Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,900cataloged exploits
36,847CVEs with public exploitation
24,695lab-tested
24,475 exploits
Exploit-DBVexDay Proof
Linux Kernel - UDP Fragmentation Offset 'UFO' Privilege Escalation (Metasploit)
CVE-2017-1000112locallinux03 Aug 2018
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE
43RISK
open
Exploit-DB
Universal Media Server 7.1.0 - SSDP Processing XML External Entity Injection
CVE-2018-13416webappsxml02 Aug 2018
In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML Extern
28RISK
open
Exploit-DB
Sun Solaris 11.3 AVS Kernel - Local Privilege Escalation
CVE-2018-2892localsolaris02 Aug 2018
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Availability Suite Service).
23RISK
open
Exploit-DB
WityCMS 0.6.2 - Cross-Site Request Forgery (Password Change)
CVE-2018-14029webappsphp02 Aug 2018
CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an attacker to take over a user account, as dem
23RISK
open
Exploit-DB
Seq 4.2.476 - Authentication Bypass
CVE-2018-8096webappswindows02 Aug 2018
Datalust Seq before 4.2.605 is vulnerable to Authentication Bypass (with the attacker obtaining admin access) via '"Name
35RISK
open
Exploit-DB
Craft CMS SEOmatic plugin 3.1.4 - Server-Side Template Injection
CVE-2018-14716webappslinux31 Jul 2018
A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because reques
35RISK
open
Exploit-DB
Responsive Filemanager 9.13.1 - Server-Side Request Forgery
CVE-2018-14728webappslinux30 Jul 2018
upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.
60RISK
open
Exploit-DB
H2 Database 1.4.197 - Information Disclosure
CVE-2018-14335MEDIUMwebappslinux30 Jul 2018
An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read
38RISK
open
Exploit-DB
Charles Proxy 4.2 - Local Privilege Escalation
CVE-2017-15358localmacos30 Jul 2018
Race condition in the Charles Proxy Settings suid binary in Charles Proxy before 4.2.1 allows local users to gain privil
23RISK
open
Exploit-DBVexDay Proof
fusermount - user_allow_other Restriction Bypass and SELinux Label Control
CVE-2018-10906MEDIUMdoslinux30 Jul 2018
In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is act
33RISK
open
Exploit-DBVexDay Proof
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
CVE-2018-10660remotelinux27 Jul 2018
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
60RISK
open
Exploit-DBVexDay Proof
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
CVE-2018-10661remotelinux27 Jul 2018
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
60RISK
open
Exploit-DBVexDay Proof
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
CVE-2018-10662remotelinux27 Jul 2018
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
60RISK
open
Exploit-DBVexDay Proof
Skia - Heap Overflow in SkScan::FillPath due to Precision Error
CVE-2018-6126dosmultiple27 Jul 2018
A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds m
23RISK
open
Exploit-DBVexDay Proof
SoftNAS Cloud < 4.0.3 - OS Command Injection
CVE-2018-14417webappsphp27 Jul 2018
A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particul
45RISK
open
Exploit-DB
Online Trade 1 - Information Disclosure
CVE-2018-14328webappslinux27 Jul 2018
Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensiti
28RISK
open
Exploit-DB
Trivum Multiroom Setup Tool 8.76 - Corss-Site Request Forgery (Admin Bypass)
CVE-2018-13859webappshardware26 Jul 2018
MusicCenter / Trivum Multiroom Setup Tool V8.76 - SNR 8604.26 - C4 Professional before V9.34 build 13381 - 12.07.18, all
28RISK
open
Exploit-DB
GetGo Download Manager 6.2.1.3200 - Denial of Service (PoC)
CVE-2017-17849doswindows25 Jul 2018
A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to exec
28RISK
open
Exploit-DB
Nagios Core 4.4.1 - Denial of Service
CVE-2018-13457doslinux24 Jul 2018
qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to
23RISK
open
Exploit-DB
Micro Focus Secure Messaging Gateway (SMG) < 471 - Remote Code Execution (Metasploit)
CVE-2018-12464CRITICALwebappsphp24 Jul 2018
Unauthenticated SQL injection in Micro Focus Secure Messaging Gateway
85RISK
open
Exploit-DB
Nagios Core 4.4.1 - Denial of Service
CVE-2018-13441doslinux24 Jul 2018
qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows atta
23RISK
open
Exploit-DB
Nagios Core 4.4.1 - Denial of Service
CVE-2018-13458doslinux24 Jul 2018
qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to
23RISK
open
Exploit-DB
Micro Focus Secure Messaging Gateway (SMG) < 471 - Remote Code Execution (Metasploit)
CVE-2018-12465CRITICALwebappsphp24 Jul 2018
Remote Code Execution in Micro Focus Secure Messaging Gateway
85RISK
open
Exploit-DB
Tenda Wireless N150 Router 5.07.50 - Cross-Site Request Forgery (Reboot Router)
CVE-2015-5996webappshardware23 Jul 2018
Cross-site request forgery (CSRF) vulnerability on Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 allo
23RISK
open
Exploit-DB
Davolink DVW 3200 Router - Password Disclosure
CVE-2018-10618webappshardware23 Jul 2018
Davolink DVW-3200N all version prior to Version 1.00.06. The device generates a weak password hash that is easily cracke
28RISK
open
Exploit-DB
Inteno’s IOPSYS - (Authenticated) Local Privilege Escalation
CVE-2018-14533locallinux21 Jul 2018
read_tmp and write_tmp in Inteno IOPSYS allow attackers to gain privileges after writing to /tmp/etc/smb.conf because /v
23RISK
open
Exploit-DB
MSVOD 10 - 'cid' SQL Injection
CVE-2018-14418webappsphp20 Jul 2018
In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.
23RISK
open
Exploit-DB
TP-Link TL-WR840N - Denial of Service
CVE-2018-14336doshardware20 Jul 2018
TP-Link WR840N devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets w
23RISK
open
Exploit-DB
Touchpad / Trivum WebTouch Setup 2.53 build 13163 - Authentication Bypass
CVE-2018-13862webappshardware20 Jul 2018
Touchpad / Trivum WebTouch Setup V9 V2.53 build 13163 of Apr 6 2018 09:10:14 (FW 303) allow unauthorized remote attacker
35RISK
open
Exploit-DB
WordPress Plugin All In One Favicon 4.6 - (Authenticated) Cross-Site Scripting
CVE-2018-13832webappsphp19 Jul 2018
Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plu
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.