Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,900cataloged exploits
36,847CVEs with public exploitation
24,695lab-tested
24,475 exploits
Exploit-DBVexDay Proof
Navigate CMS - (Unauthenticated) Remote Code Execution (Metasploit)
CVE-2018-17552remotephp08 Oct 2018
SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigat
60RISK
open
Exploit-DBVexDay Proof
Android - sdcardfs Changes current->fs Without Proper Locking
CVE-2018-9515dosandroid08 Oct 2018
In sdcardfs_create and sdcardfs_mkdir of inode.c, there is a possible memory corruption due to improper locking. This co
23RISK
open
Exploit-DBVexDay Proof
Zahir Enterprise Plus 6 - Stack Buffer Overflow (Metasploit)
CVE-2018-17408localwindows08 Oct 2018
Stack-based buffer overflows in Zahir Accounting Enterprise Plus 6 through build 10b allow remote attackers to execute a
43RISK
open
Exploit-DBVexDay Proof
Unitrends UEB - HTTP API Remote Code Execution (Metasploit)
CVE-2017-12478remotelinux08 Oct 2018
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of
60RISK
open
Exploit-DB
Git Submodule - Arbitrary Code Execution (PoC)
CVE-2018-17456locallinux05 Oct 2018
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RISK
open
Exploit-DBVexDay Proof
D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilities
CVE-2018-17441webappsphp05 Oct 2018
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser
23RISK
open
Exploit-DBVexDay Proof
D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilities
CVE-2018-17440webappsphp05 Oct 2018
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves b
35RISK
open
Exploit-DBVexDay Proof
D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilities
CVE-2018-17443webappsphp05 Oct 2018
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateS
23RISK
open
Exploit-DBVexDay Proof
D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilities
CVE-2018-17442webappsphp05 Oct 2018
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. An unrestricted file upload vulnerabili
28RISK
open
Exploit-DB
virtualenv 16.0.0 - Sandbox Escape
CVE-2018-17793locallinux04 Oct 2018
20RISK
open
Exploit-DB
Cisco Prime Infrastructure - (Unauthenticated) Remote Code Execution
CVE-2018-15379remotemultiple04 Oct 2018
Cisco Prime Infrastructure Arbitrary File Upload and Command Execution Vulnerability
60RISK
open
Exploit-DB
Airties AIR5342 1.0.0.18 - Cross-Site Scripting
CVE-2018-17591webappshardware03 Oct 2018
AirTies Air 5343v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
23RISK
open
Exploit-DB
Airties AIR5342 1.0.0.18 - Cross-Site Scripting
CVE-2018-17590webappshardware03 Oct 2018
AirTies Air 5442 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
23RISK
open
Exploit-DB
Airties AIR5342 1.0.0.18 - Cross-Site Scripting
CVE-2018-17587webappshardware03 Oct 2018
AirTies Air 5750 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
23RISK
open
Exploit-DB
RICOH MP C1803 JPN Printer - Cross-Site Scripting
CVE-2018-17310webappshardware03 Oct 2018
On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of add
23RISK
open
Exploit-DB
RICOH MP C1803 JPN Printer - Cross-Site Scripting
CVE-2018-17313webappshardware03 Oct 2018
On the RICOH MP C307 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding a
23RISK
open
Exploit-DB
Airties AIR5342 1.0.0.18 - Cross-Site Scripting
CVE-2018-17588webappshardware03 Oct 2018
AirTies Air 5021 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
23RISK
open
Exploit-DB
Airties AIR5342 1.0.0.18 - Cross-Site Scripting
CVE-2018-17593webappshardware03 Oct 2018
AirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
23RISK
open
Exploit-DB
OPAC EasyWeb Five 5.7 - 'biblio' SQL Injection
CVE-2018-17428webappsphp02 Oct 2018
An issue was discovered in OPAC EasyWeb Five 5.7. There is SQL injection via the w2001/index.php?scelta=campi biblio par
23RISK
open
Exploit-DB
Linux Kernel < 4.11.8 - 'mq_notify: double sock_put()' Local Privilege Escalation
CVE-2017-11176locallinux02 Oct 2018
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RISK
open
Exploit-DB
WUZHICMS 2.0 - Cross-Site Scripting
CVE-2018-17832webappsphp01 Oct 2018
XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.
23RISK
open
Exploit-DB
Zahir Enterprise Plus 6 build 10b - Buffer Overflow (SEH)
CVE-2018-17408localwindows_x8601 Oct 2018
Stack-based buffer overflows in Zahir Accounting Enterprise Plus 6 through build 10b allow remote attackers to execute a
43RISK
open
Exploit-DBVexDay Proof
PCProtect 4.8.35 - Privilege Escalation
CVE-2018-17776localwindows_x86-6428 Sep 2018
PCProtect Anti-Virus v4.8.35 has "Everyone: (F)" permission for %PROGRAMFILES(X86)%\PCProtect, which allows local users
23RISK
open
Exploit-DB
EE 4GEE Mini EE40_00_02.00_44 - Privilege Escalation
CVE-2018-14327localwindows27 Sep 2018
The installer for the Alcatel OSPREY3_MINI Modem component on EE EE40VB 4G mobile broadband modems with firmware before
23RISK
open
Exploit-DB
Rausoft ID.prove 2.95 - 'Username' SQL injection
CVE-2018-16659webappswindows_x86-6427 Sep 2018
An issue was discovered in Rausoft ID.prove 2.95. The login page allows SQL injection via Microsoft SQL Server stacked q
23RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - Sandbox Escape
CVE-2018-8463remotewindows27 Sep 2018
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppCont
28RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - Sandbox Escape
CVE-2018-8469remotewindows27 Sep 2018
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppCont
28RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - Sandbox Escape
CVE-2018-8468remotewindows27 Sep 2018
An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privil
28RISK
open
Exploit-DB
Linux Kernel 2.6.x / 3.10.x / 4.14.x (RedHat / Debian / CentOS) (x64) - 'Mutagen Astronomy' Local Privilege Escalation
CVE-2018-14634HIGHunder attacklocallinux_x86-6426 Sep 2018
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with a
76RISK
open
Exploit-DBVexDay Proof
Linux Kernel - VMA Use-After-Free via Buggy vmacache_flush_all() Fastpath Local Privilege Escalation
CVE-2018-17182locallinux26 Sep 2018
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.