Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,760cataloged exploits
32,083CVEs with public exploitation
1,932lab-tested
22,786 exploits
Exploit-DB
Apache Struts 2.3 < 2.3.34 / 2.5 < 2.5.16 - Remote Code Execution (2)
CVE-2018-11776HIGHunder attack25 Aug 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
Exploit-DB
Geutebrueck re_porter 16 - Cross-Site Scripting
CVE-2018-1553322 Aug 2018
A reflected cross-site scripting vulnerability exists in Geutebrueck re_porter 16 before 7.8.974.20 by appending a query
23RISK
open
Exploit-DB
Microsoft Windows 10 - Diagnostics Hub Standard Collector Service Privilege Escalation
CVE-2018-095222 Aug 2018
An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary
23RISK
open
Exploit-DB
Geutebrueck re_porter 7.8.974.20 - Credential Disclosure
CVE-2018-1553422 Aug 2018
Geutebrueck re_porter 16 before 7.8.974.20 has a possibility of unauthenticated access to sensitive information includin
35RISK
open
Exploit-DB
OpenSSH 2.3 < 7.7 - Username Enumeration
CVE-2018-15473MEDIUM21 Aug 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
Exploit-DB
WordPress Plugin Tagregator 0.6 - Cross-Site Scripting
CVE-2018-1075220 Aug 2018
The Tagregator plugin 0.6 for WordPress has stored XSS via the title field in an Add New action.
23RISK
open
Exploit-DB
MyBB Moderator Log Notes Plugin 1.1 - Cross-Site Request Forgery
CVE-2018-1150220 Aug 2018
An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display t
23RISK
open
Exploit-DB
SEIG Modbus 3.4 - Denial of Service (PoC)
CVE-2013-066220 Aug 2018
Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow
28RISK
open
Exploit-DB
SEIG Modbus 3.4 - Remote Code Execution
CVE-2013-066220 Aug 2018
Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow
28RISK
open
Exploit-DB
Easylogin Pro 1.3.0 - 'Encryptor.php' Unserialize Remote Code Execution
CVE-2018-1557620 Aug 2018
An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited
23RISK
open
Exploit-DB
SEIG SCADA System 9 - Remote Code Execution
CVE-2013-065719 Aug 2018
Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote
28RISK
open
Exploit-DB
Microsoft Edge Chakra JIT - Parameter Scope Parsing Type Confusion
CVE-2018-827917 Aug 2018
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E
45RISK
open
Exploit-DB
Microsoft Edge Chakra JIT - 'DictionaryPropertyDescriptor::CopyFrom' Type Confusion
CVE-2018-829117 Aug 2018
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
45RISK
open
Exploit-DB
Microsoft Edge Chakra JIT - ImplicitCallFlags Check Bypass with Intl
CVE-2018-828817 Aug 2018
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
45RISK
open
Exploit-DB
Microsoft Edge Chakra JIT - InitializeNumberFormat and InitializeDateTimeFormat Type Confusion
CVE-2018-8298HIGHunder attack17 Aug 2018
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
93RISK
open
Exploit-DB
ADM 3.1.2RHG1 - Remote Code Execution
CVE-2018-1151017 Aug 2018
The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/
35RISK
open
Exploit-DB
OpenSSH 2.3 < 7.7 - Username Enumeration (PoC)
CVE-2018-15473MEDIUM16 Aug 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
Exploit-DB
TP-Link WR840N 0.9.1 3.16 - Denial of Service (PoC)
CVE-2018-1517216 Aug 2018
TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header.
23RISK
open
Exploit-DB
OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions
CVE-2018-1514116 Aug 2018
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
28RISK
open
Exploit-DB
WebkitGTK+ 2.20.3 - 'ImageBufferCairo::getImageData()' Buffer Overflow (PoC)
CVE-2018-1229316 Aug 2018
The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKi
28RISK
open
Exploit-DB
Pimcore 5.2.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
CVE-2018-1405816 Aug 2018
Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
43RISK
open
Exploit-DB
OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions
CVE-2018-1514216 Aug 2018
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
28RISK
open
Exploit-DB
Pimcore 5.2.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
CVE-2018-1405716 Aug 2018
Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validati
23RISK
open
Exploit-DB
OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions
CVE-2018-1514016 Aug 2018
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
28RISK
open
Exploit-DB
Pimcore 5.2.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
CVE-2018-1405916 Aug 2018
Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick,
23RISK
open
Exploit-DB
ASUSTOR ADM 3.1.0.RFQ3 - Remote Command Execution / SQL Injection
CVE-2018-1150915 Aug 2018
ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applicat
28RISK
open
Exploit-DB
JioFi 4G M2S 1.0.2 - Denial of Service (PoC)
CVE-2018-1518115 Aug 2018
JioFi 4G Hotspot M2S devices allow attackers to cause a denial of service (secure configuration outage) via an XSS paylo
23RISK
open
Exploit-DB
ASUSTOR ADM 3.1.0.RFQ3 - Remote Command Execution / SQL Injection
CVE-2018-1151015 Aug 2018
The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/
35RISK
open
Exploit-DB
ASUSTOR ADM 3.1.0.RFQ3 - Remote Command Execution / SQL Injection
CVE-2018-1151115 Aug 2018
The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability
43RISK
open
Exploit-DB
Cloudme 1.9 - Buffer Overflow (DEP) (Metasploit)
CVE-2018-689214 Aug 2018
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.