Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
3,477 exploits
Metasploit300
glibc 'realpath()' Privilege Escalation
CVE-2018-100000116 Jan 2018
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISK
open
Metasploit300
GitStack Unauthenticated REST API Requests
CVE-2018-595515 Jan 2018
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau
60RISK
open
Metasploit500
GitStack Unsanitized Argument RCE
CVE-2018-595515 Jan 2018
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau
60RISK
open
Metasploit600
Cambium ePMP1000 'get_chart' Shell via Command Injection (v3.1-3.5-RC7)
CVE-2017-525518 Dec 2017
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web
60RISK
open
Metasploit600
Monstra CMS Authenticated Arbitrary File Upload
CVE-2017-1804818 Dec 2017
Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for exa
30RISK
open
Metasploit600
GoAhead Web Server LD_PRELOAD Arbitrary Module Load
CVE-2017-17562HIGHunder attack18 Dec 2017
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RISK
open
Metasploit600
Linksys WVBR0-25 User-Agent Command Execution
CVE-2017-1741113 Dec 2017
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authe
60RISK
open
Metasploit400
Commvault Communications Service (cvd) Command Injection
CVE-2017-1804412 Dec 2017
A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain mess
30RISK
open
Metasploit600
Apache Spark Unauthenticated Command Execution
CVE-2018-1177012 Dec 2017
From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the su
50RISK
open
Metasploit600
Palo Alto Networks readSessionVarsFromFile() Session Corruption
CVE-2017-15944CRITICALunder attack11 Dec 2017
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RISK
open
Metasploit600
Mac OS X Root Privilege Escalation
CVE-2017-1387229 Nov 2017
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The is
50RISK
open
Metasploit300
Clickjacking Vulnerability In CSRF Error Page pfSense
CVE-2017-100047921 Nov 2017
pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged e
30RISK
open
Metasploit0
Microsoft Office CVE-2017-11882
CVE-2017-11882HIGHunder attackransomware15 Nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
Metasploit500
Dup Scout Enterprise Login Buffer Overflow
CVE-2017-1369614 Nov 2017
A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9
40RISK
open
Metasploit600
Polycom Shell HDX Series Traceroute Command Execution
CVE-2025-34093HIGH12 Nov 2017
Polycom HDX Series Telnet Command Injection via lan traceroute
36RISK
open
Metasploit500
Linux BPF Sign Extension Local Privilege Escalation
CVE-2017-1699512 Nov 2017
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
Metasploit300
Roundcube TimeZone Authenticated File Disclosure
CVE-2017-16651HIGHunder attack09 Nov 2017
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary file
98RISK
open
Metasploit300
Samsung Internet Browser SOP Bypass
CVE-2017-1769208 Nov 2017
Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive informat
60RISK
open
Metasploit600
Synology DiskStation Manager smart.cgi Remote Command Execution
CVE-2017-1588908 Nov 2017
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authe
60RISK
open
Metasploit600
pfSense authenticated group member RCE
CVE-2016-1070906 Nov 2017
pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_
30RISK
open
Metasploit400
Advantech WebAccess Webvrpcs Service Opcode 80061 Stack Buffer Overflow
CVE-2017-1401602 Nov 2017
A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The applicati
43RISK
open
Metasploit300
Brother Debut http Denial Of Service
CVE-2017-1624902 Nov 2017
The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST requ
50RISK
open
Metasploit600
Xplico Remote Code Execution
CVE-2017-1666629 Oct 2017
Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name
60RISK
open
Metasploit600
Tuleap 9.6 Second-Order PHP Object Injection
CVE-2017-741123 Oct 2017
An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentEl
50RISK
open
Metasploit300
Ayukov NFTP FTP Client Buffer Overflow
CVE-2017-1522221 Oct 2017
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
50RISK
open
Metasploit600
Oracle WebLogic wls-wsat Component Deserialization RCE
CVE-2017-10271HIGHunder attackransomware19 Oct 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
Metasploit300
Easy Chat Server User Registeration Buffer Overflow (SEH)
CVE-2017-954409 Oct 2017
There is a remote stack-based buffer overflow (SEH) in register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1
23RISK
open
Metasploit600
Trend Micro InterScan Messaging Security (Virtual Appliance) Remote Code Execution
CVE-2017-1139207 Oct 2017
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote att
30RISK
open
Metasploit600
Trend Micro InterScan Messaging Security (Virtual Appliance) Remote Code Execution
CVE-2017-1139107 Oct 2017
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote att
30RISK
open
Metasploit600
Trend Micro InterScan Messaging Security (Virtual Appliance) Remote Code Execution
CVE-2017-789607 Oct 2017
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 before CP 1644 has XSS.
18RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.