Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,596cataloged exploits
36,656CVEs with public exploitation
24,695lab-tested
79,596 exploits
GitHub PoC
Just My ports of CVE-2017-8759
CVE-2017-8759HIGHunder attack11 Dec 2018
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RISK
open
Exploit-DB
PrestaShop 1.6.x/1.7.x - Remote Code Execution
CVE-2018-19126webappsphp11 Dec 2018
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file u
28RISK
open
Exploit-DB
DomainMOD 4.11.01 - Cross-Site Scripting
CVE-2018-19913webappsphp11 Dec 2018
DomainMOD through 4.11.01 has XSS via the assets/add/registrar-accounts.php UserName, Reseller ID, or notes field.
23RISK
open
Exploit-DB
TP-Link wireless router Archer C1200 - Cross-Site Scripting
CVE-2018-13134webappshardware11 Dec 2018
TP-Link Archer C1200 1.13 Build 2018/01/24 rel.52299 EU devices have XSS via the PATH_INFO to the /webpages/data URI.
23RISK
open
Exploit-DBVexDay Proof
ZTE ZXHN H168N - Improper Access Restrictions
CVE-2018-7357MEDIUMwebappshardware11 Dec 2018
ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper acc
55RISK
open
Exploit-DBVexDay Proof
McAfee True Key - McAfee.TrueKey.Service Privilege Escalation
CVE-2018-6757HIGHlocalwindows11 Dec 2018
True Key (TK) Windows Client - Privilege Escalation vulnerability
41RISK
open
Exploit-DBVexDay Proof
McAfee True Key - McAfee.TrueKey.Service Privilege Escalation
CVE-2018-6755HIGHlocalwindows11 Dec 2018
True Key (TK) Windows Client - Weak Directory Permission Vulnerability
41RISK
open
VulnCheck XDB
client-side
CVE-2018-15982HIGHunder attackransomware11 Dec 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISK
open
Exploit-DBVexDay Proof
ZTE ZXHN H168N - Improper Access Restrictions
CVE-2018-7358MEDIUMwebappshardware11 Dec 2018
ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper cha
55RISK
open
GitHub PoC4
个人整理的Centos7.x + Kubernetes-1.12.3 + Dashboard-1.8.3 无 CVE-2018-1002105 漏洞的master节点全自动快速一键安装部署文件,适用于测试环境,生产环境的快速安装部署
CVE-2018-1002105CRITICAL10 Dec 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISK
open
Exploit-DB
Kubernetes - (Authenticated) Arbitrary Requests
CVE-2018-1002105CRITICALremotemultiple10 Dec 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISK
open
VulnCheck XDB
client-side
CVE-2018-15982HIGHunder attackransomware10 Dec 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISK
open
GitHub PoC
Microsoft Equation 3.0/Convert python2 to python3
CVE-2017-11882HIGHunder attackransomware10 Dec 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC1
CVE-2014-0160
CVE-2014-0160HIGHunder attack10 Dec 2018
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
Metasploit600
ThinkPHP Multiple PHP Injection RCEs
CVE-2019-9082HIGHunder attack10 Dec 2018
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public/
100RISK
open
Metasploit600
ThinkPHP Multiple PHP Injection RCEs
CVE-2018-20062CRITICALunder attack10 Dec 2018
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RISK
open
GitHub PoC179
exp of CVE-2018-15982
CVE-2018-15982HIGHunder attackransomware10 Dec 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISK
open
Exploit-DB
Kubernetes - (Unauthenticated) Arbitrary Requests
CVE-2018-1002105CRITICALremotemultiple10 Dec 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISK
open
VulnCheck XDB
client-side
CVE-2017-11882HIGHunder attackransomware10 Dec 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
Exploit-DB
Adiscon LogAnalyzer < 4.1.7 - Cross-Site Scripting
CVE-2018-19877webappsphp09 Dec 2018
login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field.
43RISK
open
GitHub PoC2
Proof of consept for CVE-2018-17431
CVE-2018-1743108 Dec 2018
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RISK
open
VulnCheck XDB
initial-access
CVE-2018-1743108 Dec 2018
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RISK
open
Metasploit600
Cisco Prime Infrastructure Runrshell Privilege Escalation
CVE-2018-15439CRITICAL08 Dec 2018
Cisco Small Business Switches Privileged Access Vulnerability
55RISK
open
GitHub PoC223
PoC for CVE-2018-1002105.
CVE-2018-1002105CRITICAL06 Dec 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISK
open
GitHub PoC13
CVE-2018-15982_PoC
CVE-2018-15982HIGHunder attackransomware06 Dec 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISK
open
VulnCheck XDB
initial-access
CVE-2018-15961CRITICALunder attack06 Dec 2018
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISK
open
GitHub PoC9
Unrestricted file upload in Adobe ColdFusion
CVE-2018-15961CRITICALunder attack06 Dec 2018
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISK
open
GitHub PoC
Flash sources for CVE-2018-15982 used by NK
CVE-2018-15982HIGHunder attackransomware05 Dec 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RISK
open
GitHub PoC
uzzzval/cve-2004-2167
CVE-2004-216705 Dec 2018
Multiple buffer overflows in LaTeX2rtf 1.9.15, and possibly other versions, allow remote attackers to execute arbitrary
28RISK
open
GitHub PoC191
Test utility for cve-2018-1002105
CVE-2018-1002105CRITICAL05 Dec 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISK
open
previouspage 865 / 2,654next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.