Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,900cataloged exploits
36,847CVEs with public exploitation
24,695lab-tested
24,475 exploits
Exploit-DBVexDay Proof
Wireshark - 'find_signature' Heap Out-of-Bounds Read
CVE-2018-19627dosmultiple04 Dec 2018
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/v
28RISK
open
Exploit-DB
Xorg X11 Server (AIX) - Local Privilege Escalation
CVE-2018-14665localaix04 Dec 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RISK
open
Exploit-DB
NEC Univerge Sv9100 WebPro - 6.00 - Predictable Session ID / Clear Text Password Storage
CVE-2018-11741webappshardware04 Dec 2018
NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure vi
28RISK
open
Exploit-DBVexDay Proof
HP Intelligent Management - Java Deserialization Remote Code Execution (Metasploit)
CVE-2017-12557remotewindows04 Dec 2018
A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and e
60RISK
open
Exploit-DB
DomainMOD 4.11.01 - Custom Domain Fields Cross-Site Scripting
CVE-2018-19750webappsphp04 Dec 2018
DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Doma
23RISK
open
Exploit-DB
DomainMOD 4.11.01 - Owner name Field Cross-Site Scripting
CVE-2018-19749webappsphp04 Dec 2018
DomainMOD through 4.11.01 has XSS via the assets/add/account-owner.php Owner name field.
38RISK
open
Exploit-DB
DomainMOD 4.11.01 - Custom SSL Fields Cross-Site Scripting
CVE-2018-19751webappsphp04 Dec 2018
DomainMOD through 4.11.01 has XSS via the admin/ssl-fields/add.php notes field for Custom SSL Fields.
38RISK
open
Exploit-DB
NUUO NVRMini2 3.9.1 - (Authenticated) Command Injection
CVE-2018-15716webappsphp04 Dec 2018
NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted reques
28RISK
open
Exploit-DBVexDay Proof
Microsoft Lync for Mac 2011 - Injection Forced Browsing/Download
CVE-2018-8474doswindows04 Dec 2018
A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messa
35RISK
open
Exploit-DB
NEC Univerge Sv9100 WebPro - 6.00 - Predictable Session ID / Clear Text Password Storage
CVE-2018-11742webappshardware04 Dec 2018
NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.
28RISK
open
Exploit-DB
CyberArk 9.7 - Memory Disclosure
CVE-2018-9842remotewindows03 Dec 2018
CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replay
28RISK
open
Exploit-DB
Apache Superset < 0.23 - Remote Code Execution
CVE-2018-8021webappslinux03 Dec 2018
Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to pos
35RISK
open
Exploit-DBVexDay Proof
VBScript - 'rtFilter' Out-of-Bounds Read
CVE-2018-8552doswindows30 Nov 2018
An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which coul
35RISK
open
Exploit-DB
xorg-x11-server < 1.20.3 - 'modulepath' Local Privilege Escalation
CVE-2018-14665localmultiple30 Nov 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RISK
open
Exploit-DBVexDay Proof
VBScript - 'OLEAUT32!VariantClear' and 'scrrun!VBADictionary::put_Item' Use-After-Free
CVE-2018-8544doswindows30 Nov 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
35RISK
open
Exploit-DB
Schneider Electric PLC - Session Calculation Authentication Bypass
CVE-2017-6026webappshardware30 Nov 2018
A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware ver
35RISK
open
Exploit-DB
PhpSpreadsheet < 1.5.0 - XML External Entity (XXE)
CVE-2018-19277webappsphp30 Nov 2018
securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 enco
23RISK
open
Exploit-DBVexDay Proof
Mac OS X - libxpc MITM Privilege Escalation (Metasploit)
CVE-2018-4237localmacos29 Nov 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
43RISK
open
Exploit-DBVexDay Proof
WebKit JSC JIT - 'JSPropertyNameEnumerator' Type Confusion
CVE-2018-4416dosmultiple29 Nov 2018
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
35RISK
open
Exploit-DBVexDay Proof
WebKit JSC - BytecodeGenerator::hoistSloppyModeFunctionIfNecessary Does not Invalidate the 'ForInContext' Object
CVE-2018-4386dosmultiple29 Nov 2018
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RISK
open
Exploit-DBVexDay Proof
WebKit JIT - 'ByteCodeParser::handleIntrinsicCall' Type Confusion
CVE-2018-4382dosmultiple29 Nov 2018
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RISK
open
Exploit-DBVexDay Proof
Linux - Nested User Namespace idmap Limit Local Privilege Escalation (Metasploit)
CVE-2018-18955locallinux29 Nov 2018
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISK
open
Exploit-DBVexDay Proof
Unitrends Enterprise Backup - bpserverd Privilege Escalation (Metasploit)
CVE-2018-6329locallinux29 Nov 2018
It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL i
50RISK
open
Exploit-DBVexDay Proof
PHP imap_open - Remote Code Execution (Metasploit)
CVE-2018-19518remotelinux29 Nov 2018
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh c
60RISK
open
Exploit-DBVexDay Proof
Netgear Devices - (Unauthenticated) Remote Command Execution (Metasploit)
CVE-2016-1555CRITICALunder attackremotehardware27 Nov 2018
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear
100RISK
open
Exploit-DB
Ticketly 1.0 - 'kind_id' SQL Injection
CVE-2018-18923webappsphp26 Nov 2018
AbiSoft Ticketly 1.0 is affected by multiple SQL Injection vulnerabilities through the parameters name, category_id and
23RISK
open
Exploit-DBVexDay Proof
Xorg X11 Server - SUID privilege escalation (Metasploit)
CVE-2018-14665localmultiple26 Nov 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RISK
open
Exploit-DB
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (ldpreload Method)
CVE-2018-18955locallinux21 Nov 2018
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISK
open
Exploit-DB
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (cron Method)
CVE-2018-18955locallinux21 Nov 2018
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - DfMarshal Unsafe Unmarshaling Privilege Escalation
CVE-2018-8550localwindows20 Nov 2018
An elevation of privilege exists in Windows COM Aggregate Marshaler, aka "Windows COM Elevation of Privilege Vulnerabili
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.