Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
Navigate CMS - (Unauthenticated) Remote Code Execution (Metasploit)
CVE-2018-17553remotephp08 Oct 2018
An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs N
60RISK
open
Exploit-DBVexDay Proof
Navigate CMS - (Unauthenticated) Remote Code Execution (Metasploit)
CVE-2018-17552remotephp08 Oct 2018
SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigat
60RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Net-NTLMv2 Reflection DCOM/RPC (Metasploit)
CVE-2016-3225localwindows08 Oct 2018
The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
43RISK
open
Exploit-DBVexDay Proof
Android - sdcardfs Changes current->fs Without Proper Locking
CVE-2018-9515dosandroid08 Oct 2018
In sdcardfs_create and sdcardfs_mkdir of inode.c, there is a possible memory corruption due to improper locking. This co
23RISK
open
Exploit-DBVexDay Proof
D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilities
CVE-2018-17443webappsphp05 Oct 2018
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateS
23RISK
open
Exploit-DBVexDay Proof
D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilities
CVE-2018-17440webappsphp05 Oct 2018
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves b
28RISK
open
Exploit-DBVexDay Proof
D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilities
CVE-2018-17441webappsphp05 Oct 2018
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser
23RISK
open
Exploit-DBVexDay Proof
D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilities
CVE-2018-17442webappsphp05 Oct 2018
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. An unrestricted file upload vulnerabili
28RISK
open
Exploit-DBVexDay Proof
PCProtect 4.8.35 - Privilege Escalation
CVE-2018-17776localwindows_x86-6428 Sep 2018
PCProtect Anti-Virus v4.8.35 has "Everyone: (F)" permission for %PROGRAMFILES(X86)%\PCProtect, which allows local users
23RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - Sandbox Escape
CVE-2018-8468remotewindows27 Sep 2018
An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privil
28RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - Sandbox Escape
CVE-2018-8469remotewindows27 Sep 2018
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppCont
28RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - Sandbox Escape
CVE-2018-8463remotewindows27 Sep 2018
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppCont
28RISK
open
Exploit-DBVexDay Proof
Linux Kernel - VMA Use-After-Free via Buggy vmacache_flush_all() Fastpath Local Privilege Escalation
CVE-2018-17182locallinux26 Sep 2018
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::RenderMultiColumnSet::updateMinimumColumnHeight' Use-After-Free
CVE-2018-4323dosmultiple25 Sep 2018
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Jobs Factory 2.0.4 - SQL Injection
CVE-2018-17382webappsphp25 Sep 2018
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Reverse Auction Factory 4.3.8 - SQL Injection
CVE-2018-17376webappsphp25 Sep 2018
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Social Factory 3.8.3 - SQL Injection
CVE-2018-17385webappsphp25 Sep 2018
SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radiu
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Swap Factory 2.2.1 - SQL Injection
CVE-2018-17384webappsphp25 Sep 2018
SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.
23RISK
open
Exploit-DBVexDay Proof
Solaris - 'EXTREMEPARR' dtappgather Privilege Escalation (Metasploit)
CVE-2017-3622localsolaris25 Sep 2018
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Common Desktop Environment (C
38RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::RenderTreeBuilder::removeAnonymousWrappersForInlineChildrenIfNeeded' Use-After-Free
CVE-2018-4197dosmultiple25 Sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Penny Auction Factory 2.0.4 - SQL Injection
CVE-2018-17378webappsphp25 Sep 2018
SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order p
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Music Collection 3.0.3 - SQL Injection
CVE-2018-17375webappsphp25 Sep 2018
SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter.
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::AXObjectCache::handleMenuItemSelected' Use-After-Free
CVE-2018-4312dosmultiple25 Sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Article Factory Manager 4.3.9 - SQL Injection
CVE-2018-17380webappsphp25 Sep 2018
SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_e
23RISK
open
Exploit-DBVexDay Proof
Super Cms Blog Pro 1.0 - SQL Injection
CVE-2018-17391webappsphp25 Sep 2018
SQL Injection exists in authors_post.php in Super Cms Blog Pro 1.0 via the author parameter.
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::SVGTextLayoutAttributes::context' Use-After-Free
CVE-2018-4318dosmultiple25 Sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::Node::ensureRareData' Use-After-Free
CVE-2018-4306dosmultiple25 Sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Raffle Factory 3.5.2 - SQL Injection
CVE-2018-17379webappsphp25 Sep 2018
SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order paramete
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::RenderLayer::updateDescendantDependentFlags' Use-After-Free
CVE-2018-4317dosmultiple25 Sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::SVGTRefElement::updateReferencedText' Use-After-Free
CVE-2018-4315dosmultiple25 Sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.