Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,900cataloged exploits
36,847CVEs with public exploitation
24,695lab-tested
24,475 exploits
Exploit-DBVexDay Proof
Linux - BPF Sign Extension Local Privilege Escalation (Metasploit)
CVE-2017-16995locallinux19 Jul 2018
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
Exploit-DB
MyBB New Threads Plugin 1.1 - Cross-Site Scripting
CVE-2018-14392webappsphp19 Jul 2018
The New Threads plugin before 1.2 for MyBB has XSS.
35RISK
open
Exploit-DB
Open-AudIT Community 2.1.1 - Cross-Site Scripting
CVE-2018-11124webappsmultiple18 Jul 2018
Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows
23RISK
open
Exploit-DBVexDay Proof
Nanopool Claymore Dual Miner - APIs Remote Code Execution (Metasploit)
CVE-2018-1000049remotemultiple17 Jul 2018
Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner
60RISK
open
Exploit-DBVexDay Proof
QNAP Q'Center - 'change_passwd' Command Execution (Metasploit)
CVE-2018-0706remotelinux17 Jul 2018
Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticate
50RISK
open
Exploit-DBVexDay Proof
QNAP Q'Center - 'change_passwd' Command Execution (Metasploit)
CVE-2018-0707remotelinux17 Jul 2018
Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could
50RISK
open
Exploit-DB
PrestaShop < 1.6.1.19 - 'AES CBC' Privilege Escalation
CVE-2018-13784webappsphp16 Jul 2018
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfi
28RISK
open
Exploit-DBVexDay Proof
Linux (Ubuntu) - Other Users coredumps Can Be Read via setgid Directory and killpriv Bypass
CVE-2018-13405doslinux16 Jul 2018
The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an
23RISK
open
Exploit-DB
PrestaShop < 1.6.1.19 - 'BlowFish ECD' Privilege Escalation
CVE-2018-13784webappsphp16 Jul 2018
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfi
28RISK
open
Exploit-DBVexDay Proof
Fortify Software Security Center (SSC) 17.x/18.1 - XML External Entity Injection
CVE-2018-12463HIGHwebappsjava16 Jul 2018
MFSBGN03811 rev.1 - Fortify Software Security Center (SSC), Multiple vulnerabilities
46RISK
open
Exploit-DB
VelotiSmart WiFi B-380 Camera - Directory Traversal
CVE-2018-14064webappshardware16 Jul 2018
The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../..
50RISK
open
Exploit-DBVexDay Proof
WAGO e!DISPLAY 7300T - Multiple Vulnerabilities
CVE-2018-12980webappsphp13 Jul 2018
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerabilit
35RISK
open
Exploit-DBVexDay Proof
WAGO e!DISPLAY 7300T - Multiple Vulnerabilities
CVE-2018-12979webappsphp13 Jul 2018
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions
23RISK
open
Exploit-DBVexDay Proof
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-0707webappshardware13 Jul 2018
Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could
50RISK
open
Exploit-DBVexDay Proof
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-0706webappshardware13 Jul 2018
Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticate
50RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - POP/MOV SS Local Privilege Elevation (Metasploit)
CVE-2018-8897localwindows13 Jul 2018
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RISK
open
Exploit-DB
Grundig Smart Inter@ctive 3.0 - Cross-Site Request Forgery
CVE-2018-13989webappshardware13 Jul 2018
Grundig Smart Inter@ctive TV 3.0 devices allow CSRF attacks via a POST request to TCP port 8085 containing a predictable
23RISK
open
Exploit-DB
G DATA Total Security 25.4.0.3 - Activex Buffer Overflow
CVE-2018-10018doswindows13 Jul 2018
The GDASPAMLib.AntiSpam ActiveX control ASK\GDASpam.dll in G DATA Total Security 25.4.0.3 has a buffer overflow via a lo
23RISK
open
Exploit-DBVexDay Proof
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-0709webappshardware13 Jul 2018
Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow auth
28RISK
open
Exploit-DB
Cela Link CLR-M20 2.7.1.6 - Arbitrary File Upload
CVE-2018-15137webappshardware13 Jul 2018
CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml)
28RISK
open
Exploit-DB
Zeta Producer Desktop CMS 14.2.0 - Remote Code Execution / Local File Disclosure
CVE-2018-13980webappsphp13 Jul 2018
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclos
38RISK
open
Exploit-DBVexDay Proof
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-0708webappshardware13 Jul 2018
Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allo
28RISK
open
Exploit-DB
Zeta Producer Desktop CMS 14.2.0 - Remote Code Execution / Local File Disclosure
CVE-2018-13981webappsphp13 Jul 2018
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated remote code
28RISK
open
Exploit-DBVexDay Proof
phpMyAdmin - (Authenticated) Remote Code Execution (Metasploit)
CVE-2018-12613remotephp13 Jul 2018
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open
Exploit-DBVexDay Proof
WAGO e!DISPLAY 7300T - Multiple Vulnerabilities
CVE-2018-12981webappsphp13 Jul 2018
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerabilit
23RISK
open
Exploit-DBVexDay Proof
Apache CouchDB - Arbitrary Command Execution (Metasploit)
CVE-2017-12636remotelinux13 Jul 2018
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RISK
open
Exploit-DBVexDay Proof
Apache CouchDB - Arbitrary Command Execution (Metasploit)
CVE-2017-12635remotelinux13 Jul 2018
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RISK
open
Exploit-DBVexDay Proof
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-0710webappshardware13 Jul 2018
Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authe
28RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - BoundFunction::NewInstance Out-of-Bounds Read
CVE-2018-8139doswindows12 Jul 2018
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Out-of-Bounds Reads/Writes
CVE-2018-8145doswindows12 Jul 2018
An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could
35RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.