Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
22,786 exploits
Exploit-DB
Ncomputing vSpace Pro 10/11 - Directory Traversal
CVE-2018-1020123 Apr 2018
An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11. It is possible t
50RISK
open
Exploit-DB
Monstra cms 3.0.4 - Persitent Cross-Site Scripting
CVE-2018-1010923 Apr 2018
Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload
23RISK
open
Exploit-DB
Drupal avatar_uploader v7.x-1.0-beta8 - Arbitrary File Disclosure
CVE-2018-920523 Apr 2018
Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.
50RISK
open
Exploit-DB
PRTG Network Monitor < 18.1.39.1648 - Stack Overflow (Denial of Service)
CVE-2018-1025323 Apr 2018
Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.
23RISK
open
Exploit-DB
Oracle Weblogic Server 10.3.6.0 / 12.1.3.0 / 12.2.1.2 / 12.2.1.3 - Deserialization Remote Command Execution
CVE-2018-2628CRITICALunder attack22 Apr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
Exploit-DB
Cobub Razor 0.8.0 - Physical Path Leakage
CVE-2018-877020 Apr 2018
Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, contro
50RISK
open
Exploit-DB
Cobub Razor 0.8.0 - Physical Path Leakage
CVE-2018-805620 Apr 2018
Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via an invalid channel_name parameter to /index.php?/ma
28RISK
open
Exploit-DB
Geist WatchDog Console 3.2.2 - Multiple Vulnerabilities
CVE-2018-1007718 Apr 2018
XML external entity (XXE) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to re
23RISK
open
Exploit-DB
Match Clone Script 1.0.4 - Cross-Site Scripting
CVE-2018-985718 Apr 2018
PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to searchbyid.php (aka the "View Search By Id" sc
23RISK
open
Exploit-DB
Kodi 17.6 - Persistent Cross-Site Scripting
CVE-2018-883118 Apr 2018
A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/s
35RISK
open
Exploit-DB
Geist WatchDog Console 3.2.2 - Multiple Vulnerabilities
CVE-2018-1007818 Apr 2018
Cross-site scripting (XSS) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to i
23RISK
open
Exploit-DB
WordPress Plugin Caldera Forms 1.5.9.1 - Cross-Site Scripting
CVE-2018-774718 Apr 2018
Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow re
23RISK
open
Exploit-DB
Easy File Sharing Web Server 7.2 - Stack Buffer Overflow
CVE-2018-905918 Apr 2018
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code
60RISK
open
Exploit-DB
Lutron Quantum 2.0 - 3.2.243 - Information Disclosure
CVE-2018-888018 Apr 2018
Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) doesn't check for correct user authentication before showing th
28RISK
open
Exploit-DB
Brave Browser < 0.13.0 - 'window.close(self)' Denial of Service
CVE-2016-1071817 Apr 2018
Brave Browser before 0.13.0 allows a tab to close itself even if the tab was not opened by a script, resulting in denial
28RISK
open
Exploit-DB
Ultra MiniHTTPd 1.2 - 'GET' Remote Stack Buffer Overflow (PoC)
CVE-2013-501917 Apr 2018
Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resour
50RISK
open
Exploit-DB
Joomla! Component jDownloads 3.2.58 - Cross Site Scripting
CVE-2018-1006817 Apr 2018
The jDownloads extension before 3.2.59 for Joomla! has XSS.
23RISK
open
Exploit-DB
Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (Metasploit)
CVE-2018-7600CRITICALunder attackransomware17 Apr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
Exploit-DB
D-Link DIR-615 Wireless Router - Persistent Cross Site Scripting
CVE-2018-1011017 Apr 2018
D-Link DIR-615 T1 devices allow XSS via the Add User feature.
23RISK
open
Exploit-DB
Brave Browser < 0.13.0 - 'long alert() argument' Denial of Service
CVE-2017-1825617 Apr 2018
Brave Browser before 0.13.0 allows remote attackers to cause a denial of service (resource consumption) via a long alert
23RISK
open
Exploit-DB
CloudMe Sync 1.11.0 - Local Buffer Overflow
CVE-2018-788616 Apr 2018
An issue was discovered in CloudMe 1.11.0. An unauthenticated local attacker that can connect to the "CloudMe Sync" clie
23RISK
open
Exploit-DB
Microsoft Windows - 'nt!NtQueryFullAttributesFile' Kernel Stack Memory Disclosure
CVE-2018-097516 Apr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open
Exploit-DB
Microsoft Windows - 'CiSetFileCache' TOCTOU Incomplete Fix
CVE-2018-096616 Apr 2018
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security F
23RISK
open
Exploit-DB
Microsoft Windows - 'nt!NtQueryVirtualMemory (MemoryImageInformation)' Kernel 64-bit Stack Memory Disclosure
CVE-2018-096816 Apr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open
Exploit-DB
Microsoft Windows - 'nt!NtQueryVirtualMemory (Memory(Privileged)BasicInformation)' Kernel 64-bit Stack Memory Disclosure
CVE-2018-097416 Apr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open
Exploit-DB
Microsoft Windows - 'nt!NtQueryInformationTransactionManager (TransactionManagerRecoveryInformation)' Kernel Pool Memory Disclosure
CVE-2018-097216 Apr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open
Exploit-DB
Microsoft Windows - 'nt!NtQuerySystemInformation (SystemPageFileInformation(Ex))' Kernel 64-bit Stack Memory Disclosure
CVE-2018-097116 Apr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open
Exploit-DB
Microsoft Windows - 'nt!NtQueryInformationProcess (ProcessImageFileName)' Kernel 64-bit Pool/Stack Memory Disclosure
CVE-2018-097316 Apr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open
Exploit-DB
Cobub Razor 0.8.0 - SQL injection
CVE-2018-805716 Apr 2018
A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a
28RISK
open
Exploit-DB
Microsoft Windows - 'nt!NtQueryAttributesFile' Kernel Stack Memory Disclosure
CVE-2018-096916 Apr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.