Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,660cataloged exploits
36,715CVEs with public exploitation
24,695lab-tested
79,596 exploits
Metasploit500
VyOS restricted-shell Escape and Privilege Escalation
CVE-2018-1855605 Nov 2018
A privilege escalation issue was discovered in VyOS 1.1.8. The default configuration also allows operator users to execu
23RISK
open
Exploit-DB
Advantech WebAccess SCADA 8.3.2 - Remote Code Execution
CVE-2018-15705webappsasp05 Nov 2018
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any f
28RISK
open
Exploit-DB
Royal TS/X - Information Disclosure
CVE-2018-18865webappsjson05 Nov 2018
The Royal browser extensions TS before 4.3.60728 (Release Date 2018-07-28) and TSX before 3.3.1 (Release Date 2018-09-13
23RISK
open
Metasploit600
Intelliants Subrion CMS 4.2.1 - Authenticated File Upload Bypass to RCE
CVE-2018-1942204 Nov 2018
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca
50RISK
open
Exploit-DB
Intel (Skylake / Kaby Lake) - 'PortSmash' CPU SMT Side-Channel
CVE-2018-5407localhardware02 Nov 2018
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks
23RISK
open
GitHub PoC
bolonobolo/CVE-2018-14665
CVE-2018-1466502 Nov 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RISK
open
GitHub PoC2
matlink/CVE-2018-17961
CVE-2018-1796101 Nov 2018
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving err
23RISK
open
Metasploit400
Reliable Datagram Sockets (RDS) rds_atomic_free_op NULL pointer dereference Privilege Escalation
CVE-2018-533301 Nov 2018
In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning
38RISK
open
Metasploit400
Reliable Datagram Sockets (RDS) rds_atomic_free_op NULL pointer dereference Privilege Escalation
CVE-2019-921301 Nov 2018
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which make
38RISK
open
GitHub PoC80
CVE-2018-8440 standalone exploit
CVE-2018-8440HIGHunder attackransomware31 Oct 2018
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
91RISK
open
GitHub PoC2
Fully functional script for brute forcing SSH and trying credentials - CVE-2018-15473
CVE-2018-15473MEDIUM31 Oct 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
VulnCheck XDB
local
CVE-2018-8440HIGHunder attackransomware31 Oct 2018
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
91RISK
open
GitHub PoC10
CVE-2018-2628漏洞工具包
CVE-2018-2628CRITICALunder attack30 Oct 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
Exploit-DB
Microstrategy Web 7 - Cross-Site Scripting / Directory Traversal
CVE-2018-18776webappsjsp30 Oct 2018
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (
23RISK
open
Exploit-DB
Microstrategy Web 7 - Cross-Site Scripting / Directory Traversal
CVE-2018-18777webappsjsp30 Oct 2018
Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subp
43RISK
open
Exploit-DB
xorg-x11-server 1.20.3 - Privilege Escalation
CVE-2018-14665localopenbsd30 Oct 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RISK
open
GitHub PoC
matlink/cve-2017-1000083-atril-nautilus
CVE-2017-100008330 Oct 2018
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to e
50RISK
open
GitHub PoC
matlink/evince-cve-2017-1000083
CVE-2017-100008330 Oct 2018
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to e
50RISK
open
Exploit-DB
Microstrategy Web 7 - Cross-Site Scripting / Directory Traversal
CVE-2018-18775webappsjsp30 Oct 2018
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (
38RISK
open
Exploit-DB
SaltOS Erp Crm 3.1 r8126 - SQL Injection
CVE-2018-18761webappsphp29 Oct 2018
SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection.
28RISK
open
Exploit-DB
Point of Sales (POS) in VB.Net MySQL Database 1.0 - SQL Injection
CVE-2018-18805webappsphp29 Oct 2018
Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb.
23RISK
open
GitHub PoC1
kastellanos/CVE-2018-7602
CVE-2018-7602CRITICALunder attackransomware29 Oct 2018
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RISK
open
Exploit-DBVexDay Proof
systemd - 'chown_one()' Dereference Symlinks
CVE-2018-15687HIGHlocallinux29 Oct 2018
systemd: chown_one() can dereference symlinks
41RISK
open
Exploit-DBVexDay Proof
systemd - 'reexec' State Injection
CVE-2018-15686HIGHdoslinux29 Oct 2018
systemd: reexec state injection: fgets() on overlong lines leads to line splitting
41RISK
open
Exploit-DB
SaltOS Erp Crm 3.1 r8126 - SQL Injection (2)
CVE-2018-18763webappsphp29 Oct 2018
SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection.
23RISK
open
Exploit-DB
SaltOS Erp Crm 3.1 r8126 - Database File Download
CVE-2018-18762webappsphp29 Oct 2018
SaltOS 3.1 r8126 contains a database download vulnerability.
23RISK
open
Exploit-DB
School Event Management System 1.0 - Arbitrary File Upload
CVE-2018-18793webappsphp29 Oct 2018
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
23RISK
open
Exploit-DB
K-iwi Framework 1775 - SQL Injection
CVE-2018-18755webappsphp29 Oct 2018
K-iwi Framework 1775 has SQL Injection via the admin/user/group/update user_group_id parameter or the admin/user/user/up
23RISK
open
Exploit-DB
School Attendance Monitoring System 1.0 - SQL Injection
CVE-2018-18798webappsphp29 Oct 2018
Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.ph
23RISK
open
Exploit-DB
Bakeshop Inventory System in VB.Net and MS Access Database 1.0 - SQL Injection
CVE-2018-18804webappsphp29 Oct 2018
Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb.
23RISK
open
previouspage 870 / 2,654next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.