Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,828cataloged exploits
32,132CVEs with public exploitation
1,932lab-tested
22,786 exploits
Exploit-DB
WAGO e!DISPLAY 7300T - Multiple Vulnerabilities
CVE-2018-1298013 Jul 2018
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerabilit
35RISK
open
Exploit-DB
G DATA Total Security 25.4.0.3 - Activex Buffer Overflow
CVE-2018-1001813 Jul 2018
The GDASPAMLib.AntiSpam ActiveX control ASK\GDASpam.dll in G DATA Total Security 25.4.0.3 has a buffer overflow via a lo
23RISK
open
Exploit-DB
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-070613 Jul 2018
Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticate
50RISK
open
Exploit-DB
Zeta Producer Desktop CMS 14.2.0 - Remote Code Execution / Local File Disclosure
CVE-2018-1398113 Jul 2018
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated remote code
28RISK
open
Exploit-DB
phpMyAdmin - (Authenticated) Remote Code Execution (Metasploit)
CVE-2018-1261313 Jul 2018
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open
Exploit-DB
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-070813 Jul 2018
Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allo
28RISK
open
Exploit-DB
Apache CouchDB - Arbitrary Command Execution (Metasploit)
CVE-2017-1263613 Jul 2018
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RISK
open
Exploit-DB
Cela Link CLR-M20 2.7.1.6 - Arbitrary File Upload
CVE-2018-1513713 Jul 2018
CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml)
28RISK
open
Exploit-DB
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-070713 Jul 2018
Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could
50RISK
open
Exploit-DB
Microsoft Windows - POP/MOV SS Local Privilege Elevation (Metasploit)
CVE-2018-889713 Jul 2018
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RISK
open
Exploit-DB
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-070913 Jul 2018
Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow auth
28RISK
open
Exploit-DB
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-071013 Jul 2018
Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authe
28RISK
open
Exploit-DB
Apache CouchDB - Arbitrary Command Execution (Metasploit)
CVE-2017-1263513 Jul 2018
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RISK
open
Exploit-DB
Grundig Smart Inter@ctive 3.0 - Cross-Site Request Forgery
CVE-2018-1398913 Jul 2018
Grundig Smart Inter@ctive TV 3.0 devices allow CSRF attacks via a POST request to TCP port 8085 containing a predictable
23RISK
open
Exploit-DB
WAGO e!DISPLAY 7300T - Multiple Vulnerabilities
CVE-2018-1297913 Jul 2018
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions
23RISK
open
Exploit-DB
WAGO e!DISPLAY 7300T - Multiple Vulnerabilities
CVE-2018-1298113 Jul 2018
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerabilit
23RISK
open
Exploit-DB
Zeta Producer Desktop CMS 14.2.0 - Remote Code Execution / Local File Disclosure
CVE-2018-1398013 Jul 2018
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclos
38RISK
open
Exploit-DB
Microsoft Edge Chakra JIT - Type Confusion with Hoisted SetConcatStrMultiItemBE Instructions
CVE-2018-822912 Jul 2018
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISK
open
Exploit-DB
Microsoft Edge Chakra JIT - Out-of-Bounds Reads/Writes
CVE-2018-814512 Jul 2018
An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could
35RISK
open
Exploit-DB
Microsoft Edge Chakra JIT - BoundFunction::NewInstance Out-of-Bounds Read
CVE-2018-813912 Jul 2018
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
35RISK
open
Exploit-DB
IBM QRadar SIEM - Remote Code Execution (Metasploit)
CVE-2016-972211 Jul 2018
IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be r
43RISK
open
Exploit-DB
IBM QRadar SIEM - Remote Code Execution (Metasploit)
CVE-2018-141811 Jul 2018
IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM
50RISK
open
Exploit-DB
Instagram-Clone Script 2.0 - Cross-Site Scripting
CVE-2018-1384911 Jul 2018
edit_requests.php in yTakkar Instagram-clone through 2018-04-23 has XSS via an onmouseover payload because of an inadequ
23RISK
open
Exploit-DB
JavaScript Core - Arbitrary Code Execution
CVE-2018-419211 Jul 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
28RISK
open
Exploit-DB
IBM QRadar SIEM - Remote Code Execution (Metasploit)
CVE-2018-1612MEDIUM11 Jul 2018
IBM QRadar Incident Forensics (IBM QRadar SIEM 7.2, and 7.3) could allow a remote attacker to bypass authentication and
60RISK
open
Exploit-DB
Linux Kernel < 4.13.9 (Ubuntu 16.04 / Fedora 27) - Local Privilege Escalation
CVE-2017-1699510 Jul 2018
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
Exploit-DB
Tor Browser < 0.3.2.10 - Use After Free (PoC)
CVE-2018-049109 Jul 2018
A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of se
28RISK
open
Exploit-DB
Activision Infinity Ward Call of Duty Modern Warfare 2 - Buffer Overflow
CVE-2018-1071809 Jul 2018
Stack-based buffer overflow in Activision Infinity Ward Call of Duty Modern Warfare 2 before 2018-04-26 allows remote at
35RISK
open
Exploit-DB
Oracle WebLogic 12.1.2.0 - RMI Registry UnicastRef Object Java Deserialization Remote Code Execution
CVE-2017-324807 Jul 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RISK
open
Exploit-DB
PolarisOffice 2017 8 - Remote Code Execution
CVE-2018-1258906 Jul 2018
Polaris Office 2017 8.1 allows attackers to execute arbitrary code via a Trojan horse puiframeworkproresenu.dll file in
28RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.