Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,900cataloged exploits
36,847CVEs with public exploitation
24,695lab-tested
24,475 exploits
Exploit-DBVexDay Proof
Responsive FileManager < 9.13.4 - Directory Traversal
CVE-2018-15535webappsphp27 Aug 2018
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname
50RISK
open
Exploit-DBVexDay Proof
Adobe Flash - AVC Processing Out-of-Bounds Read
CVE-2018-12827doslinux27 Aug 2018
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead t
35RISK
open
Exploit-DB
RICOH MP C4504ex Printer - Cross-Site Request Forgery (Add Admin)
CVE-2018-15884webappshardware27 Aug 2018
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
23RISK
open
Exploit-DBVexDay Proof
Foxit PDF Reader 9.0.1.1049 - Pointer Overwrite Use-After-Free (Metasploit)
CVE-2018-9948localwindows27 Aug 2018
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RISK
open
Exploit-DBVexDay Proof
HP Jetdirect - Path Traversal Arbitrary Code Execution (Metasploit)
CVE-2017-2741remoteunix27 Aug 2018
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmwa
60RISK
open
Exploit-DB
ManageEngine ADManager Plus 6.5.7 - Cross-Site Scripting
CVE-2018-15740webappswindows_x86-6426 Aug 2018
Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.
23RISK
open
Exploit-DB
Apache Struts 2.3 < 2.3.34 / 2.5 < 2.5.16 - Remote Code Execution (1)
CVE-2018-11776HIGHunder attackremotelinux26 Aug 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
Exploit-DB
Apache Struts 2.3 < 2.3.34 / 2.5 < 2.5.16 - Remote Code Execution (2)
CVE-2018-11776HIGHunder attackremotemultiple25 Aug 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
Exploit-DB
ManageEngine ADManager Plus 6.5.7 - HTML Injection
CVE-2018-15608webappswindows25 Aug 2018
Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.
23RISK
open
Exploit-DB
Geutebrueck re_porter 16 - Cross-Site Scripting
CVE-2018-15533webappshardware22 Aug 2018
A reflected cross-site scripting vulnerability exists in Geutebrueck re_porter 16 before 7.8.974.20 by appending a query
23RISK
open
Exploit-DB
Geutebrueck re_porter 7.8.974.20 - Credential Disclosure
CVE-2018-15534webappshardware22 Aug 2018
Geutebrueck re_porter 16 before 7.8.974.20 has a possibility of unauthenticated access to sensitive information includin
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 10 - Diagnostics Hub Standard Collector Service Privilege Escalation
CVE-2018-0952localwindows22 Aug 2018
An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary
23RISK
open
Exploit-DBVexDay Proof
OpenSSH 2.3 < 7.7 - Username Enumeration
CVE-2018-15473MEDIUMremotelinux21 Aug 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
Exploit-DB
WordPress Plugin Tagregator 0.6 - Cross-Site Scripting
CVE-2018-10752webappsphp20 Aug 2018
The Tagregator plugin 0.6 for WordPress has stored XSS via the title field in an Add New action.
23RISK
open
Exploit-DBVexDay Proof
Easylogin Pro 1.3.0 - 'Encryptor.php' Unserialize Remote Code Execution
CVE-2018-15576remotephp20 Aug 2018
An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited
23RISK
open
Exploit-DB
SEIG Modbus 3.4 - Remote Code Execution
CVE-2013-0662remotewindows_x8620 Aug 2018
Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow
28RISK
open
Exploit-DB
SEIG Modbus 3.4 - Denial of Service (PoC)
CVE-2013-0662doswindows_x8620 Aug 2018
Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow
28RISK
open
Exploit-DB
MyBB Moderator Log Notes Plugin 1.1 - Cross-Site Request Forgery
CVE-2018-11502webappsphp20 Aug 2018
An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display t
23RISK
open
Exploit-DB
SEIG SCADA System 9 - Remote Code Execution
CVE-2013-0657remotewindows_x8619 Aug 2018
Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote
28RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - ImplicitCallFlags Check Bypass with Intl
CVE-2018-8288doswindows17 Aug 2018
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Parameter Scope Parsing Type Confusion
CVE-2018-8279doswindows17 Aug 2018
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E
45RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - 'DictionaryPropertyDescriptor::CopyFrom' Type Confusion
CVE-2018-8291doswindows17 Aug 2018
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - InitializeNumberFormat and InitializeDateTimeFormat Type Confusion
CVE-2018-8298HIGHunder attackdoswindows17 Aug 2018
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
93RISK
open
Exploit-DB
ADM 3.1.2RHG1 - Remote Code Execution
CVE-2018-11510webappshardware17 Aug 2018
The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/
35RISK
open
Exploit-DB
TP-Link WR840N 0.9.1 3.16 - Denial of Service (PoC)
CVE-2018-15172doshardware16 Aug 2018
TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header.
23RISK
open
Exploit-DB
Pimcore 5.2.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
CVE-2018-14057webappsphp16 Aug 2018
Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validati
23RISK
open
Exploit-DBVexDay Proof
OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions
CVE-2018-15142webappslinux16 Aug 2018
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
28RISK
open
Exploit-DBVexDay Proof
OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions
CVE-2018-15141webappslinux16 Aug 2018
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
28RISK
open
Exploit-DB
Pimcore 5.2.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
CVE-2018-14059webappsphp16 Aug 2018
Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick,
23RISK
open
Exploit-DB
Pimcore 5.2.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
CVE-2018-14058webappsphp16 Aug 2018
Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
43RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.