Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
22,786 exploits
Exploit-DB
HPE iMC 7.3 - Remote Code Execution (Metasploit)
CVE-2017-1250018 May 2018
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found
28RISK
open
Exploit-DB
Microsoft Edge Chakra JIT - Bound Check Elimination Bug
CVE-2018-098018 May 2018
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RISK
open
Exploit-DB
HPE iMC 7.3 - Remote Code Execution (Metasploit)
CVE-2017-898218 May 2018
A Remote Authentication Restriction Bypass vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E05
28RISK
open
Exploit-DB
Jenkins CLI - HTTP Java Deserialization (Metasploit)
CVE-2016-929917 May 2018
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a
60RISK
open
Exploit-DB
Nanopool Claymore Dual Miner 7.3 - Remote Code Execution
CVE-2018-100004917 May 2018
Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner
60RISK
open
Exploit-DB
Intelbras NCLOUD 300 1.0 - Authentication bypass
CVE-2018-1109417 May 2018
An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/Rebo
35RISK
open
Exploit-DB
Apache Struts 2 - Struts 1 Plugin Showcase OGNL Code Execution (Metasploit)
CVE-2017-9791CRITICALunder attack17 May 2018
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RISK
open
Exploit-DB
Powerlogic/Schneider Electric IONXXXX Series - Cross-Site Request Forgery
CVE-2016-580917 May 2018
An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series
23RISK
open
Exploit-DB
VirtueMart 3.1.14 - Persistent Cross-Site Scripting
CVE-2018-746516 May 2018
An XSS issue was discovered in VirtueMart before 3.2.14. All the textareas in the backend of the plugin can be closed by
23RISK
open
Exploit-DB
RSA Authentication Manager 8.2.1.4.0-build1394922 / < 8.3 P1 - XML External Entity Injection / Cross-Site Flashing / DOM Cross-Site Scripting
CVE-2018-124716 May 2018
RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability
28RISK
open
Exploit-DB
totemomail Encryption Gateway 6.0.0 Build 371 - Cross-Site Request Forgery
CVE-2018-656316 May 2018
Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow
23RISK
open
Exploit-DB
Microsoft Windows - Token Process Trust SID Access Check Bypass Privilege Escalation
CVE-2018-813416 May 2018
An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows
23RISK
open
Exploit-DB
Inteno IOPSYS 2.0 < 4.2.0 - 'p910nd' Remote Command Execution
CVE-2018-1012316 May 2018
p910nd on Inteno IOPSYS 2.0 through 4.2.0 allows remote attackers to read, or append data to, arbitrary files via reques
28RISK
open
Exploit-DB
Rockwell Scada System 27.011 - Cross-Site Scripting
CVE-2016-2279MEDIUM16 May 2018
Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* bef
33RISK
open
Exploit-DB
Libuser - 'roothelper' Local Privilege Escalation (Metasploit)
CVE-2015-324616 May 2018
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod
38RISK
open
Exploit-DB
Libuser - 'roothelper' Local Privilege Escalation (Metasploit)
CVE-2015-324516 May 2018
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in t
38RISK
open
Exploit-DB
2345 Security Guard 3.7 - '2345NsProtect.sys' Denial of Service
CVE-2018-1103414 May 2018
In 2345 Security Guard 3.7, the driver file (2345NsProtect.sys, X64 version) allows local users to cause a denial of ser
23RISK
open
Exploit-DB
WUZHI CMS 4.1.0 - 'form[qq_10]' Cross-Site Scripting
CVE-2018-1031313 May 2018
WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set
23RISK
open
Exploit-DB
WUZHI CMS 4.1.0 - 'tag[pinyin]' Cross-Site Scripting
CVE-2018-1031113 May 2018
A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitr
23RISK
open
Exploit-DB
Microsoft Windows 2003 SP2 - 'RRAS' SMB Remote Code Execution
CVE-2017-1188513 May 2018
Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold,
35RISK
open
Exploit-DB
Open-AudIT Community 2.2.0 - Cross-Site Scripting
CVE-2018-1031411 May 2018
Cross-site scripting (XSS) vulnerability in Open-AudIT Community 2.2.0 allows remote attackers to inject arbitrary web s
23RISK
open
Exploit-DB
Open-AudIT Professional - 2.1.1 - Cross-Site Scripting
CVE-2018-915511 May 2018
Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary we
23RISK
open
Exploit-DB
EMC RecoverPoint 4.3 - 'Admin CLI' Command Injection
CVE-2018-118511 May 2018
An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0
23RISK
open
Exploit-DB
2345 Security Guard 3.7 - '2345BdPcSafe.sys' Denial of Service
CVE-2018-1083011 May 2018
In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of serv
23RISK
open
Exploit-DB
Dell Touchpad - 'ApMsgFwd.exe' Denial of Service
CVE-2018-1082810 May 2018
An issue was discovered in Alps Pointing-device Driver 10.1.101.207. ApMsgFwd.exe allows the current user to map and wri
23RISK
open
Exploit-DB
ModbusPal 1.6b - XML External Entity Injection
CVE-2018-1083210 May 2018
ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations c
23RISK
open
Exploit-DB
Fastweb FASTGate 0.00.47 - Cross-Site Request Forgery
CVE-2018-602310 May 2018
Fastweb FASTgate 0.00.47 devices are vulnerable to CSRF, with impacts including Wi-Fi password changing, Guest Wi-Fi act
23RISK
open
Exploit-DB
Mantis Bug Tracker 1.1.3 - 'manage_proj_page' PHP Code Execution (Metasploit)
CVE-2008-468710 May 2018
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RISK
open
Exploit-DB
MyBB Latest Posts on Profile Plugin 1.1 - Cross-Site Scripting
CVE-2018-1058010 May 2018
The "Latest Posts on Profile" plugin 1.1 for MyBB has XSS because there is an added section in a user profile that displ
23RISK
open
Exploit-DB
PlaySMS - 'import.php' (Authenticated) CSV File Upload Code Execution (Metasploit)
CVE-2017-910108 May 2018
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.