Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,900cataloged exploits
36,847CVEs with public exploitation
24,695lab-tested
24,475 exploits
Exploit-DBVexDay Proof
Joomla! Component Raffle Factory 3.5.2 - SQL Injection
CVE-2018-17379webappsphp25 Sep 2018
SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order paramete
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::InlineTextBox::paint' Out-of-Bounds Read
CVE-2018-4328dosmultiple25 Sep 2018
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::AXObjectCache::handleMenuItemSelected' Use-After-Free
CVE-2018-4312dosmultiple25 Sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::SVGTRefElement::updateReferencedText' Use-After-Free
CVE-2018-4315dosmultiple25 Sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISK
open
Exploit-DB
Joomla! Component Collection Factory 4.1.9 - SQL Injection
CVE-2018-17383webappsphp25 Sep 2018
SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir para
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Jobs Factory 2.0.4 - SQL Injection
CVE-2018-17382webappsphp25 Sep 2018
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
23RISK
open
Exploit-DB
Joomla! Component Timetable Schedule 3.6.8 - SQL Injection
CVE-2018-17394webappsphp25 Sep 2018
SQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter.
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::RenderTreeBuilder::removeAnonymousWrappersForInlineChildrenIfNeeded' Use-After-Free
CVE-2018-4197dosmultiple25 Sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::RenderLayer::updateDescendantDependentFlags' Use-After-Free
CVE-2018-4317dosmultiple25 Sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISK
open
Exploit-DB
Joomla! Component Questions 1.4.3 - SQL Injection
CVE-2018-17377webappsphp25 Sep 2018
SQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter.
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::Node::ensureRareData' Use-After-Free
CVE-2018-4306dosmultiple25 Sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::SVGTextLayoutAttributes::context' Use-After-Free
CVE-2018-4318dosmultiple25 Sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Social Factory 3.8.3 - SQL Injection
CVE-2018-17385webappsphp25 Sep 2018
SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radiu
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Music Collection 3.0.3 - SQL Injection
CVE-2018-17375webappsphp25 Sep 2018
SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter.
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::RenderMultiColumnSet::updateMinimumColumnHeight' Use-After-Free
CVE-2018-4323dosmultiple25 Sep 2018
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Swap Factory 2.2.1 - SQL Injection
CVE-2018-17384webappsphp25 Sep 2018
SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.
23RISK
open
Exploit-DBVexDay Proof
Solaris - 'EXTREMEPARR' dtappgather Privilege Escalation (Metasploit)
CVE-2017-3622localsolaris25 Sep 2018
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Common Desktop Environment (C
38RISK
open
Exploit-DBVexDay Proof
Joomla! Component Article Factory Manager 4.3.9 - SQL Injection
CVE-2018-17380webappsphp25 Sep 2018
SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_e
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Reverse Auction Factory 4.3.8 - SQL Injection
CVE-2018-17376webappsphp25 Sep 2018
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter
23RISK
open
Exploit-DB
Joomla! Component AlphaIndex Dictionaries 1.0 - SQL Injection
CVE-2018-17397webappsphp25 Sep 2018
SQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter.
23RISK
open
Exploit-DBVexDay Proof
Super Cms Blog Pro 1.0 - SQL Injection
CVE-2018-17391webappsphp25 Sep 2018
SQL Injection exists in authors_post.php in Super Cms Blog Pro 1.0 via the author parameter.
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Penny Auction Factory 2.0.4 - SQL Injection
CVE-2018-17378webappsphp25 Sep 2018
SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order p
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::SVGAnimateElementBase::resetAnimatedType' Use-After-Free
CVE-2018-4314dosmultiple25 Sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
28RISK
open
Exploit-DB
LG SuperSign EZ CMS 2.5 - Remote Code Execution
CVE-2018-17173webappshardware24 Sep 2018
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getT
50RISK
open
Exploit-DB
Joomla! Component CW Article Attachments 1.0.6 - 'id' SQL Injection
CVE-2018-14592webappsphp24 Sep 2018
The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 fo
23RISK
open
Exploit-DB
MyBB Visual Editor 1.8.18 - Cross-Site Scripting
CVE-2018-17128webappsphp24 Sep 2018
A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.
45RISK
open
Exploit-DB
Navigate CMS 2.8 - Cross-Site Scripting
CVE-2018-17255webappsphp24 Sep 2018
20RISK
open
Exploit-DBVexDay Proof
WebRTC - FEC Out-of-Bounds Read
CVE-2018-16083dosmultiple21 Sep 2018
An out of bounds read in forward error correction code in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote
23RISK
open
Exploit-DBVexDay Proof
WebRTC - VP9 Processing Use-After-Free
CVE-2018-16071dosmultiple21 Sep 2018
A use after free in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Double Dereference in NtEnumerateKey Elevation of Privilege
CVE-2018-8410doswindows19 Sep 2018
An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.