Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,900cataloged exploits
36,847CVEs with public exploitation
24,695lab-tested
24,475 exploits
Exploit-DBVexDay Proof
MachForm < 4.2.3 - SQL Injection / Path Traversal / Upload Bypass
CVE-2018-6410webappsphp30 May 2018
An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter.
23RISK
open
Exploit-DBVexDay Proof
Dolibarr ERP/CRM 7.0.0 - (Authenticated) SQL Injection
CVE-2018-10094webappsphp30 May 2018
SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vecto
60RISK
open
Exploit-DB
Procps-ng - Multiple Vulnerabilities
CVE-2018-1121LOWlocallinux30 May 2018
procps-ng, procps is vulnerable to a process hiding through race condition. Since the kernel's proc_pid_readdir() return
28RISK
open
Exploit-DB
Procps-ng - Multiple Vulnerabilities
CVE-2018-1124HIGHlocallinux30 May 2018
procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec
41RISK
open
Exploit-DB
Procps-ng - Multiple Vulnerabilities
CVE-2018-1122HIGHlocallinux30 May 2018
procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset
41RISK
open
Exploit-DB
Procps-ng - Multiple Vulnerabilities
CVE-2018-1120LOWlocallinux30 May 2018
A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file onto a process's memory
28RISK
open
Exploit-DB
NUUO NVRmini2 / NVRsolo - Arbitrary File Upload
CVE-2018-11523webappshardware29 May 2018
upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files.
23RISK
open
Exploit-DB
MyBB ChangUonDyU Plugin 1.0.2 - Cross-Site Scripting
CVE-2018-11532webappsphp29 May 2018
An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonst
23RISK
open
Exploit-DB
Sitemakin SLAC 1.0 - 'my_item_search' SQL Injection
CVE-2018-11535webappsphp29 May 2018
An issue was discovered in SITEMAKIN SLAC (Site Login and Access Control) v1.0. The parameter "my_item_search" in users.
23RISK
open
Exploit-DB
wityCMS 0.6.1 - Cross-Site Scripting
CVE-2018-11512webappsphp28 May 2018
Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "Ge
23RISK
open
Exploit-DB
DomainMod 4.09.03 - 'sslpaid' Cross-Site Scripting
CVE-2018-11404webappsphp28 May 2018
DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter.
23RISK
open
Exploit-DB
DomainMod 4.09.03 - 'oid' Cross-Site Scripting
CVE-2018-11403webappsphp28 May 2018
DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter.
23RISK
open
Exploit-DB
Bitmain Antminer D3/L3+/S9 - Remote Command Execution
CVE-2018-11220remotehardware27 May 2018
Bitmain Antminer D3, L3+, and S9 devices allow Remote Command Execution via the system restore function.
28RISK
open
Exploit-DB
Werewolf Online 0.8.8 - Information Disclosure
CVE-2018-11505localandroid27 May 2018
The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat outp
23RISK
open
Exploit-DB
ClipperCMS 1.3.3 - Cross-Site Scripting
CVE-2018-11332webappsphp27 May 2018
Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in
23RISK
open
Exploit-DB
EasyService Billing 1.0 - Cross-Site Scripting
CVE-2018-11443webappsphp26 May 2018
The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0.
23RISK
open
Exploit-DB
EasyService Billing 1.0 - Cross-Site Request Forgery
CVE-2018-11442webappsphp26 May 2018
A CSRF issue was discovered in EasyService Billing 1.0, which was triggered via a quotation-new3-new2.php?add=true&id= U
23RISK
open
Exploit-DB
EasyService Billing 1.0 - 'q' SQL Injection
CVE-2018-11444webappsphp26 May 2018
A SQL Injection issue was observed in the parameter "q" in jobcard-ongoing.php in EasyService Billing 1.0.
23RISK
open
Exploit-DB
EasyService Billing 1.0 - Cross-Site Request Forgery
CVE-2018-11445webappsphp26 May 2018
A CSRF issue was discovered on the User Add/System Settings Page (system-settings-user-new2.php) in EasyService Billing
23RISK
open
Exploit-DBVexDay Proof
Oracle WebCenter Sites 11.1.1.8.0/12.2.1.x - Cross-Site Scripting
CVE-2018-2791webappsmultiple25 May 2018
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported
50RISK
open
Exploit-DB
Oracle WebCenter FatWire Content Server < 7 - Improper Access Control
CVE-2017-10033webappslinux25 May 2018
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Support Tools). Support
23RISK
open
Exploit-DBVexDay Proof
Skia and Firefox - Integer Overflow in SkTDArray Leading to Out-of-Bounds Write
CVE-2018-5159dosmultiple25 May 2018
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks,
28RISK
open
Exploit-DB
SAP Internet Transaction Server 6200.x - Session Fixation / Cross-Site Scripting
CVE-2018-11415webappsmultiple25 May 2018
SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: th
23RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - Cross Context Use-After-Free
CVE-2018-0946doswindows25 May 2018
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
35RISK
open
Exploit-DB
Honeywell XL Web Controller - Cross-Site Scripting
CVE-2014-3110webappslinux24 May 2018
Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earli
23RISK
open
Exploit-DBVexDay Proof
Samsung Galaxy S7 Edge - Overflow in OMACP WbXml String Extension Processing
CVE-2018-10751dosandroid23 May 2018
A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Ex
23RISK
open
Exploit-DB
Siemens SCALANCE S613 - Remote Denial of Service
CVE-2016-3963doslinux23 May 2018
Siemens SCALANCE S613 allows remote attackers to cause a denial of service (web-server outage) via traffic to TCP port 4
23RISK
open
Exploit-DB
ERPnext 11 - Cross-Site Scripting
CVE-2018-11339webappsjava22 May 2018
An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.
23RISK
open
Exploit-DB
Siemens SIMATIC S7-1200 CPU - Cross-Site Scripting
CVE-2014-2908webappslinux22 May 2018
Cross-site scripting (XSS) vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x
43RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'POP/MOV SS' Privilege Escalation
CVE-2018-8897localwindows22 May 2018
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.