Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,980cataloged exploits
36,899CVEs with public exploitation
24,695lab-tested
24,476 exploits
Exploit-DB
Avaya IP Office (IPO) < 10.1 - ActiveX Buffer Overflow
CVE-2017-12969doswindows05 Nov 2017
Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows r
28RISK
open
Exploit-DB
Avaya IP Office (IPO) < 10.1 - 'SoftConsole' Remote Buffer Overflow (SEH)
CVE-2017-11309remotewindows05 Nov 2017
Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary co
23RISK
open
Exploit-DB
WordPress Plugin Userpro < 4.9.17.1 - Authentication Bypass
CVE-2017-16562webappsphp04 Nov 2017
The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers
28RISK
open
Exploit-DB
GraphicsMagick - Memory Disclosure / Heap Overflow
CVE-2017-16352dosmultiple03 Nov 2017
GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerability found in the "Display visual image dir
28RISK
open
Exploit-DBVexDay Proof
tnftp - 'savefile' Arbitrary Command Execution (Metasploit)
CVE-2014-8517remoteunix03 Nov 2017
The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 thro
50RISK
open
Exploit-DBVexDay Proof
Ipswitch WS_FTP Professional < 12.6.0.3 - Local Buffer Overflow (SEH)
CVE-2017-16513doswindows03 Nov 2017
Ipswitch WS_FTP Professional before 12.6.0.3 has buffer overflows in the local search field and the backup locations fie
23RISK
open
Exploit-DB
Logitech Media Server 7.9.0 - 'Radio URL' Cross-Site Scripting
CVE-2017-16568webappsmultiple03 Nov 2017
Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality.
23RISK
open
Exploit-DB
GraphicsMagick - Memory Disclosure / Heap Overflow
CVE-2017-16353dosmultiple03 Nov 2017
GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function
28RISK
open
Exploit-DB
Logitech Media Server 7.9.0 - 'favorites' Cross-Site Scripting
CVE-2017-16567webappsmultiple03 Nov 2017
Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Favorites" feature. T
23RISK
open
Exploit-DB
Debut Embedded HTTPd 1.20 - Denial of Service
CVE-2017-16249doshardware02 Nov 2017
The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST requ
50RISK
open
Exploit-DB
OctoberCMS 1.0.426 (Build 426) - Cross-Site Request Forgery
CVE-2017-16244webappsphp01 Nov 2017
Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for po
23RISK
open
Exploit-DB
Cisco UCS Platform Emulator 3.1(2ePE1) - Remote Code Execution
CVE-2017-12243remotelinux01 Nov 2017
A vulnerability in the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewal
45RISK
open
Exploit-DB
Vir.IT eXplorer Anti-Virus 8.5.39 - 'VIAGLT64.SYS' Local Privilege Escalation
CVE-2017-16237localwindows01 Nov 2017
In Vir.IT eXplorer Anti-Virus before 8.5.42, the driver file (VIAGLT64.SYS) contains an Arbitrary Write vulnerability be
23RISK
open
Exploit-DB
ZyXEL PK5001Z Modem - Backdoor Account
CVE-2016-10401remotehardware31 Oct 2017
ZyXEL PK5001Z devices have zyad5001 as the su password, which makes it easier for remote attackers to obtain root access
28RISK
open
Exploit-DB
Ingenious 2.3.0 - Arbitrary File Upload
CVE-2017-15957webappsphp30 Oct 2017
my_profile.php in Ingenious School Management System 2.3.0 allows a student or teacher to upload an arbitrary file.
23RISK
open
Exploit-DB
Article Directory Script 3.0 - 'id' SQL Injection
CVE-2017-15960webappsphp30 Oct 2017
Article Directory Script 3.0 allows SQL Injection via the id parameter to author.php or category.php.
23RISK
open
Exploit-DB
MyBuilder Clone 1.0 - 'subcategory' SQL Injection
CVE-2017-15968webappsphp30 Oct 2017
MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter.
23RISK
open
Exploit-DB
Online Exam Test Application - 'sort' SQL Injection
CVE-2017-15989webappsphp30 Oct 2017
Online Exam Test Application allows SQL Injection via the resources.php sort parameter in a category action.
23RISK
open
Exploit-DB
iTech Gigs Script 1.21 - SQL Injection
CVE-2017-15963webappsphp30 Oct 2017
iTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser pa
23RISK
open
Exploit-DB
Php Inventory - Arbitrary File Upload
CVE-2017-15990webappsphp30 Oct 2017
Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/.
23RISK
open
Exploit-DB
iProject Management System 1.0 - 'ID' SQL Injection
CVE-2017-15961webappsphp30 Oct 2017
iProject Management System 1.0 allows SQL Injection via the ID parameter to index.php.
23RISK
open
Exploit-DB
AROX School ERP PHP Script - 'id' SQL Injection
CVE-2017-15978webappsphp30 Oct 2017
AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter.
23RISK
open
Exploit-DB
PHP CityPortal 2.0 - SQL Injection
CVE-2017-15970webappsphp30 Oct 2017
PHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter.
23RISK
open
Exploit-DB
PG All Share Video 1.0 - SQL Injection
CVE-2017-15969webappsphp30 Oct 2017
PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_cata
23RISK
open
Exploit-DB
Website Broker Script - 'status_id' SQL Injection
CVE-2017-15992webappsphp30 Oct 2017
Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php.
23RISK
open
Exploit-DB
Mailing List Manager Pro 3.0 - SQL Injection
CVE-2017-15967webappsphp30 Oct 2017
Mailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the e
23RISK
open
Exploit-DBVexDay Proof
Oracle Java SE - Web Start jnlp XML External Entity Processing Information Disclosure
CVE-2017-10309webappsxml30 Oct 2017
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affecte
23RISK
open
Exploit-DB
Vastal I-Tech Agent Zone - 'searchCommercial.php' / 'searchResidential.php' SQL Injection
CVE-2017-15991webappsphp30 Oct 2017
Vastal I-Tech Agent Zone (aka The Real Estate Script) allows SQL Injection in searchCommercial.php via the property_type
23RISK
open
Exploit-DB
ZeeBuddy 2x - 'groupid' SQL Injection
CVE-2017-15976webappsphp30 Oct 2017
ZeeBuddy 2x allows SQL Injection via the admin/editadgroup.php groupid parameter, a different vulnerability than CVE-200
23RISK
open
Exploit-DB
Shareet - 'photo' SQL Injection
CVE-2017-15979webappsphp30 Oct 2017
Shareet - Photo Sharing Social Network 1.0 allows SQL Injection via the photo parameter.
23RISK
open
previouspage 124 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.