Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
22,786 exploits
Exploit-DB
WordPress Plugin WPAMS - SQL Injection
CVE-2017-1484726 Sep 2017
Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.
23RISK
open
Exploit-DB
TicketPlus - Arbitrary File Upload
CVE-2017-1484026 Sep 2017
TeamWork TicketPlus allows Arbitrary File Upload in updateProfile.
23RISK
open
Exploit-DB
Job Links - Arbitrary File Upload
CVE-2017-1483826 Sep 2017
TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange.
23RISK
open
Exploit-DB
WordPress Plugin School Management System - SQL Injection
CVE-2017-1484326 Sep 2017
Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.
23RISK
open
Exploit-DB
WordPress Plugin WPCHURCH - SQL Injection
CVE-2017-1484526 Sep 2017
Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.
23RISK
open
Exploit-DB
WordPress Plugin Hospital Management System - SQL Injection
CVE-2017-1484626 Sep 2017
Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.
23RISK
open
Exploit-DB
SMSmaster - SQL Injection
CVE-2017-1484226 Sep 2017
Mojoomla SMSmaster Multipurpose SMS Gateway for WordPress allows SQL Injection via the id parameter.
23RISK
open
Exploit-DB
AMC Master - Arbitrary File Upload
CVE-2017-1484126 Sep 2017
Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handli
23RISK
open
Exploit-DB
Photo Fusion - Arbitrary File Upload
CVE-2017-1483926 Sep 2017
TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.
23RISK
open
Exploit-DB
Apple iOS 10.2 - Broadcom Out-of-Bounds Write when Handling 802.11k Neighbor Report Response
CVE-2017-1112025 Sep 2017
On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malformed RRM neighbor repo
23RISK
open
Exploit-DB
Supervisor 3.0a1 < 3.3.2 - XML-RPC (Authenticated) Remote Code Execution (Metasploit)
CVE-2017-1161025 Sep 2017
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RISK
open
Exploit-DB
Adobe Flash - Out-of-Bounds Write in MP4 Edge Processing
CVE-2017-1128125 Sep 2017
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploita
35RISK
open
Exploit-DB
Adobe Flash - Out-of-Bounds Memory Read in MP4 Parsing
CVE-2017-1128125 Sep 2017
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploita
35RISK
open
Exploit-DB
Oracle 9i XDB 9.2.0.1 - HTTP PASS Buffer Overflow
CVE-2003-072725 Sep 2017
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to
50RISK
open
Exploit-DB
Adobe Flash - Out-of-Bounds Read in applyToRange
CVE-2017-1128225 Sep 2017
Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation co
35RISK
open
Exploit-DB
CyberLink LabelPrint < 2.5 - Local Buffer Overflow (SEH Unicode)
CVE-2017-1462723 Sep 2017
Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) au
43RISK
open
Exploit-DB
Claydip Airbnb Clone 1.0 - Arbitrary File Upload
CVE-2017-1470422 Sep 2017
Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Larav
23RISK
open
Exploit-DB
Cash Back Comparison Script 1.0 - SQL Injection
CVE-2017-1470322 Sep 2017
SQL injection vulnerability in Cash Back Comparison Script 1.0 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Exploit-DB
Linux Kernel < 4.13.1 - BlueTooth Buffer Overflow (PoC)
CVE-2017-100025121 Sep 2017
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and includ
28RISK
open
Exploit-DB
PHPMyFAQ 2.9.8 - Cross-Site Scripting (1)
CVE-2017-1461821 Sep 2017
Cross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ through 2.9.8 allows remote attackers to inject
23RISK
open
Exploit-DB
Microsoft Edge Chakra - 'JavascriptFunction::ReparseAsmJsModule' Incorrectly Re-parses
CVE-2017-875521 Sep 2017
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary
45RISK
open
Exploit-DB
ERS Data System 1.8.1 - Java Deserialization
CVE-2017-1470221 Sep 2017
ERS Data System 1.8.1.0 allows remote attackers to execute arbitrary code, related to "com.branaghgroup.ecers.update.Upd
23RISK
open
Exploit-DB
Microsoft Edge Chakra - Deferred Parsing Makes Wrong Scopes
CVE-2017-874021 Sep 2017
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current u
45RISK
open
Exploit-DB
Microsoft Edge Chakra - 'Parser::ParseCatch' Does Not Handle 'eval()' (Denial of Service)
CVE-2017-1176421 Sep 2017
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code
35RISK
open
Exploit-DB
Microsoft Edge - Chakra Incorrectly Parses Object Patterns
CVE-2017-872921 Sep 2017
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current u
45RISK
open
Exploit-DB
Android Bluetooth - 'Blueborne' Information Leak (2)
CVE-2017-078520 Sep 2017
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RISK
open
Exploit-DB
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1)
CVE-2017-12615HIGHunder attackransomware20 Sep 2017
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open
Exploit-DB
Microsoft Edge 38.14393.1066.0 - Memory Corruption with Partial Page Loading
CVE-2017-873119 Sep 2017
Microsoft Edge in Microsoft Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the
35RISK
open
Exploit-DB
Microsoft Edge 38.14393.1066.0 - 'COptionsCollectionCacheItem::GetAt' Out-of-Bounds Read
CVE-2017-873419 Sep 2017
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arb
35RISK
open
Exploit-DB
HPE < 7.2 - Java Deserialization
CVE-2016-437219 Sep 2017
HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01,
28RISK
open
previouspage 123 / 760next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.