Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DBVexDay Proof
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
CVE-2018-8736webappsphp30 Apr 2018
A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RC
50RISK
open
Exploit-DBVexDay Proof
Apple macOS 10.13.2 - Double mach_port_deallocate in kextd due to Failure to Comply with MIG Ownership Rules
CVE-2018-4139dosmacos30 Apr 2018
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "kext tools"
23RISK
open
Exploit-DBVexDay Proof
Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code (Metasploit)
CVE-2018-7602CRITICALunder attackransomwarewebappsphp30 Apr 2018
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RISK
open
Exploit-DBVexDay Proof
Apple macOS/iOS - ReportCrash mach port Replacement due to Failure to Respect MIG Ownership Rules
CVE-2018-4206dosmultiple30 Apr 2018
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2
23RISK
open
Exploit-DBVexDay Proof
Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code Execution (PoC)
CVE-2018-7602CRITICALunder attackransomwarewebappsphp25 Apr 2018
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RISK
open
Exploit-DBVexDay Proof
Adobe Flash - Overflow when Playing Sound
CVE-2018-4936dosmultiple24 Apr 2018
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Heap Overflow vulnerability. Successful exploitat
28RISK
open
Exploit-DBVexDay Proof
Adobe Flash - Overflow in Slab Rendering
CVE-2018-4935dosmultiple24 Apr 2018
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exp
28RISK
open
Exploit-DBVexDay Proof
Adobe Flash - Out-of-Bounds Write in blur Filtering
CVE-2018-4937dosmultiple24 Apr 2018
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exp
28RISK
open
Exploit-DBVexDay Proof
ASUS infosvr - Authentication Bypass Command Execution (Metasploit)
CVE-2014-9583remotehardware24 Apr 2018
common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC
60RISK
open
Exploit-DBVexDay Proof
Adobe Flash - Info Leak in Image Inflation
CVE-2018-4934dosmultiple24 Apr 2018
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful expl
28RISK
open
Exploit-DBVexDay Proof
Oracle Weblogic Server 10.3.6.0 / 12.1.3.0 / 12.2.1.2 / 12.2.1.3 - Deserialization Remote Command Execution
CVE-2018-2628CRITICALunder attackremotemultiple22 Apr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
Exploit-DBVexDay Proof
Match Clone Script 1.0.4 - Cross-Site Scripting
CVE-2018-9857webappsphp18 Apr 2018
PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to searchbyid.php (aka the "View Search By Id" sc
23RISK
open
Exploit-DBVexDay Proof
Ultra MiniHTTPd 1.2 - 'GET' Remote Stack Buffer Overflow (PoC)
CVE-2013-5019localwindows_x8617 Apr 2018
Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resour
50RISK
open
Exploit-DBVexDay Proof
Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (Metasploit)
CVE-2018-7600CRITICALunder attackransomwareremotephp17 Apr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'nt!NtQueryInformationProcess (ProcessImageFileName)' Kernel 64-bit Pool/Stack Memory Disclosure
CVE-2018-0973doswindows16 Apr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'nt!NtQuerySystemInformation (SystemPageFileInformation(Ex))' Kernel 64-bit Stack Memory Disclosure
CVE-2018-0971doswindows16 Apr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'nt!NtQueryVolumeInformationFile' Kernel Stack Memory Disclosure
CVE-2018-0970doswindows16 Apr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'nt!NtQueryVirtualMemory (MemoryImageInformation)' Kernel 64-bit Stack Memory Disclosure
CVE-2018-0968doswindows16 Apr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'CiSetFileCache' TOCTOU Incomplete Fix
CVE-2018-0966doswindows16 Apr 2018
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security F
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'nt!NtQueryAttributesFile' Kernel Stack Memory Disclosure
CVE-2018-0969doswindows16 Apr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'nt!NtQueryVirtualMemory (Memory(Privileged)BasicInformation)' Kernel 64-bit Stack Memory Disclosure
CVE-2018-0974doswindows16 Apr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'nt!NtQueryInformationTransactionManager (TransactionManagerRecoveryInformation)' Kernel Pool Memory Disclosure
CVE-2018-0972doswindows16 Apr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'nt!NtQueryFullAttributesFile' Kernel Stack Memory Disclosure
CVE-2018-0975doswindows16 Apr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open
Exploit-DBVexDay Proof
Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution
CVE-2018-7600CRITICALunder attackransomwarewebappsphp13 Apr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
Exploit-DBVexDay Proof
Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (PoC)
CVE-2018-7600CRITICALunder attackransomwarewebappsphp13 Apr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
Exploit-DBVexDay Proof
WebKit - WebAssembly Parsing Does not Correctly Check Section Order
CVE-2018-4121dosmultiple09 Apr 2018
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud b
28RISK
open
Exploit-DBVexDay Proof
Cobub Razor 0.7.2 - Cross-Site Request Forgery
CVE-2018-7746webappsphp06 Apr 2018
An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/manage/chann
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Multiple Use-After-Free Issues in jscript Array Methods
CVE-2018-0935doswindows05 Apr 2018
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Se
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Defender - 'mpengine.dll' Memory Corruption
CVE-2018-0986doswindows05 Apr 2018
A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a speci
35RISK
open
Exploit-DBVexDay Proof
Google Chrome V8 - 'ElementsAccessorBase::CollectValuesOrEntriesImpl' Type Confusion
CVE-2018-6064dosmultiple03 Apr 2018
Type Confusion in the implementation of __defineGetter__ in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.