Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,697cataloged exploits
36,715CVEs with public exploitation
24,695lab-tested
79,697 exploits
Metasploit300
Microsoft Windows ALPC Task Scheduler Local Privilege Elevation
CVE-2018-8440HIGHunder attackransomware27 Aug 2018
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
91RISK
open
Exploit-DBVexDay Proof
HP Jetdirect - Path Traversal Arbitrary Code Execution (Metasploit)
CVE-2017-2741remoteunix27 Aug 2018
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmwa
60RISK
open
Exploit-DB
Gleez CMS 1.2.0 - Cross-Site Request Forgery (Add Admin)
CVE-2018-15845webappsphp27 Aug 2018
There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add.
23RISK
open
Exploit-DBVexDay Proof
WordPress Plugin Plainview Activity Monitor 20161228 - (Authenticated) Command Injection
CVE-2018-15877webappsphp27 Aug 2018
The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell meta
60RISK
open
Exploit-DBVexDay Proof
Foxit PDF Reader 9.0.1.1049 - Pointer Overwrite Use-After-Free (Metasploit)
CVE-2018-9948localwindows27 Aug 2018
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RISK
open
Exploit-DBVexDay Proof
Foxit PDF Reader 9.0.1.1049 - Pointer Overwrite Use-After-Free (Metasploit)
CVE-2018-9958localwindows27 Aug 2018
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1
50RISK
open
VulnCheck XDB
initial-access
CVE-2018-11776HIGHunder attack27 Aug 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
Exploit-DBVexDay Proof
Electron WebPreferences - Remote Code Execution
CVE-2018-15685remotemultiple27 Aug 2018
GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindow
28RISK
open
GitHub PoC21
Proof of Concept for CVE-2018-11776
CVE-2018-11776HIGHunder attack27 Aug 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
Exploit-DB
RICOH MP C4504ex Printer - Cross-Site Request Forgery (Add Admin)
CVE-2018-15884webappshardware27 Aug 2018
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
23RISK
open
Exploit-DBVexDay Proof
Responsive FileManager < 9.13.4 - Directory Traversal
CVE-2018-15536webappsphp27 Aug 2018
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in arc
23RISK
open
Exploit-DB
Apache Struts 2.3 < 2.3.34 / 2.5 < 2.5.16 - Remote Code Execution (1)
CVE-2018-11776HIGHunder attackremotelinux26 Aug 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
Exploit-DB
ManageEngine ADManager Plus 6.5.7 - Cross-Site Scripting
CVE-2018-15740webappswindows_x86-6426 Aug 2018
Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.
23RISK
open
Metasploit600
Wordpress Plainview Activity Monitor RCE
CVE-2018-1587726 Aug 2018
The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell meta
60RISK
open
VulnCheck XDB
initial-access
CVE-2018-11776HIGHunder attack25 Aug 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-11776HIGHunder attack25 Aug 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-11776HIGHunder attack25 Aug 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
Exploit-DB
ManageEngine ADManager Plus 6.5.7 - HTML Injection
CVE-2018-15608webappswindows25 Aug 2018
Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.
23RISK
open
GitHub PoC3
moayadalmalat/CVE-2017-12636
CVE-2017-1263625 Aug 2018
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RISK
open
GitHub PoC303
An exploit for Apache Struts CVE-2018-11776
CVE-2018-11776HIGHunder attack25 Aug 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
GitHub PoC4
Environment for CVE-2018-11776 / S2-057 (Apache Struts 2)
CVE-2018-11776HIGHunder attack25 Aug 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
GitHub PoC12
Vulnerable docker container for CVE-2018-11776
CVE-2018-11776HIGHunder attack25 Aug 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
Exploit-DB
Apache Struts 2.3 < 2.3.34 / 2.5 < 2.5.16 - Remote Code Execution (2)
CVE-2018-11776HIGHunder attackremotemultiple25 Aug 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
GitHub PoC10
CVE-2018-11776(S2-057) EXPLOIT CODE
CVE-2018-11776HIGHunder attack24 Aug 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-11776HIGHunder attack24 Aug 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
GitHub PoC123
Working Python test and PoC for CVE-2018-11776, includes Docker lab
CVE-2018-11776HIGHunder attack24 Aug 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
VulnCheck XDB
client-side
CVE-2018-8414HIGHunder attack24 Aug 2018
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows
93RISK
open
VulnCheck XDB
initial-access
CVE-2018-11776HIGHunder attack24 Aug 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
GitHub PoC21
Simple poc of CVE-2018-8414 Windows Package Setting RCE Vulnerability
CVE-2018-8414HIGHunder attack24 Aug 2018
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows
93RISK
open
GitHub PoC15
Creating a vulnerable environment and the PoC
CVE-2018-11776HIGHunder attack23 Aug 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
previouspage 883 / 2,657next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.