Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,900cataloged exploits
36,847CVEs with public exploitation
24,695lab-tested
24,475 exploits
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Magic Value Type Confusion
CVE-2018-0953doswindows22 May 2018
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
35RISK
open
Exploit-DBVexDay Proof
Linux 4.4.0 < 4.4.0-53 - 'AF_PACKET chocobo_root' Local Privilege Escalation (Metasploit)
CVE-2016-8655locallinux22 May 2018
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cau
43RISK
open
Exploit-DB
ERPnext 11 - Cross-Site Scripting
CVE-2018-11339webappsjava22 May 2018
An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.
23RISK
open
Exploit-DB
MakeMyTrip 7.2.4 - Information Disclosure
CVE-2018-11242localandroid22 May 2018
An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypte
23RISK
open
Exploit-DBVexDay Proof
AMD / ARM / Intel - Speculative Execution Variant 4 Speculative Store Bypass
CVE-2018-3639MEDIUMdoshardware22 May 2018
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addres
45RISK
open
Exploit-DB
ManageEngine Recovery Manager Plus 5.3 - Cross-Site Scripting
CVE-2018-9163webappsjava21 May 2018
A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) all
23RISK
open
Exploit-DB
Microsoft Internet Explorer 11 (Windows 7 x86/x64) - vbscript Code Execution
CVE-2018-8174HIGHunder attackransomwarelocalwindows21 May 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISK
open
Exploit-DBVexDay Proof
Linux 2.6.30 < 2.6.36-rc8 - Reliable Datagram Sockets (RDS) Privilege Escalation (Metasploit)
CVE-2010-3904HIGHunder attacklocallinux21 May 2018
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the
91RISK
open
Exploit-DB
Schneider Electric PLCs - Cross-Site Request Forgery
CVE-2013-0663webappswindows21 May 2018
Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10
23RISK
open
Exploit-DB
D-Link DSL-3782 - Authentication Bypass
CVE-2018-8898webappshardware20 May 2018
A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B0
28RISK
open
Exploit-DB
HPE iMC 7.3 - Remote Code Execution (Metasploit)
CVE-2017-8982remotewindows18 May 2018
A Remote Authentication Restriction Bypass vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E05
28RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Bound Check Elimination Bug
CVE-2018-0980doswindows18 May 2018
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RISK
open
Exploit-DBVexDay Proof
Linux 4.8.0 < 4.8.0-46 - AF_PACKET packet_set_ring Privilege Escalation (Metasploit)
CVE-2017-7308locallinux18 May 2018
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate cer
43RISK
open
Exploit-DBVexDay Proof
DynoRoot DHCP Client - Command Injection
CVE-2018-1111HIGHlocallinux18 May 2018
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RISK
open
Exploit-DB
HPE iMC 7.3 - Remote Code Execution (Metasploit)
CVE-2017-12500remotewindows18 May 2018
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found
28RISK
open
Exploit-DBVexDay Proof
Apache Struts 2 - Struts 1 Plugin Showcase OGNL Code Execution (Metasploit)
CVE-2017-9791CRITICALunder attackremotemultiple17 May 2018
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RISK
open
Exploit-DB
Powerlogic/Schneider Electric IONXXXX Series - Cross-Site Request Forgery
CVE-2016-5809webappslinux17 May 2018
An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series
23RISK
open
Exploit-DB
Intelbras NCLOUD 300 1.0 - Authentication bypass
CVE-2018-11094webappshardware17 May 2018
An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/Rebo
35RISK
open
Exploit-DBVexDay Proof
Jenkins CLI - HTTP Java Deserialization (Metasploit)
CVE-2016-9299remotelinux17 May 2018
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a
60RISK
open
Exploit-DBVexDay Proof
Nanopool Claymore Dual Miner 7.3 - Remote Code Execution
CVE-2018-1000049remotewindows17 May 2018
Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner
60RISK
open
Exploit-DB
totemomail Encryption Gateway 6.0.0 Build 371 - Cross-Site Request Forgery
CVE-2018-6563webappsasp16 May 2018
Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow
23RISK
open
Exploit-DBVexDay Proof
Libuser - 'roothelper' Local Privilege Escalation (Metasploit)
CVE-2015-3246MEDIUMunder attacklocallinux16 May 2018
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod
78RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Token Process Trust SID Access Check Bypass Privilege Escalation
CVE-2018-8134localwindows16 May 2018
An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows
23RISK
open
Exploit-DB
Inteno IOPSYS 2.0 < 4.2.0 - 'p910nd' Remote Command Execution
CVE-2018-10123remotehardware16 May 2018
p910nd on Inteno IOPSYS 2.0 through 4.2.0 allows remote attackers to read, or append data to, arbitrary files via reques
28RISK
open
Exploit-DB
RSA Authentication Manager 8.2.1.4.0-build1394922 / < 8.3 P1 - XML External Entity Injection / Cross-Site Flashing / DOM Cross-Site Scripting
CVE-2018-1247webappsjava16 May 2018
RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability
28RISK
open
Exploit-DB
Rockwell Scada System 27.011 - Cross-Site Scripting
CVE-2016-2279MEDIUMwebappswindows16 May 2018
Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* bef
33RISK
open
Exploit-DBVexDay Proof
Libuser - 'roothelper' Local Privilege Escalation (Metasploit)
CVE-2015-3245locallinux16 May 2018
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in t
38RISK
open
Exploit-DB
VirtueMart 3.1.14 - Persistent Cross-Site Scripting
CVE-2018-7465webappsphp16 May 2018
An XSS issue was discovered in VirtueMart before 3.2.14. All the textareas in the backend of the plugin can be closed by
23RISK
open
Exploit-DB
2345 Security Guard 3.7 - '2345NsProtect.sys' Denial of Service
CVE-2018-11034doswindows14 May 2018
In 2345 Security Guard 3.7, the driver file (2345NsProtect.sys, X64 version) allows local users to cause a denial of ser
23RISK
open
Exploit-DB
WUZHI CMS 4.1.0 - 'tag[pinyin]' Cross-Site Scripting
CVE-2018-10311webappsphp13 May 2018
A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitr
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.