Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,622cataloged exploits
36,681CVEs with public exploitation
24,695lab-tested
79,596 exploits
VulnCheck XDB
client-side
CVE-2016-4657HIGHunder attack11 Nov 2018
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RISK
open
GitHub PoC
Setup, exploit and patch for CVE-2009-4092 Simplog CSRF
CVE-2009-409210 Nov 2018
Cross-site request forgery (CSRF) vulnerability in user.php in Simplog 0.9.3.2, and possibly earlier, allows remote atta
23RISK
open
GitHub PoC1
Wordpress plugin Site-Editor v1.1.1 LFI exploit
CVE-2018-742209 Nov 2018
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RISK
open
GitHub PoC10
PHPMyAdmin v4.8.0 and v.4.8.1 LFI exploit
CVE-2018-1261309 Nov 2018
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open
VulnCheck XDB
initial-access
CVE-2018-742209 Nov 2018
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RISK
open
GitHub PoC5
CMS Made Simple 2.2.7 RCE exploit
CVE-2018-1051709 Nov 2018
In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code ex
28RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2018-1261309 Nov 2018
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open
GitHub PoC3
beraphin/CVE-2018-6789
CVE-2018-6789CRITICALunder attackransomware08 Nov 2018
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2014-0160HIGHunder attack08 Nov 2018
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-6789CRITICALunder attackransomware08 Nov 2018
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISK
open
GitHub PoC
matlink/CVE-2018-17456
CVE-2018-1745608 Nov 2018
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RISK
open
Metasploit300
WordPress WP GDPR Compliance Plugin Privilege Escalation
CVE-2018-1920708 Nov 2018
The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to exe
60RISK
open
GitHub PoC
来自:https://www.freebuf.com/articles/web/31700.html
CVE-2014-0160HIGHunder attack08 Nov 2018
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
Exploit-DB
OpenSLP 2.0.0 - Multiple Vulnerabilities
CVE-2016-7567locallinux07 Nov 2018
Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have
28RISK
open
Exploit-DBVexDay Proof
FaceTime - RTP Video Processing Heap Corruption
CVE-2018-4384dosios06 Nov 2018
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1,
23RISK
open
Exploit-DBVexDay Proof
FaceTime - 'VCPDecompressionDecodeFrame' Memory Corruption
CVE-2018-4366dosmacos06 Nov 2018
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.
23RISK
open
Exploit-DBVexDay Proof
FaceTime - 'readSPSandGetDecoderParams' Stack Corruption
CVE-2018-4367dosmacos06 Nov 2018
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.
23RISK
open
Exploit-DB
libiec61850 1.3 - Stack Based Buffer Overflow
CVE-2018-18957locallinux06 Nov 2018
An issue has been found in libIEC61850 v1.3. It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_pu
28RISK
open
Exploit-DBVexDay Proof
blueimp's jQuery 9.22.0 - (Arbitrary) File Upload (Metasploit)
CVE-2018-9206remotephp06 Nov 2018
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISK
open
VulnCheck XDB
local
CVE-2020-3950HIGHunder attack06 Nov 2018
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for
86RISK
open
Exploit-DB
CMS Made Simple 2.2.7 - (Authenticated) Remote Code Execution
CVE-2018-10517webappsphp06 Nov 2018
In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code ex
28RISK
open
GitHub PoC14
Exploit for PlaySMS 1.4 authenticated RCE
CVE-2017-910106 Nov 2018
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack06 Nov 2018
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC21
an RCE (remote command execution) approach of CVE-2018-7750
CVE-2018-775006 Nov 2018
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x
28RISK
open
Metasploit500
VyOS restricted-shell Escape and Privilege Escalation
CVE-2018-1855605 Nov 2018
A privilege escalation issue was discovered in VyOS 1.1.8. The default configuration also allows operator users to execu
23RISK
open
Exploit-DB
PHP Proxy 3.0.3 - Local File Inclusion
CVE-2018-19458webappsphp05 Nov 2018
In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI UR
50RISK
open
Exploit-DB
LiquidVPN 1.36 / 1.37 - Privilege Escalation
CVE-2018-18858localmacos05 Nov 2018
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RISK
open
Exploit-DB
LiquidVPN 1.36 / 1.37 - Privilege Escalation
CVE-2018-18856localmacos05 Nov 2018
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RISK
open
Exploit-DB
Advantech WebAccess SCADA 8.3.2 - Remote Code Execution
CVE-2018-15707webappsasp05 Nov 2018
Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could
23RISK
open
Exploit-DB
Advantech WebAccess SCADA 8.3.2 - Remote Code Execution
CVE-2018-15705webappsasp05 Nov 2018
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any f
28RISK
open
previouspage 869 / 2,654next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.