Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,760cataloged exploits
32,083CVEs with public exploitation
1,932lab-tested
22,786 exploits
Exploit-DB
Jorani Leave Management 0.6.5 - (Authenticated) 'startdate' SQL Injection
CVE-2018-1591806 Sep 2018
An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permission
23RISK
open
Exploit-DB
Apache Roller 5.0.3 - XML External Entity Injection (File Disclosure)
CVE-2014-003006 Sep 2018
The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks
28RISK
open
Exploit-DB
Jorani Leave Management 0.6.5 - Cross-Site Scripting
CVE-2018-1591706 Sep 2018
Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HT
38RISK
open
Exploit-DB
Cisco Umbrella Roaming Client 2.0.168 - Local Privilege Escalation
CVE-2018-043806 Sep 2018
Cisco Umbrella Enterprise Roaming Client Privilege Escalation Vulnerability
23RISK
open
Exploit-DB
Cisco Umbrella Roaming Client 2.0.168 - Local Privilege Escalation
CVE-2018-043706 Sep 2018
Cisco Umbrella Enterprise Roaming Client and Enterprise Roaming Module Privilege Escalation Vulnerability
23RISK
open
Exploit-DB
WirelessHART Fieldgate SWG70 3.0 - Directory Traversal
CVE-2018-1605906 Sep 2018
Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename par
43RISK
open
Exploit-DB
Tenda ADSL Router D152 - Cross-Site Scripting
CVE-2018-1449705 Sep 2018
Tenda D152 ADSL routers allow XSS via a crafted SSID.
23RISK
open
Exploit-DB
FsPro Labs Event Log Explorer v4.6.1.2115 - XML External Entity Injection
CVE-2018-1625203 Sep 2018
FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.
23RISK
open
Exploit-DB
D-Link DIR-615 - Denial of Service (PoC)
CVE-2018-1583903 Sep 2018
D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header.
35RISK
open
Exploit-DB
Network Manager VPNC 1.2.6 - 'Username' Local Privilege Escalation (Metasploit)
CVE-2018-10900HIGH31 Aug 2018
Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attac
56RISK
open
Exploit-DB
DamiCMS 6.0.0 - Cross-Site Request Forgery (Change Admin Password)
CVE-2018-1584431 Aug 2018
An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's pas
23RISK
open
Exploit-DB
Cybrotech CyBroHttpServer 1.0.3 - Cross-Site Scripting
CVE-2018-1613430 Aug 2018
Cybrotech CyBroHttpServer 1.0.3 allows XSS via a URI.
23RISK
open
Exploit-DB
DLink DIR-601 - Credential Disclosure
CVE-2018-1271030 Aug 2018
An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (whi
45RISK
open
Exploit-DB
Cybrotech CyBroHttpServer 1.0.3 - Directory Traversal
CVE-2018-1613330 Aug 2018
Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.
50RISK
open
Exploit-DB
Argus Surveillance DVR 4.0.0.0 - Directory Traversal
CVE-2018-1574529 Aug 2018
Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F
60RISK
open
Exploit-DB
phpMyAdmin 4.7.x - Cross-Site Request Forgery
CVE-2017-100049929 Aug 2018
phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a
23RISK
open
Exploit-DB
Microsoft Windows - JScript RegExp.lastIndex Use-After-Free
CVE-2018-835328 Aug 2018
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
35RISK
open
Exploit-DB
Adobe Flash - AVC Processing Out-of-Bounds Read
CVE-2018-1282727 Aug 2018
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead t
35RISK
open
Exploit-DB
HP Jetdirect - Path Traversal Arbitrary Code Execution (Metasploit)
CVE-2017-274127 Aug 2018
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmwa
60RISK
open
Exploit-DB
Foxit PDF Reader 9.0.1.1049 - Pointer Overwrite Use-After-Free (Metasploit)
CVE-2018-995827 Aug 2018
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1
50RISK
open
Exploit-DB
Electron WebPreferences - Remote Code Execution
CVE-2018-1568527 Aug 2018
GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindow
28RISK
open
Exploit-DB
Responsive FileManager < 9.13.4 - Directory Traversal
CVE-2018-1553627 Aug 2018
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in arc
23RISK
open
Exploit-DB
Foxit PDF Reader 9.0.1.1049 - Pointer Overwrite Use-After-Free (Metasploit)
CVE-2018-994827 Aug 2018
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RISK
open
Exploit-DB
WordPress Plugin Plainview Activity Monitor 20161228 - (Authenticated) Command Injection
CVE-2018-1587727 Aug 2018
The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell meta
60RISK
open
Exploit-DB
Responsive FileManager < 9.13.4 - Directory Traversal
CVE-2018-1553527 Aug 2018
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname
50RISK
open
Exploit-DB
RICOH MP C4504ex Printer - Cross-Site Request Forgery (Add Admin)
CVE-2018-1588427 Aug 2018
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
23RISK
open
Exploit-DB
Gleez CMS 1.2.0 - Cross-Site Request Forgery (Add Admin)
CVE-2018-1584527 Aug 2018
There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add.
23RISK
open
Exploit-DB
Apache Struts 2.3 < 2.3.34 / 2.5 < 2.5.16 - Remote Code Execution (1)
CVE-2018-11776HIGHunder attack26 Aug 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
Exploit-DB
ManageEngine ADManager Plus 6.5.7 - Cross-Site Scripting
CVE-2018-1574026 Aug 2018
Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.
23RISK
open
Exploit-DB
ManageEngine ADManager Plus 6.5.7 - HTML Injection
CVE-2018-1560825 Aug 2018
Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.