Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,900cataloged exploits
36,847CVEs with public exploitation
24,695lab-tested
24,475 exploits
Exploit-DB
Nikto 2.1.6 - CSV Injection
CVE-2018-11652locallinux18 Jun 2018
CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the S
28RISK
open
Exploit-DB
Redis-cli < 5.0 - Buffer Overflow (PoC)
CVE-2018-12326locallinux18 Jun 2018
Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution
23RISK
open
Exploit-DB
Pale Moon Browser < 27.9.3 - Use After Free (PoC)
CVE-2018-12292localwindows18 Jun 2018
A use-after-free vulnerability exists in DOMProxyHandler::EnsureExpandoObject in Pale Moon before 27.9.3.
23RISK
open
Exploit-DB
Dimofinf CMS 3.0.0 - Cross-Site Scripting
CVE-2018-12094webappsphp15 Jun 2018
Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arb
23RISK
open
Exploit-DB
OEcms 3.1 - Cross-Site Scripting
CVE-2018-12095webappsphp15 Jun 2018
A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerabil
38RISK
open
Exploit-DB
Joomla! Component Ek Rishta 2.10 - SQL Injection
CVE-2018-12254webappsphp14 Jun 2018
router.php in the Harmis Ek rishta (aka ek-rishta) 2.10 component for Joomla! allows SQL Injection via the PATH_INFO to
23RISK
open
Exploit-DB
MACCMS 10 - Cross-Site Request Forgery (Add User)
CVE-2018-12114webappsphp13 Jun 2018
Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.
23RISK
open
Exploit-DBVexDay Proof
DHCP Client - Command Injection 'DynoRoot' (Metasploit)
CVE-2018-1111HIGHremotelinux13 Jun 2018
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 10 - Child Process Restriction Mitigation Bypass
CVE-2018-0982localwindows13 Jun 2018
An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows
23RISK
open
Exploit-DB
RSLinx Classic and FactoryTalk Linx Gateway - Privilege Escalation
CVE-2018-10619localwindows13 Jun 2018
An unquoted search path or element in RSLinx Classic Versions 3.90.01 and prior and FactoryTalk Linx Gateway Versions 3.
23RISK
open
Exploit-DBVexDay Proof
glibc - 'realpath()' Privilege Escalation (Metasploit)
CVE-2018-1000001locallinux13 Jun 2018
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISK
open
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2018-5751webappsxml12 Jun 2018
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
23RISK
open
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2018-5754webappsxml12 Jun 2018
Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and
23RISK
open
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2018-5753webappsxml12 Jun 2018
The frontend component in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev
23RISK
open
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2018-5755webappsxml12 Jun 2018
Absolute path traversal vulnerability in the readerengine component in Open-Xchange OX App Suite before 7.6.3-rev3, 7.8.
23RISK
open
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2018-5756webappsxml12 Jun 2018
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
23RISK
open
Exploit-DB
Canon PrintMe EFI - Cross-Site Scripting
CVE-2018-12111webappsphp12 Jun 2018
Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitra
23RISK
open
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2018-5752webappsxml12 Jun 2018
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
23RISK
open
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2017-17062webappsxml12 Jun 2018
The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev4
23RISK
open
Exploit-DB
Schools Alert Management Script - SQL Injection
CVE-2018-12055webappsphp11 Jun 2018
Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.ph
23RISK
open
Exploit-DB
WordPress Plugin Pie Register < 3.0.9 - Blind SQL Injection
CVE-2018-10969webappsphp11 Jun 2018
SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute ar
23RISK
open
Exploit-DB
Schools Alert Management Script - Arbitrary File Read
CVE-2018-12054webappsphp11 Jun 2018
Arbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absol
50RISK
open
Exploit-DB
WebKitGTK+ < 2.21.3 - 'WebKitFaviconDatabase' Denial of Service (Metasploit)
CVE-2018-11646doslinux11 Jun 2018
webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFavicon
50RISK
open
Exploit-DB
Schools Alert Management Script - Arbitrary File Deletion
CVE-2018-12053webappsphp11 Jun 2018
Arbitrary File Deletion exists in PHP Scripts Mall Schools Alert Management Script via the img parameter in delete_img.p
28RISK
open
Exploit-DB
Schools Alert Management Script - 'get_sec.php' SQL Injection
CVE-2018-12052webappsphp11 Jun 2018
SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php.
23RISK
open
Exploit-DBVexDay Proof
WebKit - Use-After-Free when Resuming Generator
CVE-2018-4218dosmultiple08 Jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
23RISK
open
Exploit-DB
XiongMai uc-httpd 1.0.0 - Buffer Overflow
CVE-2018-10088webappshardware08 Jun 2018
Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE
50RISK
open
Exploit-DBVexDay Proof
WebRTC - VP9 Frame Processing Out-of-Bounds Memory Access
CVE-2018-6130dosmultiple08 Jun 2018
Incorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to pot
23RISK
open
Exploit-DBVexDay Proof
WebKit - WebAssembly Compilation Info Leak
CVE-2018-4222dosmultiple08 Jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
28RISK
open
Exploit-DBVexDay Proof
TrendMicro OfficeScan XG 11.0 - Change Prevention Bypass
CVE-2018-10507localwindows08 Jun 2018
A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to take a series of steps to bypass or
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.