Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
22,786 exploits
Exploit-DB
D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilities
CVE-2018-1744005 Oct 2018
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves b
35RISK
open
Exploit-DB
Git Submodule - Arbitrary Code Execution (PoC)
CVE-2018-1745605 Oct 2018
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RISK
open
Exploit-DB
D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilities
CVE-2018-1744105 Oct 2018
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser
23RISK
open
Exploit-DB
D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilities
CVE-2018-1744305 Oct 2018
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateS
23RISK
open
Exploit-DB
Cisco Prime Infrastructure - (Unauthenticated) Remote Code Execution
CVE-2018-1537904 Oct 2018
Cisco Prime Infrastructure Arbitrary File Upload and Command Execution Vulnerability
60RISK
open
Exploit-DB
Airties AIR5342 1.0.0.18 - Cross-Site Scripting
CVE-2018-1758703 Oct 2018
AirTies Air 5750 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
23RISK
open
Exploit-DB
Airties AIR5342 1.0.0.18 - Cross-Site Scripting
CVE-2018-1758803 Oct 2018
AirTies Air 5021 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
23RISK
open
Exploit-DB
Airties AIR5342 1.0.0.18 - Cross-Site Scripting
CVE-2018-1759303 Oct 2018
AirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
23RISK
open
Exploit-DB
RICOH MP C1803 JPN Printer - Cross-Site Scripting
CVE-2018-1731003 Oct 2018
On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of add
23RISK
open
Exploit-DB
Airties AIR5342 1.0.0.18 - Cross-Site Scripting
CVE-2018-1759003 Oct 2018
AirTies Air 5442 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
23RISK
open
Exploit-DB
Airties AIR5342 1.0.0.18 - Cross-Site Scripting
CVE-2018-1759103 Oct 2018
AirTies Air 5343v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
23RISK
open
Exploit-DB
RICOH MP C1803 JPN Printer - Cross-Site Scripting
CVE-2018-1731303 Oct 2018
On the RICOH MP C307 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding a
23RISK
open
Exploit-DB
OPAC EasyWeb Five 5.7 - 'biblio' SQL Injection
CVE-2018-1742802 Oct 2018
An issue was discovered in OPAC EasyWeb Five 5.7. There is SQL injection via the w2001/index.php?scelta=campi biblio par
23RISK
open
Exploit-DB
Linux Kernel < 4.11.8 - 'mq_notify: double sock_put()' Local Privilege Escalation
CVE-2017-1117602 Oct 2018
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RISK
open
Exploit-DB
WUZHICMS 2.0 - Cross-Site Scripting
CVE-2018-1783201 Oct 2018
XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.
23RISK
open
Exploit-DB
Zahir Enterprise Plus 6 build 10b - Buffer Overflow (SEH)
CVE-2018-1740801 Oct 2018
Stack-based buffer overflows in Zahir Accounting Enterprise Plus 6 through build 10b allow remote attackers to execute a
43RISK
open
Exploit-DB
PCProtect 4.8.35 - Privilege Escalation
CVE-2018-1777628 Sep 2018
PCProtect Anti-Virus v4.8.35 has "Everyone: (F)" permission for %PROGRAMFILES(X86)%\PCProtect, which allows local users
23RISK
open
Exploit-DB
Microsoft Edge - Sandbox Escape
CVE-2018-846827 Sep 2018
An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privil
28RISK
open
Exploit-DB
Microsoft Edge - Sandbox Escape
CVE-2018-846327 Sep 2018
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppCont
28RISK
open
Exploit-DB
Microsoft Edge - Sandbox Escape
CVE-2018-846927 Sep 2018
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppCont
28RISK
open
Exploit-DB
EE 4GEE Mini EE40_00_02.00_44 - Privilege Escalation
CVE-2018-1432727 Sep 2018
The installer for the Alcatel OSPREY3_MINI Modem component on EE EE40VB 4G mobile broadband modems with firmware before
23RISK
open
Exploit-DB
Rausoft ID.prove 2.95 - 'Username' SQL injection
CVE-2018-1665927 Sep 2018
An issue was discovered in Rausoft ID.prove 2.95. The login page allows SQL injection via Microsoft SQL Server stacked q
23RISK
open
Exploit-DB
Linux Kernel 2.6.x / 3.10.x / 4.14.x (RedHat / Debian / CentOS) (x64) - 'Mutagen Astronomy' Local Privilege Escalation
CVE-2018-14634HIGHunder attack26 Sep 2018
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with a
76RISK
open
Exploit-DB
Linux Kernel - VMA Use-After-Free via Buggy vmacache_flush_all() Fastpath Local Privilege Escalation
CVE-2018-1718226 Sep 2018
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RISK
open
Exploit-DB
WebKit - 'WebCore::RenderLayer::updateDescendantDependentFlags' Use-After-Free
CVE-2018-431725 Sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISK
open
Exploit-DB
Joomla! Component AlphaIndex Dictionaries 1.0 - SQL Injection
CVE-2018-1739725 Sep 2018
SQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter.
23RISK
open
Exploit-DB
Solaris - 'EXTREMEPARR' dtappgather Privilege Escalation (Metasploit)
CVE-2017-362225 Sep 2018
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Common Desktop Environment (C
38RISK
open
Exploit-DB
WebKit - 'WebCore::SVGAnimateElementBase::resetAnimatedType' Use-After-Free
CVE-2018-431425 Sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
28RISK
open
Exploit-DB
Joomla! Component Social Factory 3.8.3 - SQL Injection
CVE-2018-1738525 Sep 2018
SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radiu
23RISK
open
Exploit-DB
Joomla! Component Timetable Schedule 3.6.8 - SQL Injection
CVE-2018-1739425 Sep 2018
SQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter.
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.