Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
22,786 exploits
Exploit-DB
Online Trade 1 - Information Disclosure
CVE-2018-1432827 Jul 2018
Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensiti
28RISK
open
Exploit-DB
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
CVE-2018-1066227 Jul 2018
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
60RISK
open
Exploit-DB
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
CVE-2018-1066127 Jul 2018
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
60RISK
open
Exploit-DB
SoftNAS Cloud < 4.0.3 - OS Command Injection
CVE-2018-1441727 Jul 2018
A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particul
45RISK
open
Exploit-DB
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
CVE-2018-1066027 Jul 2018
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
60RISK
open
Exploit-DB
Trivum Multiroom Setup Tool 8.76 - Corss-Site Request Forgery (Admin Bypass)
CVE-2018-1385926 Jul 2018
MusicCenter / Trivum Multiroom Setup Tool V8.76 - SNR 8604.26 - C4 Professional before V9.34 build 13381 - 12.07.18, all
28RISK
open
Exploit-DB
GetGo Download Manager 6.2.1.3200 - Denial of Service (PoC)
CVE-2017-1784925 Jul 2018
A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to exec
28RISK
open
Exploit-DB
Micro Focus Secure Messaging Gateway (SMG) < 471 - Remote Code Execution (Metasploit)
CVE-2018-12464CRITICAL24 Jul 2018
Unauthenticated SQL injection in Micro Focus Secure Messaging Gateway
85RISK
open
Exploit-DB
Nagios Core 4.4.1 - Denial of Service
CVE-2018-1344124 Jul 2018
qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows atta
23RISK
open
Exploit-DB
Micro Focus Secure Messaging Gateway (SMG) < 471 - Remote Code Execution (Metasploit)
CVE-2018-12465CRITICAL24 Jul 2018
Remote Code Execution in Micro Focus Secure Messaging Gateway
85RISK
open
Exploit-DB
Nagios Core 4.4.1 - Denial of Service
CVE-2018-1345824 Jul 2018
qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to
23RISK
open
Exploit-DB
Nagios Core 4.4.1 - Denial of Service
CVE-2018-1345724 Jul 2018
qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to
23RISK
open
Exploit-DB
Davolink DVW 3200 Router - Password Disclosure
CVE-2018-1061823 Jul 2018
Davolink DVW-3200N all version prior to Version 1.00.06. The device generates a weak password hash that is easily cracke
28RISK
open
Exploit-DB
Tenda Wireless N150 Router 5.07.50 - Cross-Site Request Forgery (Reboot Router)
CVE-2015-599623 Jul 2018
Cross-site request forgery (CSRF) vulnerability on Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 allo
23RISK
open
Exploit-DB
Inteno’s IOPSYS - (Authenticated) Local Privilege Escalation
CVE-2018-1453321 Jul 2018
read_tmp and write_tmp in Inteno IOPSYS allow attackers to gain privileges after writing to /tmp/etc/smb.conf because /v
23RISK
open
Exploit-DB
Touchpad / Trivum WebTouch Setup 2.53 build 13163 - Authentication Bypass
CVE-2018-1386220 Jul 2018
Touchpad / Trivum WebTouch Setup V9 V2.53 build 13163 of Apr 6 2018 09:10:14 (FW 303) allow unauthorized remote attacker
35RISK
open
Exploit-DB
MSVOD 10 - 'cid' SQL Injection
CVE-2018-1441820 Jul 2018
In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.
23RISK
open
Exploit-DB
TP-Link TL-WR840N - Denial of Service
CVE-2018-1433620 Jul 2018
TP-Link WR840N devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets w
23RISK
open
Exploit-DB
Linux - BPF Sign Extension Local Privilege Escalation (Metasploit)
CVE-2017-1699519 Jul 2018
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
Exploit-DB
MyBB New Threads Plugin 1.1 - Cross-Site Scripting
CVE-2018-1439219 Jul 2018
The New Threads plugin before 1.2 for MyBB has XSS.
35RISK
open
Exploit-DB
WordPress Plugin All In One Favicon 4.6 - (Authenticated) Cross-Site Scripting
CVE-2018-1383219 Jul 2018
Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plu
23RISK
open
Exploit-DB
Open-AudIT Community 2.1.1 - Cross-Site Scripting
CVE-2018-1112418 Jul 2018
Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows
23RISK
open
Exploit-DB
Nanopool Claymore Dual Miner - APIs Remote Code Execution (Metasploit)
CVE-2018-100004917 Jul 2018
Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner
60RISK
open
Exploit-DB
QNAP Q'Center - 'change_passwd' Command Execution (Metasploit)
CVE-2018-070617 Jul 2018
Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticate
50RISK
open
Exploit-DB
QNAP Q'Center - 'change_passwd' Command Execution (Metasploit)
CVE-2018-070717 Jul 2018
Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could
50RISK
open
Exploit-DB
Linux (Ubuntu) - Other Users coredumps Can Be Read via setgid Directory and killpriv Bypass
CVE-2018-1340516 Jul 2018
The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an
23RISK
open
Exploit-DB
VelotiSmart WiFi B-380 Camera - Directory Traversal
CVE-2018-1406416 Jul 2018
The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../..
50RISK
open
Exploit-DB
PrestaShop < 1.6.1.19 - 'BlowFish ECD' Privilege Escalation
CVE-2018-1378416 Jul 2018
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfi
28RISK
open
Exploit-DB
Fortify Software Security Center (SSC) 17.x/18.1 - XML External Entity Injection
CVE-2018-12463HIGH16 Jul 2018
MFSBGN03811 rev.1 - Fortify Software Security Center (SSC), Multiple vulnerabilities
46RISK
open
Exploit-DB
PrestaShop < 1.6.1.19 - 'AES CBC' Privilege Escalation
CVE-2018-1378416 Jul 2018
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfi
28RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.