Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,980cataloged exploits
36,899CVEs with public exploitation
24,695lab-tested
24,476 exploits
Exploit-DBVexDay Proof
Advantech WebAccess 8.2-2017.03.31 - Webvrpcs Service Opcode 80061 Stack Buffer Overflow (Metasploit)
CVE-2017-14016webappswindows14 Dec 2017
A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The applicati
43RISK
open
Exploit-DB
Readymade Video Sharing Script 3.2 - HTML Injection
CVE-2017-17649webappsphp14 Dec 2017
Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter.
23RISK
open
Exploit-DBVexDay Proof
FS Lynda Clone 1.0 - SQL Injection
CVE-2017-17643webappsphp14 Dec 2017
FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
23RISK
open
Exploit-DB
Linksys WVBR0 - 'User-Agent' Remote Command Injection
CVE-2017-17411webappshardware14 Dec 2017
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authe
60RISK
open
Exploit-DBVexDay Proof
Joomla! Component JEXTN Video Gallery 3.0.5 - 'id' SQL Injection
CVE-2017-17872webappsphp13 Dec 2017
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component JEXTN Question And Answer 3.1.0 - SQL Injection
CVE-2017-17871webappsphp13 Dec 2017
The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action
23RISK
open
Exploit-DBVexDay Proof
GNU C Library Dynamic Loader glibc ld.so - Memory Leak / Buffer Overflow
CVE-2017-1000408locallinux13 Dec 2017
A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environme
23RISK
open
Exploit-DB
Meinberg LANTIME Web Configuration Utility 6.16.008 - Arbitrary File Read
CVE-2017-16787webappscgi13 Dec 2017
The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote attackers to read
23RISK
open
Exploit-DB
vBulletin 5.x - 'cacheTemplates' Remote Arbitrary File Deletion
CVE-2017-17672webappsmultiple13 Dec 2017
In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file delet
28RISK
open
Exploit-DBVexDay Proof
GNU C Library Dynamic Loader glibc ld.so - Memory Leak / Buffer Overflow
CVE-2017-1000409locallinux13 Dec 2017
A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environ
23RISK
open
Exploit-DB
Accesspress Anonymous Post Pro < 3.2.0 - Arbitrary File Upload
CVE-2017-16949webappsphp12 Dec 2017
An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper in
28RISK
open
Exploit-DBVexDay Proof
Apple macOS/iOS - Multiple Kernel Use-After-Frees due to Incorrect IOKit Object Lifetime Management in IOTimeSyncClockManagerUserClient
CVE-2017-13847dosmultiple12 Dec 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The is
23RISK
open
Exploit-DBVexDay Proof
Apple XNU Kernel - Memory Corruption due to Integer Overflow in __offsetof Usage in posix_spawn on 32-bit Platforms
CVE-2017-13876dosmultiple12 Dec 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component JBuildozer 1.4.1 - 'appid' SQL Injection
CVE-2017-17870webappsphp12 Dec 2017
The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.
23RISK
open
Exploit-DBVexDay Proof
Apple macOS/iOS - Kernel Double Free due to Incorrect API Usage in Flow Divert Socket Option Handling
CVE-2017-13867dosmultiple12 Dec 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISK
open
Exploit-DBVexDay Proof
Apple macOS - Kernel Code Execution due to Lack of Bounds Checking in AppleIntelCapriController::GetLinkConfig
CVE-2017-13875dosmacos12 Dec 2017
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graph
23RISK
open
Exploit-DBVexDay Proof
Foodspotting Clone Script 1.0 - 'quicksearch.php?q' SQL Injection
CVE-2017-17617webappsphp11 Dec 2017
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
23RISK
open
Exploit-DBVexDay Proof
Apple macOS XNU Kernel - Memory Disclosure due to bug in Kernel API for Detecting Kernel Memory Disclosures
CVE-2017-13865dosmacos11 Dec 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISK
open
Exploit-DBVexDay Proof
Readymade PHP Classified Script 3.3 - 'subctid' / 'mctid' SQL Injection
CVE-2017-17626webappsphp11 Dec 2017
Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.
23RISK
open
Exploit-DB
MLM Forex Market Plan Script 2.0.4 - 'newid' / 'eventid' SQL Injection
CVE-2017-17635webappsphp11 Dec 2017
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eve
23RISK
open
Exploit-DBVexDay Proof
Kickstarter Clone Acript 2.0 - 'projid' SQL Injection
CVE-2017-17618webappsphp11 Dec 2017
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
23RISK
open
Exploit-DBVexDay Proof
Laundry Booking Script 1.0 - 'list?city' SQL Injection
CVE-2017-17619webappsphp11 Dec 2017
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open
Exploit-DBVexDay Proof
Responsive Events & Movie Ticket Booking Script 3.2.1 - 'findcity.php?q' SQL Injection
CVE-2017-17632webappsphp11 Dec 2017
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RISK
open
Exploit-DBVexDay Proof
Multiplex Movie Theater Booking Script 3.1.5 - 'moid' / 'eid' SQL Injection
CVE-2017-17633webappsphp11 Dec 2017
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php
23RISK
open
Exploit-DBVexDay Proof
Single Theater Booking Script 3.2.1 - 'findcity.php?q' SQL Injection
CVE-2017-17634webappsphp11 Dec 2017
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RISK
open
Exploit-DBVexDay Proof
Groupon Clone Script 3.01 - 'state_id' / 'search' SQL Injection
CVE-2017-17638webappsphp11 Dec 2017
Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
23RISK
open
Exploit-DBVexDay Proof
Muslim Matrimonial Script 3.02 - 'succid' SQL Injection
CVE-2017-17639webappsphp11 Dec 2017
Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.
23RISK
open
Exploit-DB
Advanced World Database 2.0.5 - SQL Injection
CVE-2017-17640webappsphp11 Dec 2017
Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country pa
23RISK
open
Exploit-DBVexDay Proof
Vanguard 1.4 - SQL Injection
CVE-2017-17873webappsphp11 Dec 2017
Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.
23RISK
open
Exploit-DBVexDay Proof
Apple macOS - 'necp_get_socket_attributes' so_pcb Type Confusion
CVE-2017-13855dosmacos11 Dec 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISK
open
previouspage 118 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.