Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
22,786 exploits
Exploit-DB
phpMyAdmin 4.8.1 - (Authenticated) Local File Inclusion (2)
CVE-2018-1261322 Jun 2018
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open
Exploit-DB
QEMU Guest Agent 2.12.50 - Denial of Service
CVE-2018-1261722 Jun 2018
qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 h
28RISK
open
Exploit-DB
GreenCMS 2.3.0603 - Information Disclosure
CVE-2018-1260422 Jun 2018
GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_d
28RISK
open
Exploit-DB
Dell EMC RecoverPoint < 5.1.2 - Local Root Command Execution
CVE-2018-123521 Jun 2018
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command inje
35RISK
open
Exploit-DB
phpMyAdmin 4.8.1 - (Authenticated) Local File Inclusion (1)
CVE-2018-1261321 Jun 2018
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open
Exploit-DB
LFCMS 3.7.0 - Cross-Site Request Forgery (Add User)
CVE-2018-1260221 Jun 2018
A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily.
23RISK
open
Exploit-DB
LFCMS 3.7.0 - Cross-Site Request Forgery (Add Admin)
CVE-2018-1260321 Jun 2018
Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authen
23RISK
open
Exploit-DB
Microsoft Windows 10 - Desktop Bridge Activation Arbitrary Directory Creation Privilege Escalation
CVE-2018-820820 Jun 2018
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
23RISK
open
Exploit-DB
MaDDash 2.0.2 - Directory Listing
CVE-2018-1252420 Jun 2018
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provi
23RISK
open
Exploit-DB
Apache CouchDB < 2.1.0 - Remote Code Execution
CVE-2017-1263620 Jun 2018
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RISK
open
Exploit-DB
IPConfigure Orchid VMS 2.0.5 - Directory Traversal / Information Disclosure (Metasploit)
CVE-2018-1095620 Jun 2018
IPConfigure Orchid Core VMS 2.0.5 allows Directory Traversal.
50RISK
open
Exploit-DB
ntp 4.2.8p11 - Local Buffer Overflow (PoC)
CVE-2018-1232720 Jun 2018
Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or es
28RISK
open
Exploit-DB
Microsoft Windows 10 - Desktop Bridge Virtual Registry CVE-2018-0880 Incomplete Fix Privilege Escalation
CVE-2018-821420 Jun 2018
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
23RISK
open
Exploit-DB
Redis 5.0 - Denial of Service
CVE-2018-1245320 Jun 2018
Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers t
28RISK
open
Exploit-DB
MaDDash 2.0.2 - Directory Listing
CVE-2018-1252320 Jun 2018
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provi
23RISK
open
Exploit-DB
MaDDash 2.0.2 - Directory Listing
CVE-2018-1252220 Jun 2018
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ pro
23RISK
open
Exploit-DB
MaDDash 2.0.2 - Directory Listing
CVE-2018-1252520 Jun 2018
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ pr
23RISK
open
Exploit-DB
Redis-cli < 5.0 - Buffer Overflow (PoC)
CVE-2018-1232618 Jun 2018
Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution
23RISK
open
Exploit-DB
Microsoft COM for Windows - Privilege Escalation
CVE-2018-0824HIGHunder attack18 Jun 2018
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized
100RISK
open
Exploit-DB
Pale Moon Browser < 27.9.3 - Use After Free (PoC)
CVE-2018-1229218 Jun 2018
A use-after-free vulnerability exists in DOMProxyHandler::EnsureExpandoObject in Pale Moon before 27.9.3.
23RISK
open
Exploit-DB
Nikto 2.1.6 - CSV Injection
CVE-2018-1165218 Jun 2018
CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the S
28RISK
open
Exploit-DB
OEcms 3.1 - Cross-Site Scripting
CVE-2018-1209515 Jun 2018
A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerabil
38RISK
open
Exploit-DB
Dimofinf CMS 3.0.0 - Cross-Site Scripting
CVE-2018-1209415 Jun 2018
Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arb
23RISK
open
Exploit-DB
Joomla! Component Ek Rishta 2.10 - SQL Injection
CVE-2018-1225414 Jun 2018
router.php in the Harmis Ek rishta (aka ek-rishta) 2.10 component for Joomla! allows SQL Injection via the PATH_INFO to
23RISK
open
Exploit-DB
glibc - 'realpath()' Privilege Escalation (Metasploit)
CVE-2018-100000113 Jun 2018
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISK
open
Exploit-DB
MACCMS 10 - Cross-Site Request Forgery (Add User)
CVE-2018-1211413 Jun 2018
Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.
23RISK
open
Exploit-DB
Microsoft Windows 10 - Child Process Restriction Mitigation Bypass
CVE-2018-098213 Jun 2018
An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows
23RISK
open
Exploit-DB
DHCP Client - Command Injection 'DynoRoot' (Metasploit)
CVE-2018-1111HIGH13 Jun 2018
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RISK
open
Exploit-DB
RSLinx Classic and FactoryTalk Linx Gateway - Privilege Escalation
CVE-2018-1061913 Jun 2018
An unquoted search path or element in RSLinx Classic Versions 3.90.01 and prior and FactoryTalk Linx Gateway Versions 3.
23RISK
open
Exploit-DB
Canon PrintMe EFI - Cross-Site Scripting
CVE-2018-1211112 Jun 2018
Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitra
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.