Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
79,386 exploits
Exploit-DBVexDay Proof
Netatalk 3.1.12 - Authentication Bypass
CVE-2018-1160CRITICALremotemultiple21 Dec 2018
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking
70RISK
open
Exploit-DBVexDay Proof
VBScript - VbsErase Reference Leak Use-After-Free
CVE-2018-8625doswindows20 Dec 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
35RISK
open
VulnCheck XDB
client-side
CVE-2017-10271HIGHunder attackransomware20 Dec 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC
Weblogic(CVE-2017-10271)
CVE-2017-10271HIGHunder attackransomware20 Dec 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
VulnCheck XDB
client-side
CVE-2015-925120 Dec 2018
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed wi
28RISK
open
GitHub PoC5
Flash 2018-15982 UAF
CVE-2018-15982HIGHunder attackransomware20 Dec 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISK
open
Exploit-DBVexDay Proof
VBScript - MSXML Execution Policy Bypass
CVE-2018-8619doswindows20 Dec 2018
A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly rest
35RISK
open
GitHub PoC
https://github.com/milo2012/CVE-2018-0296.git
CVE-2018-0296HIGHunder attack19 Dec 2018
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RISK
open
Metasploit600
Mailcleaner Remote Code Execution
CVE-2018-2032319 Dec 2018
www/soap/application/MCSoap/Logs.php in MailCleaner Community Edition 2018.08 allows remote attackers to execute arbitra
30RISK
open
GitHub PoC6
LibSSH Authentication Bypass CVE-2018-10933
CVE-2018-10933CRITICAL19 Dec 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC
qiantu88/CVE-2017-12617
CVE-2017-12617HIGHunder attack19 Dec 2018
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISK
open
GitHub PoC
CVE-2003-0264 - SLMail 5.5 POP3 'PASS' Remote Buffer Overflow Vulnerability. Tested on Windows XP Professional SP3.
CVE-2003-026419 Dec 2018
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RISK
open
VulnCheck XDB
initial-access
CVE-2017-12617HIGHunder attack19 Dec 2018
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-0296HIGHunder attack19 Dec 2018
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RISK
open
GitHub PoC
CVE-2012-5106 - Freefloat FTP Server Buffer Overflow Vulnerability. Tested on Windows XP Professional SP3.
CVE-2012-510619 Dec 2018
Stack-based buffer overflow in FreeFloat FTP Server 1.0 allows remote authenticated users to execute arbitrary code via
28RISK
open
GitHub PoC
CVE-2004-2271 - Minishare 1.4.1 HTTP Server Remote Buffer Overflow Vulnerability. Tested on Windows XP Professional SP3.
CVE-2004-227119 Dec 2018
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET req
60RISK
open
Exploit-DB
Linux Kernel 4.4 - 'rtnetlink' Stack Memory Disclosure
CVE-2016-4486locallinux19 Dec 2018
The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain
23RISK
open
Exploit-DB
Yeswiki Cercopitheque - 'id' SQL Injection
CVE-2018-13045webappsphp19 Dec 2018
SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to ex
23RISK
open
Exploit-DB
Integria IMS 5.0.83 - 'search_string' Cross-Site Scripting
CVE-2018-19828webappsphp19 Dec 2018
Artica Integria IMS 5.0.83 has XSS via the search_string parameter.
23RISK
open
Exploit-DB
Bolt CMS < 3.6.2 - Cross-Site Scripting
CVE-2018-19933webappsphp19 Dec 2018
Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and Ne
23RISK
open
GitHub PoC
qiantu88/CVE-2018-8120
CVE-2018-8120HIGHunder attackransomware19 Dec 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
Exploit-DBVexDay Proof
IBM Operational Decision Manager 8.x - XML External Entity Injection
CVE-2018-1821HIGHwebappsmultiple19 Dec 2018
IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) a
46RISK
open
GitHub PoC
CVE-2007-1567 - WarFTP 1.65 'USER' Remote Buffer Overflow Vulnerability. Tested on Windows XP Professional SP3.
CVE-2007-156719 Dec 2018
Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of s
35RISK
open
GitHub PoC
Yable/CVE-2018-4878
CVE-2018-4878HIGHunder attackransomware19 Dec 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISK
open
Exploit-DB
Integria IMS 5.0.83 - Cross-Site Request Forgery
CVE-2018-19829webappsphp19 Dec 2018
Artica Integria IMS 5.0.83 has CSRF in godmode/usuarios/lista_usuarios, resulting in the ability to delete an arbitrary
23RISK
open
Exploit-DB
MiniShare 1.4.1 - 'HEAD/POST' Remote Buffer Overflow
CVE-2018-19861remotewindows18 Dec 2018
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD re
28RISK
open
Exploit-DB
MiniShare 1.4.1 - 'HEAD/POST' Remote Buffer Overflow
CVE-2018-19862remotewindows18 Dec 2018
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST re
28RISK
open
Exploit-DB
SDL Web Content Manager 8.5.0 - XML External Entity Injection
CVE-2018-19371webappsxml18 Dec 2018
The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive
23RISK
open
GitHub PoC85
An implementation of CVE-2009-0689 for the Nintendo Wii.
CVE-2009-068918 Dec 2018
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'jscript!JsArrayFunctionHeapSort' Out-of-Bounds Write
CVE-2018-8631doswindows18 Dec 2018
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet
35RISK
open
previouspage 860 / 2,647next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.