Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,697cataloged exploits
36,715CVEs with public exploitation
24,695lab-tested
79,697 exploits
GitHub PoC26
lexfo/cve-2017-11176
CVE-2017-1117602 Oct 2018
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RISK
open
GitHub PoC4
MASS Exploiter
CVE-2018-7600CRITICALunder attackransomware02 Oct 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-14847CRITICALunder attack02 Oct 2018
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open
Exploit-DB
Linux Kernel < 4.11.8 - 'mq_notify: double sock_put()' Local Privilege Escalation
CVE-2017-11176locallinux02 Oct 2018
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RISK
open
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALunder attackransomware02 Oct 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
Exploit-DB
Zahir Enterprise Plus 6 build 10b - Buffer Overflow (SEH)
CVE-2018-17408localwindows_x8601 Oct 2018
Stack-based buffer overflows in Zahir Accounting Enterprise Plus 6 through build 10b allow remote attackers to execute a
43RISK
open
GitHub PoC
likekabin/CVE-2018-17182
CVE-2018-1718201 Oct 2018
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RISK
open
GitHub PoC1
likekabin/vmacache_CVE-2018-17182
CVE-2018-1718201 Oct 2018
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RISK
open
Exploit-DB
WUZHICMS 2.0 - Cross-Site Scripting
CVE-2018-17832webappsphp01 Oct 2018
XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.
23RISK
open
GitHub PoC130
Linux 内核VMA-UAF 提权漏洞(CVE-2018-17182),0day
CVE-2018-1718229 Sep 2018
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RISK
open
Metasploit300
Zahir Enterprise Plus 6 Stack Buffer Overflow
CVE-2018-1740828 Sep 2018
Stack-based buffer overflows in Zahir Accounting Enterprise Plus 6 through build 10b allow remote attackers to execute a
43RISK
open
Exploit-DBVexDay Proof
PCProtect 4.8.35 - Privilege Escalation
CVE-2018-17776localwindows_x86-6428 Sep 2018
PCProtect Anti-Virus v4.8.35 has "Everyone: (F)" permission for %PROGRAMFILES(X86)%\PCProtect, which allows local users
23RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - Sandbox Escape
CVE-2018-8469remotewindows27 Sep 2018
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppCont
28RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - Sandbox Escape
CVE-2018-8468remotewindows27 Sep 2018
An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privil
28RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - Sandbox Escape
CVE-2018-8463remotewindows27 Sep 2018
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppCont
28RISK
open
Exploit-DB
Rausoft ID.prove 2.95 - 'Username' SQL injection
CVE-2018-16659webappswindows_x86-6427 Sep 2018
An issue was discovered in Rausoft ID.prove 2.95. The login page allows SQL injection via Microsoft SQL Server stacked q
23RISK
open
Exploit-DB
EE 4GEE Mini EE40_00_02.00_44 - Privilege Escalation
CVE-2018-14327localwindows27 Sep 2018
The installer for the Alcatel OSPREY3_MINI Modem component on EE EE40VB 4G mobile broadband modems with firmware before
23RISK
open
VulnCheck XDB
local
CVE-2014-3153HIGHunder attack27 Sep 2018
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISK
open
GitHub PoC20
Gain root privilege by exploiting CVE-2014-3153 vulnerability
CVE-2014-3153HIGHunder attack27 Sep 2018
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISK
open
GitHub PoC
Make CVE-2007-4607 exploitable again!
CVE-2007-460727 Sep 2018
Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used
50RISK
open
Metasploit600
Navigate CMS Unauthenticated Remote Code Execution
CVE-2018-1755326 Sep 2018
An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs N
60RISK
open
Metasploit600
Navigate CMS Unauthenticated Remote Code Execution
CVE-2018-1755226 Sep 2018
SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigat
60RISK
open
GitHub PoC
bkhablenko/CVE-2017-8046
CVE-2017-804626 Sep 2018
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISK
open
Exploit-DBVexDay Proof
Linux Kernel - VMA Use-After-Free via Buggy vmacache_flush_all() Fastpath Local Privilege Escalation
CVE-2018-17182locallinux26 Sep 2018
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RISK
open
Exploit-DB
Linux Kernel 2.6.x / 3.10.x / 4.14.x (RedHat / Debian / CentOS) (x64) - 'Mutagen Astronomy' Local Privilege Escalation
CVE-2018-14634HIGHunder attacklocallinux_x86-6426 Sep 2018
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with a
76RISK
open
GitHub PoC1
cscli/CVE-2017-5223
CVE-2017-522326 Sep 2018
An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML docume
23RISK
open
VulnCheck XDB
initial-access
CVE-2017-804626 Sep 2018
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::SVGTextLayoutAttributes::context' Use-After-Free
CVE-2018-4318dosmultiple25 Sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISK
open
Exploit-DB
Joomla! Component Timetable Schedule 3.6.8 - SQL Injection
CVE-2018-17394webappsphp25 Sep 2018
SQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter.
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::SVGTRefElement::updateReferencedText' Use-After-Free
CVE-2018-4315dosmultiple25 Sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RISK
open
previouspage 878 / 2,657next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.