack17 Apr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
Metasploit0
Nagios XI Chained Remote Code Execution
CVE-2018-873517 Apr 2018
Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execut
50RISK
open
Metasploit0
Nagios XI Chained Remote Code Execution
CVE-2018-873317 Apr 2018
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an
43RISK
open
Metasploit0
Nagios XI Chained Remote Code Execution
CVE-2018-873417 Apr 2018
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker
50RISK
open
Metasploit0
Nagios XI Chained Remote Code Execution
CVE-2018-873617 Apr 2018
A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RC
50RISK
open
Metasploit600
Pi-Hole Whitelist OS Command Execution
CVE-2025-34087CRITICAL15 Apr 2018
Pi-Hole AdminLTE Whitelist (now 'Web Allowlist') Remote Command Execution
63RISK
open
Metasploit600
H2 Web Interface Create Alias RCE
CVE-2018-1005409 Apr 2018
H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can
30RISK
open
Metasploit600
Drupal Drupalgeddon 2 Forms API Property Injection
CVE-2018-7600CRITICALunder attackransomware28 Mar 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
Metasploit600
Mac OS X libxpc MITM Privilege Escalation
CVE-2018-423715 Mar 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
43RISK
open
Metasploit0
Safari Webkit Proxy Object Type Confusion
CVE-2018-4233HIGH15 Mar 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
68RISK
open
Metasploit0
Safari Proxy Object Type Confusion
CVE-2018-4233HIGH15 Mar 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
68RISK
open
Metasploit0
Safari Webkit Proxy Object Type Confusion
CVE-2017-1386115 Mar 2018
An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. watchOS be
43RISK
open
Metasploit0
Safari Proxy Object Type Confusion
CVE-2018-4404HIGH15 Mar 2018
In iOS before 11.4 and macOS High Sierra before 10.13.5, a memory corruption issue exists and was addressed with improve
61RISK
open
Metasploit300
SAP Internet Graphics Server (IGS) XMLCHART XXE
CVE-2018-239214 Mar 2018
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML Exter
50RISK
open
Metasploit600
Unitrends Enterprise Backup bpserverd Privilege Escalation
CVE-2018-632914 Mar 2018
It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL i
50RISK
open
Metasploit300
SAP Internet Graphics Server (IGS) XMLCHART XXE
CVE-2018-239314 Mar 2018
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML Exter
23RISK
open
Metasploit300
Flexense HTTP Server Denial Of Service
CVE-2018-806509 Mar 2018
An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access v
60RISK
open
Metasploit300
HTTP SickRage Password Leak
CVE-2018-916008 Mar 2018
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
60RISK
open
Metasploit600
ManageEngine Applications Manager Remote Code Execution
CVE-2018-789007 Mar 2018
A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The pu
60RISK
open
Metasploit600
ClipBucket beats_uploader Unauthenticated Arbitrary File Upload
CVE-2018-766503 Mar 2018
An issue was discovered in ClipBucket before 4.0.0 Release 4902. A malicious file can be uploaded via the name parameter
23RISK
open
Metasploit300
Memcached Stats Amplification Scanner
CVE-2018-100011527 Feb 2018
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vuln
60RISK
open
Metasploit600
Nanopool Claymore Dual Miner APIs RCE
CVE-2018-100004909 Feb 2018
Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner
50RISK
open
Metasploit300
Claymore Dual GPU Miner Format String dos attack
CVE-2018-631706 Feb 2018
The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format strin
50RISK
open
Metasploit0
Exodus Wallet (ElectronJS Framework) remote Code Execution
CVE-2018-100000625 Jan 2018
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the pro
60RISK
open
Metasploit600
AsusWRT LAN Unauthenticated Remote Code Execution
CVE-2018-599922 Jan 2018
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, pro
60RISK
open
Metasploit600
AsusWRT LAN Unauthenticated Remote Code Execution
CVE-2018-600022 Jan 2018
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpn
60RISK
open
Metasploit500
CloudMe Sync v1.10.9
CVE-2018-689217 Jan 2018
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.