Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,900cataloged exploits
36,847CVEs with public exploitation
24,695lab-tested
24,475 exploits
Exploit-DB
Royal TS/X - Information Disclosure
CVE-2018-18865webappsjson05 Nov 2018
The Royal browser extensions TS before 4.3.60728 (Release Date 2018-07-28) and TSX before 3.3.1 (Release Date 2018-09-13
23RISK
open
Exploit-DB
Advantech WebAccess SCADA 8.3.2 - Remote Code Execution
CVE-2018-15707webappsasp05 Nov 2018
Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could
23RISK
open
Exploit-DB
Advantech WebAccess SCADA 8.3.2 - Remote Code Execution
CVE-2018-15705webappsasp05 Nov 2018
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any f
28RISK
open
Exploit-DB
LiquidVPN 1.36 / 1.37 - Privilege Escalation
CVE-2018-18859localmacos05 Nov 2018
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RISK
open
Exploit-DB
PHP Proxy 3.0.3 - Local File Inclusion
CVE-2018-19458webappsphp05 Nov 2018
In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI UR
50RISK
open
Exploit-DB
LiquidVPN 1.36 / 1.37 - Privilege Escalation
CVE-2018-18857localmacos05 Nov 2018
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RISK
open
Exploit-DB
Intel (Skylake / Kaby Lake) - 'PortSmash' CPU SMT Side-Channel
CVE-2018-5407localhardware02 Nov 2018
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks
23RISK
open
Exploit-DB
Microstrategy Web 7 - Cross-Site Scripting / Directory Traversal
CVE-2018-18777webappsjsp30 Oct 2018
Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subp
43RISK
open
Exploit-DB
Microstrategy Web 7 - Cross-Site Scripting / Directory Traversal
CVE-2018-18775webappsjsp30 Oct 2018
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (
38RISK
open
Exploit-DB
Microstrategy Web 7 - Cross-Site Scripting / Directory Traversal
CVE-2018-18776webappsjsp30 Oct 2018
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (
23RISK
open
Exploit-DB
xorg-x11-server 1.20.3 - Privilege Escalation
CVE-2018-14665localopenbsd30 Oct 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RISK
open
Exploit-DB
School Event Management System 1.0 - SQL Injection
CVE-2018-18795webappsphp29 Oct 2018
School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter.
23RISK
open
Exploit-DB
K-iwi Framework 1775 - SQL Injection
CVE-2018-18755webappsphp29 Oct 2018
K-iwi Framework 1775 has SQL Injection via the admin/user/group/update user_group_id parameter or the admin/user/user/up
23RISK
open
Exploit-DB
Bakeshop Inventory System in VB.Net and MS Access Database 1.0 - SQL Injection
CVE-2018-18804webappsphp29 Oct 2018
Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb.
23RISK
open
Exploit-DBVexDay Proof
systemd - 'chown_one()' Dereference Symlinks
CVE-2018-15687HIGHlocallinux29 Oct 2018
systemd: chown_one() can dereference symlinks
41RISK
open
Exploit-DB
Modbus Slave 7.0.0 - Denial of Service (PoC)
CVE-2018-18759doswindows29 Oct 2018
Modbus Slave 7.0.0 in modbus tools has a Buffer Overflow.
23RISK
open
Exploit-DB
SaltOS Erp Crm 3.1 r8126 - SQL Injection (2)
CVE-2018-18763webappsphp29 Oct 2018
SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection.
23RISK
open
Exploit-DB
SaltOS Erp Crm 3.1 r8126 - Database File Download
CVE-2018-18762webappsphp29 Oct 2018
SaltOS 3.1 r8126 contains a database download vulnerability.
23RISK
open
Exploit-DB
SaltOS Erp Crm 3.1 r8126 - SQL Injection
CVE-2018-18761webappsphp29 Oct 2018
SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection.
28RISK
open
Exploit-DB
RhinOS CMS 3.x - Arbitrary File Download
CVE-2018-18760webappsphp29 Oct 2018
RhinOS 3.0 build 1190 allows CSRF.
23RISK
open
Exploit-DB
School Event Management System 1.0 - Arbitrary File Upload
CVE-2018-18793webappsphp29 Oct 2018
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
23RISK
open
Exploit-DB
School Event Management System 1.0 - Cross-Site Request Forgery (Update Admin)
CVE-2018-18794webappsphp29 Oct 2018
School Event Management System 1.0 allows CSRF via user/controller.php?action=edit.
23RISK
open
Exploit-DB
School Attendance Monitoring System 1.0 - Cross-Site Request Forgery (Update Admin)
CVE-2018-18797webappsphp29 Oct 2018
School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php.
23RISK
open
Exploit-DB
School Attendance Monitoring System 1.0 - Arbitrary File Upload
CVE-2018-18799webappsphp29 Oct 2018
School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos.
23RISK
open
Exploit-DB
PayPal-Credit Card-Debit Card Payment 1.0 - SQL Injection
CVE-2018-18800webappsphp29 Oct 2018
The Tubigan "Welcome to our Resort" 1.0 software allows SQL Injection via index.php?p=accomodation&q=[SQL], index.php?p=
23RISK
open
Exploit-DB
E-Negosyo System 1.0 - SQL Injection
CVE-2018-18801webappsphp29 Oct 2018
The BSEN Ordering software 1.0 has SQL Injection via student/index.php?view=view&id=[SQL] or index.php?q=single-item&id=
23RISK
open
Exploit-DB
Curriculum Evaluation System 1.0 - SQL Injection
CVE-2018-18803webappsphp29 Oct 2018
Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb
23RISK
open
Exploit-DB
ASRock Drivers - Privilege Escalation
CVE-2018-10710doswindows29 Oct 2018
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Str
23RISK
open
Exploit-DB
ASRock Drivers - Privilege Escalation
CVE-2018-10712doswindows29 Oct 2018
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Str
23RISK
open
Exploit-DB
ASRock Drivers - Privilege Escalation
CVE-2018-10711doswindows29 Oct 2018
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Str
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.