Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,596cataloged exploits
36,656CVEs with public exploitation
24,695lab-tested
79,596 exploits
GitHub PoC
cve-2018-14667 demo
CVE-2018-14667CRITICALunder attack18 Nov 2018
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RISK
open
GitHub PoC83
Tool for CVE-2018-16323
CVE-2018-1632318 Nov 2018
ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that ha
35RISK
open
GitHub PoC3
CVE-2018-16509 (Ghostscript contains multiple -dSAFER sandbox bypass vulnerabilities)
CVE-2018-1650917 Nov 2018
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RISK
open
Exploit-DBVexDay Proof
Linux - Broken uid/gid Mapping for Nested User Namespaces
CVE-2018-18955locallinux16 Nov 2018
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISK
open
Exploit-DB
DomainMOD 4.11.01 - 'raid' Cross-Site Scripting
CVE-2018-19136webappsphp16 Nov 2018
DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter.
38RISK
open
GitHub PoC
Implementation of CVE-2018-10933 with CIDR block scanner
CVE-2018-10933CRITICAL16 Nov 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
Metasploit500
Linux Nested User Namespace idmap Limit Local Privilege Escalation
CVE-2018-1895515 Nov 2018
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISK
open
Exploit-DB
PHP-Proxy 5.1.0 - Local File Inclusion
CVE-2018-19246webappsphp15 Nov 2018
PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users w
28RISK
open
Exploit-DB
WordPress Plugin Ninja Forms 3.3.17 - Cross-Site Scripting
CVE-2018-19287webappsphp15 Nov 2018
XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes
38RISK
open
Exploit-DBVexDay Proof
Dell OpenManage Network Manager 6.2.0.51 SP3 - Multiple Vulnerabilities
CVE-2018-15767webappslinux14 Nov 2018
Improper Authorization Vulnerability
28RISK
open
Metasploit600
Nagios XI Magpie_debug.php Root Remote Code Execution
CVE-2018-1571014 Nov 2018
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.
50RISK
open
Exploit-DB
ntpd 4.2.8p10 - Out-of-Bounds Read (PoC)
CVE-2018-7182locallinux14 Nov 2018
The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-
28RISK
open
Metasploit600
Nagios XI Magpie_debug.php Root Remote Code Execution
CVE-2018-1570814 Nov 2018
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP r
60RISK
open
Exploit-DBVexDay Proof
Dell OpenManage Network Manager 6.2.0.51 SP3 - Multiple Vulnerabilities
CVE-2018-15768webappslinux14 Nov 2018
Insecure MySQL Configuration Vulnerability
23RISK
open
Exploit-DB
Advanced Comment System 1.0 - SQL Injection
CVE-2018-18619webappsphp14 Nov 2018
internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability bec
23RISK
open
Exploit-DB
SwitchVPN for macOS 2.1012.03 - Privilege Escalation
CVE-2018-18860localmacos14 Nov 2018
A local privilege escalation vulnerability has been identified in the SwitchVPN client 2.1012.03 for macOS. Due to over-
23RISK
open
Exploit-DB
CentOS Web Panel 0.9.8.740 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2018-18772webappsphp13 Nov 2018
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as dem
23RISK
open
Exploit-DBVexDay Proof
Evince 3.24.0 - Command Injection
CVE-2017-1000083doslinux13 Nov 2018
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to e
50RISK
open
Exploit-DB
CentOS Web Panel 0.9.8.740 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2018-18773webappsphp13 Nov 2018
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demo
23RISK
open
Exploit-DB
CentOS Web Panel 0.9.8.740 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2018-18774webappsphp13 Nov 2018
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter.
23RISK
open
Exploit-DBVexDay Proof
Cisco Immunet < 6.2.0 / Cisco AMP For Endpoints 6.2.0 - Denial of Service
CVE-2018-15437MEDIUMdoswindows13 Nov 2018
Cisco Immunet and Cisco AMP for Endpoints System Scan Denial of Service Vulnerability
33RISK
open
Exploit-DB
ClipperCMS 1.3.3 - Cross-Site Request Forgery (File Upload)
CVE-2018-19135webappsphp13 Nov 2018
ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an
23RISK
open
Metasploit400
Redis Replication Code Execution
CVE-2018-1121813 Nov 2018
Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10,
30RISK
open
Exploit-DB
xorg-x11-server < 1.20.1 - Local Privilege Escalation
CVE-2018-14665locallinux13 Nov 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RISK
open
GitHub PoC
My first try to code my own LPE exploit.
CVE-2017-1117613 Nov 2018
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RISK
open
Exploit-DB
WordPress Plugin Media File Manager 1.4.2 - Directory Traversal / Cross-Site Scripting
CVE-2018-19042webappsphp12 Nov 2018
The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the di
28RISK
open
Exploit-DB
WordPress Plugin Media File Manager 1.4.2 - Directory Traversal / Cross-Site Scripting
CVE-2018-19041webappsphp12 Nov 2018
The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the
23RISK
open
Exploit-DB
WordPress Plugin Media File Manager 1.4.2 - Directory Traversal / Cross-Site Scripting
CVE-2018-19043webappsphp12 Nov 2018
The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename)
28RISK
open
Exploit-DB
WordPress Plugin Media File Manager 1.4.2 - Directory Traversal / Cross-Site Scripting
CVE-2018-19040webappsphp12 Nov 2018
The Media File Manager plugin 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir para
28RISK
open
GitHub PoC9
CVE-2016-4657 web-kit vulnerability for ios 9.3, nintendo switch browser vulnerability
CVE-2016-4657HIGHunder attack11 Nov 2018
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RISK
open
previouspage 868 / 2,654next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.