Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
8,460 exploits
VulnCheck XDB
client-side
CVE-2016-3714HIGHunder attack18 Jun 2018
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack18 Jun 2018
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
local
CVE-2017-1000253HIGHunder attackransomware18 Jun 2018
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb7
76RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2018-1151018 Jun 2018
The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/
35RISK
open
VulnCheck XDB
local
CVE-2018-0824HIGHunder attack15 Jun 2018
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized
100RISK
open
VulnCheck XDB
local
CVE-2016-7255HIGHunder attack09 Jun 2018
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RISK
open
VulnCheck XDB
local
CVE-2018-8120HIGHunder attackransomware07 Jun 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALunder attackransomware06 Jun 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-8581HIGHunder attackransomware06 Jun 2018
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of
76RISK
open
VulnCheck XDB
initial-access
CVE-2018-10562CRITICALunder attackransomware06 Jun 2018
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RISK
open
VulnCheck XDB
infoleak
CVE-2018-1203106 Jun 2018
Local file inclusion in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file via server/node_upgrad
43RISK
open
VulnCheck XDB
initial-access
CVE-2018-2628CRITICALunder attack05 Jun 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-10271HIGHunder attackransomware05 Jun 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
VulnCheck XDB
client-side
CVE-2018-8174HIGHunder attackransomware01 Jun 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISK
open
VulnCheck XDB
client-side
CVE-2018-8174HIGHunder attackransomware30 May 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2018-10562CRITICALunder attackransomware26 May 2018
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-15944CRITICALunder attack24 May 2018
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RISK
open
VulnCheck XDB
client-side
CVE-2018-8174HIGHunder attackransomware22 May 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISK
open
VulnCheck XDB
local
CVE-2018-8120HIGHunder attackransomware19 May 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
VulnCheck XDB
local
CVE-2018-8120HIGHunder attackransomware17 May 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-10562CRITICALunder attackransomware17 May 2018
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALunder attackransomware13 May 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-1029911 May 2018
An integer overflow in the batchTransfer function of a smart contract implementation for Beauty Ecosystem Coin (BEC), th
23RISK
open
VulnCheck XDB
initial-access
CVE-2017-7494CRITICALunder attackransomware10 May 2018
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2018-999509 May 2018
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
VulnCheck XDB
info-leak
CVE-2018-999508 May 2018
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
VulnCheck XDB
initial-access
CVE-2018-2628CRITICALunder attack03 May 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
VulnCheck XDB
infoleak
CVE-2018-999529 Apr 2018
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
VulnCheck XDB
initial-access
CVE-2017-7269CRITICALunder attack28 Apr 2018
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALunder attackransomware27 Apr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
previouspage 270 / 282next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.