Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,900cataloged exploits
36,847CVEs with public exploitation
24,695lab-tested
24,475 exploits
Exploit-DB
XiongMai uc-httpd 1.0.0 - Buffer Overflow
CVE-2018-10088webappshardware08 Jun 2018
Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE
50RISK
open
Exploit-DB
Splunk < 7.0.1 - Information Disclosure
CVE-2018-11409webappslinux08 Jun 2018
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json
60RISK
open
Exploit-DBVexDay Proof
WebKit - WebAssembly Compilation Info Leak
CVE-2018-4222dosmultiple08 Jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
28RISK
open
Exploit-DB
Monstra CMS < 3.0.4 - Cross-Site Scripting (1)
CVE-2018-10118webappsphp07 Jun 2018
Monstra CMS 3.0.4 has Stored XSS via the Name field on the Create New Page screen under the admin/index.php?id=pages URI
23RISK
open
Exploit-DBVexDay Proof
XNU Kernel - Heap Overflow Due to Bad Bounds Checking in MPTCP
CVE-2018-4241dosmultiple06 Jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
23RISK
open
Exploit-DBVexDay Proof
Apple macOS Kernel - Use-After-Free Due to Lack of Locking in nvidia GeForce Driver
CVE-2018-4230dosmacos06 Jun 2018
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "NVIDIA Grap
23RISK
open
Exploit-DBVexDay Proof
Apple macOS/iOS Kernel - Heap Overflow Due to Lack of Lower Size Check in getvolattrlist
CVE-2018-4243dosmultiple06 Jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
28RISK
open
Exploit-DBVexDay Proof
PHP 7.2.2 - 'php_stream_url_wrap_http_ex' Buffer Overflow
CVE-2018-7584dosphp06 Jun 2018
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer
45RISK
open
Exploit-DBVexDay Proof
WebKit - not_number defineProperties UAF (Metasploit)
CVE-2016-4656HIGHunder attackremoteios05 Jun 2018
The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denia
91RISK
open
Exploit-DBVexDay Proof
WebKit - not_number defineProperties UAF (Metasploit)
CVE-2016-4655MEDIUMunder attackremoteios05 Jun 2018
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RISK
open
Exploit-DB
Linux Kernel < 4.16.11 - 'ext4_read_inline_data()' Memory Corruption
CVE-2018-11412doslinux05 Jun 2018
In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untruste
28RISK
open
Exploit-DBVexDay Proof
WebKit - not_number defineProperties UAF (Metasploit)
CVE-2016-4657HIGHunder attackremoteios05 Jun 2018
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RISK
open
Exploit-DB
WebKitGTK+ < 2.21.3 - Crash (PoC)
CVE-2018-11646locallinux05 Jun 2018
webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFavicon
50RISK
open
Exploit-DB
Jenkins Mailer Plugin < 1.20 - Cross-Site Request Forgery (Send Email)
CVE-2018-8718webappslinux05 Jun 2018
Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated
23RISK
open
Exploit-DB
Pagekit < 1.0.13 - Cross-Site Scripting Code Generator
CVE-2018-11564webappsphp05 Jun 2018
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature.
23RISK
open
Exploit-DBVexDay Proof
MyBB Recent Threads Plugin 1.0 - Cross-Site Scripting
CVE-2018-11715webappsphp05 Jun 2018
The Recent Threads plugin before 1.1 for MyBB allows XSS via a thread subject.
23RISK
open
Exploit-DB
CyberArk < 10 - Memory Disclosure
CVE-2018-9842remotelinux04 Jun 2018
CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replay
28RISK
open
Exploit-DB
EMS Master Calendar < 8.0.0.20180520 - Cross-Site Scripting
CVE-2018-11628webappsaspx04 Jun 2018
Data input into EMS Master Calendar before 8.0.0.201805210 via URL parameters is not properly sanitized, allowing malici
23RISK
open
Exploit-DB
Brother HL Series Printers 1.15 - Cross-Site Scripting
CVE-2018-11581webappshardware04 Jun 2018
Cross-site scripting (XSS) vulnerability on Brother HL series printers allows remote attackers to inject arbitrary web s
23RISK
open
Exploit-DB
SearchBlox 8.6.7 - XML External Entity Injection
CVE-2018-11586webappsjava04 Jun 2018
XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to re
28RISK
open
Exploit-DB
Zip-n-Go 4.9 - Buffer Overflow (SEH)
CVE-2018-16302localwindows04 Jun 2018
MediaComm Zip-n-Go before 4.95 has a Buffer Overflow via a crafted file.
23RISK
open
Exploit-DB
GreenCMS 2.3.0603 - Cross-Site Request Forgery (Add Admin)
CVE-2018-11671webappsphp03 Jun 2018
An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that can add an admin account via index.php
23RISK
open
Exploit-DB
GreenCMS 2.3.0603 - Cross-Site Request Forgery / Remote Code Execution
CVE-2018-11670webappsphp03 Jun 2018
An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - EntrySimpleObjectSlotGetter Type Confusion
CVE-2018-8133doswindows31 May 2018
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RISK
open
Exploit-DB
Procps-ng - Multiple Vulnerabilities
CVE-2018-1122HIGHlocallinux30 May 2018
procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset
41RISK
open
Exploit-DB
Procps-ng - Multiple Vulnerabilities
CVE-2018-1120LOWlocallinux30 May 2018
A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file onto a process's memory
28RISK
open
Exploit-DB
Procps-ng - Multiple Vulnerabilities
CVE-2018-1123LOWlocallinux30 May 2018
procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection
28RISK
open
Exploit-DB
Procps-ng - Multiple Vulnerabilities
CVE-2018-1124HIGHlocallinux30 May 2018
procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec
41RISK
open
Exploit-DB
Siemens SIMATIC S7-300 CPU - Remote Denial of Service
CVE-2015-2177HIGHdoslinux30 May 2018
Siemens SIMATIC S7-300 CPU devices allow remote attackers to cause a denial of service (defect-mode transition) via craf
53RISK
open
Exploit-DB
Yosoro 1.0.4 - Remote Code Execution
CVE-2018-11522webappsmacos30 May 2018
Yosoro 1.0.4 has stored XSS.
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.