Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
22,786 exploits
Exploit-DB
Freelance Website Script 2.0.6 - 'pr_id' / 'catid' SQL Injection
CVE-2017-1761311 Dec 2017
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php cati
23RISK
open
Exploit-DB
MLM Forced Matrix 2.0.9 - 'newid' SQL Injection
CVE-2017-1763611 Dec 2017
MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
23RISK
open
Exploit-DB
Advanced World Database 2.0.5 - SQL Injection
CVE-2017-1764011 Dec 2017
Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country pa
23RISK
open
Exploit-DB
Apple macOS - 'getrusage' Stack Leak Through struct Padding
CVE-2017-1386911 Dec 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISK
open
Exploit-DB
Entrepreneur Bus Booking Script 3.0.4 - 'sourcebus' SQL Injection
CVE-2017-1760411 Dec 2017
Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter.
23RISK
open
Exploit-DB
Linux Kernel - 'mincore()' Heap Page Disclosure (PoC)
CVE-2017-1699411 Dec 2017
The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, w
23RISK
open
Exploit-DB
Multireligion Responsive Matrimonial 4.7.2 - 'succid' SQL Injection
CVE-2017-1763111 Dec 2017
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
23RISK
open
Exploit-DB
Vanguard 1.4 - SQL Injection
CVE-2017-1787311 Dec 2017
Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.
23RISK
open
Exploit-DB
Multivendor Penny Auction Clone Script 1.0 - SQL Injection
CVE-2017-1762111 Dec 2017
Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.
23RISK
open
Exploit-DB
Hot Scripts Clone 3.1 - 'subctid' / 'mctid' SQL Injection
CVE-2017-1761211 Dec 2017
Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.
23RISK
open
Exploit-DB
Laundry Booking Script 1.0 - 'list?city' SQL Injection
CVE-2017-1761911 Dec 2017
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open
Exploit-DB
Online Exam Test Application Script 1.6 - 'exams.php?sort' SQL Injection
CVE-2017-1762211 Dec 2017
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
23RISK
open
Exploit-DB
Linux Kernel - 'The Huge Dirty Cow' Overwriting The Huge Zero Page (2)
CVE-2017-100040511 Dec 2017
The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside
23RISK
open
Exploit-DB
Single Theater Booking Script 3.2.1 - 'findcity.php?q' SQL Injection
CVE-2017-1763411 Dec 2017
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RISK
open
Exploit-DB
MLM Forex Market Plan Script 2.0.4 - 'newid' / 'eventid' SQL Injection
CVE-2017-1763511 Dec 2017
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eve
23RISK
open
Exploit-DB
Responsive Events & Movie Ticket Booking Script 3.2.1 - 'findcity.php?q' SQL Injection
CVE-2017-1763211 Dec 2017
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RISK
open
Exploit-DB
Professional Service Script 1.0 - 'service-list?city' SQL Injection
CVE-2017-1762511 Dec 2017
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
23RISK
open
Exploit-DB
Readymade Video Sharing Script 3.2 - SQL Injection
CVE-2017-1762711 Dec 2017
Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.
23RISK
open
Exploit-DB
Apple macOS/iOS - Kernel Double Free due to IOSurfaceRootUserClient not Respecting MIG Ownership Rules
CVE-2017-1386111 Dec 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. watchOS be
43RISK
open
Exploit-DB
Facebook Clone Script 1.0 - 'id' / 'send' SQL Injection
CVE-2017-1761511 Dec 2017
Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.
23RISK
open
Exploit-DB
Multiplex Movie Theater Booking Script 3.1.5 - 'moid' / 'eid' SQL Injection
CVE-2017-1763311 Dec 2017
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php
23RISK
open
Exploit-DB
Muslim Matrimonial Script 3.02 - 'succid' SQL Injection
CVE-2017-1763911 Dec 2017
Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.
23RISK
open
Exploit-DB
Apple macOS XNU Kernel - Memory Disclosure due to bug in Kernel API for Detecting Kernel Memory Disclosures
CVE-2017-1386511 Dec 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISK
open
Exploit-DB
Responsive Realestate Script 3.2 - 'property-list?tbud' SQL Injection
CVE-2017-1762811 Dec 2017
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
23RISK
open
Exploit-DB
Groupon Clone Script 3.01 - 'state_id' / 'search' SQL Injection
CVE-2017-1763811 Dec 2017
Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
23RISK
open
Exploit-DB
Yoga Class Script 1.0 - 'list?city' SQL Injection
CVE-2017-1763011 Dec 2017
Yoga Class Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open
Exploit-DB
Car Rental Script 2.0.4 - 'val' SQL Injection
CVE-2017-1763711 Dec 2017
Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.
23RISK
open
Exploit-DB
Secure E-commerce Script 2.0.1 - 'searchcat' / 'searchmain' SQL Injection
CVE-2017-1762911 Dec 2017
Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_d
23RISK
open
Exploit-DB
Resume Clone Script 2.0.5 - SQL Injection
CVE-2017-1764111 Dec 2017
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
23RISK
open
Exploit-DB
Basic Job Site Script 2.0.5 - SQL Injection
CVE-2017-1764211 Dec 2017
Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.
23RISK
open
previouspage 113 / 760next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.