Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
Google Chrome V8 - 'ElementsAccessorBase::CollectValuesOrEntriesImpl' Type Confusion
CVE-2018-6064dosmultiple03 Apr 2018
Type Confusion in the implementation of __defineGetter__ in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote
23RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Stack-to-Heap Copy (Incomplete Fix) (2)
CVE-2018-0934doswindows03 Apr 2018
ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution,
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Stack-to-Heap Copy (Incomplete Fix) (1)
CVE-2018-0934doswindows03 Apr 2018
ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution,
35RISK
open
Exploit-DBVexDay Proof
WampServer 3.1.1 - Cross-Site Scripting / Cross-Site Request Forgery
CVE-2018-8732webappsphp02 Apr 2018
Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or H
23RISK
open
Exploit-DBVexDay Proof
WampServer 3.1.2 - Cross-Site Request Forgery
CVE-2018-8817webappsphp02 Apr 2018
Wampserver before 3.1.3 has CSRF in add_vhost.php.
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Acymailing Starter 5.9.5 - CSV Macro Injection
CVE-2018-9107webappsphp30 Mar 2018
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing exte
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component AcySMS 3.5.0 - CSV Macro Injection
CVE-2018-9106webappsphp30 Mar 2018
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extensio
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Fields - SQLi Remote Code Execution (Metasploit)
CVE-2017-8917webappsphp29 Mar 2018
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISK
open
Exploit-DBVexDay Proof
GitStack - Unsanitized Argument Remote Code Execution (Metasploit)
CVE-2018-5955remotewindows29 Mar 2018
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau
60RISK
open
Exploit-DBVexDay Proof
Exodus Wallet (ElectronJS Framework) - Remote Code Execution (Metasploit)
CVE-2018-1000006remotewindows29 Mar 2018
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the pro
60RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Remote Assistance - XML External Entity Injection
CVE-2018-0878LOWwebappswindows28 Mar 2018
Windows Remote Assistance in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Window
33RISK
open
Exploit-DBVexDay Proof
Dell EMC NetWorker - Denial of Service
CVE-2018-1218doslinux23 Mar 2018
In Dell EMC NetWorker versions prior to 9.2.1.1, versions prior to 9.1.1.6, 9.0.x, and versions prior to 8.2.4.11, the '
28RISK
open
Exploit-DBVexDay Proof
WordPress Plugin Site Editor 1.1.1 - Local File Inclusion
CVE-2018-7422webappsphp23 Mar 2018
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Desktop Bridge Virtual Registry NtLoadKey Arbitrary File Read/Write Privilege Escalation
CVE-2018-0882localwindows20 Mar 2018
The Desktop Bridge in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an el
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'NtQueryVirtualMemory(MemoryMappedFilenameInformation)' 64-bit Pool Memory Disclosure
CVE-2018-0894doswindows_x86-6420 Mar 2018
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Serve
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'NtQueryInformationThread(ThreadBasicInformation)' 64-bit Stack Memory Disclosure
CVE-2018-0895doswindows_x86-6420 Mar 2018
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Serve
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'nt!KiDispatchException' 64-bit Stack Memory Disclosure
CVE-2018-0897doswindows_x86-6420 Mar 2018
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Serve
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'nt!NtWaitForDebugEvent' 64-bit Stack Memory Disclosure
CVE-2018-0901doswindows_x86-6420 Mar 2018
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Serve
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Desktop Bridge Virtual Registry Arbitrary File Read/Write Privilege Escalation
CVE-2018-0880localwindows20 Mar 2018
The Desktop Bridge in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an el
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Desktop Bridge VFS Privilege Escalation
CVE-2018-0877localwindows_x86-6420 Mar 2018
The Desktop Bridge Virtual File System (VFS) in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server,
23RISK
open
Exploit-DBVexDay Proof
Google Software Updater macOS - Unsafe use of Distributed Objects Privilege Escalation
CVE-2018-6084localmacos20 Mar 2018
Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359.117 allowed a local
23RISK
open
Exploit-DBVexDay Proof
Internet Explorer - 'RegExp.lastMatch' Memory Disclosure
CVE-2018-0891doswindows20 Mar 2018
ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT
28RISK
open
Exploit-DBVexDay Proof
Firefox 44.0.2 - ASM.JS JIT-Spray Remote Code Execution
CVE-2016-1960remotewindows16 Mar 2018
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox
35RISK
open
Exploit-DBVexDay Proof
Firefox 44.0.2 - ASM.JS JIT-Spray Remote Code Execution
CVE-2017-5375remotewindows16 Mar 2018
JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. T
35RISK
open
Exploit-DBVexDay Proof
Firefox 46.0.1 - ASM.JS JIT-Spray Remote Code Execution
CVE-2016-2819remotewindows16 Mar 2018
Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to ex
28RISK
open
Exploit-DBVexDay Proof
Firefox 46.0.1 - ASM.JS JIT-Spray Remote Code Execution
CVE-2017-5375remotewindows16 Mar 2018
JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. T
35RISK
open
Exploit-DBVexDay Proof
Tuleap 9.17.99.189 - Blind SQL Injection
CVE-2018-7538webappsphp13 Mar 2018
A SQL injection vulnerability in the tracker functionality of Enalean Tuleap software engineering platform before 9.18 a
23RISK
open
Exploit-DBVexDay Proof
Advantech WebAccess < 8.3 - Directory Traversal / Remote Code Execution
CVE-2017-16720webappswindows12 Mar 2018
A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within th
35RISK
open
Exploit-DBVexDay Proof
uWSGI < 2.0.17 - Directory Traversal
CVE-2018-7490webappsphp02 Mar 2018
uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversa
50RISK
open
Exploit-DBVexDay Proof
Apple iOS 11.2.5 / watchOS 4.2.2 / tvOS 11.2.5 - 'bluetoothd' Memory Corruption
CVE-2018-4087dosmultiple28 Feb 2018
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchO
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.