Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,978GitHub PoC 13,282VulnCheck XDB 8,176Nuclei 4,202Metasploit 3,462✓ verified onlyrecentpopularrisk
22,786 exploits
Exploit-DB
libao 1.2.0 - Denial of Service
The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of servic
23RISK
open ↗Exploit-DB
Sound eXchange (SoX) 14.4.2 - Multiple Vulnerabilities
The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (d
23RISK
open ↗Exploit-DB
libvorbis 1.3.5 - Multiple Vulnerabilities
The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial
23RISK
open ↗Exploit-DB
Vorbis Tools oggenc 1.4.0 - '.wav' Denial of Service
The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of serv
23RISK
open ↗Exploit-DB
Jenkins < 1.650 - Java Deserialization
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to ex
60RISK
open ↗Exploit-DB
McAfee Security Scan Plus - Remote Command Execution
A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior
28RISK
open ↗Exploit-DB
SoundTouch 1.9.2 - Multiple Vulnerabilities
The TDStretchSSE::calcCrossCorr function in source/SoundTouch/sse_optimized.cpp in SoundTouch 1.9.2 allows remote attack
23RISK
open ↗Exploit-DB
libjpeg-turbo 1.5.1 - Denial of Service
The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service
23RISK
open ↗Exploit-DB
SoundTouch 1.9.2 - Multiple Vulnerabilities
The TDStretch::processSamples function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to
23RISK
open ↗Exploit-DB
LAME 3.99.5 - Multiple Vulnerabilities
The unpack_read_samples function in frontend/get_audio.c in LAME 3.99.5 allows remote attackers to cause a denial of ser
23RISK
open ↗Exploit-DB
SoundTouch 1.9.2 - Multiple Vulnerabilities
The TDStretch::acceptNewOverlapLength function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote atta
23RISK
open ↗Exploit-DB
Fortinet FortiOS < 5.6.0 - Cross-Site Scripting
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthor
38RISK
open ↗Exploit-DB
Fortinet FortiOS < 5.6.0 - Cross-Site Scripting
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthor
43RISK
open ↗Exploit-DB
Fortinet FortiOS < 5.6.0 - Cross-Site Scripting
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to exec
38RISK
open ↗Exploit-DB
GNU libiberty - Buffer Overflow
Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary
23RISK
open ↗Exploit-DB
AudioCoder 0.8.46 - Local Buffer Overflow (SEH)
Buffer overflow in AudioCoder 0.8.46 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RISK
open ↗Exploit-DB
Microsoft Windows - '.LNK' Shortcut File Code Execution (Metasploit)
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RISK
open ↗Exploit-DB
WebKit JSC - 'ArgumentsEliminationPhase::transform' Incorrect LoadVarargs Handling
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open ↗Exploit-DB
WebKit JSC - 'JSArray::appendMemcpy' Uninitialized Memory Copy
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open ↗Exploit-DB
WebKit JSC - 'JSObject::putInlineSlow' / 'JSValue::putToPrimitive' Universal Cross-Site Scripting
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open ↗Exploit-DB
WebKit JSC - 'DFG::ByteCodeParser::flush(InlineStackEntry* inlineStackEntry)' Incorrect Scope Register Handling
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open ↗Exploit-DB
WebKit - 'WebCore::RenderObject' with Accessibility Enabled Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open ↗Exploit-DB
WebKit - 'WebCore::AccessibilityNodeObject::textUnderElement' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open ↗Exploit-DB
WebKit - 'WebCore::Node::getFlag' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open ↗Exploit-DB
Razer Synapse 2.20.15.1104 - rzpnk.sys ZwOpenProcess (Metasploit)
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpe
60RISK
open ↗Exploit-DB
Microsoft Internet Explorer - 'mshtml.dll' Remote Code Execution (MS17-007)
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilde
93RISK
open ↗Exploit-DB
WebKit - 'WebCore::AccessibilityRenderObject::handleAriaExpandedChanged' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open ↗Exploit-DB
WebKit - 'WebCore::Node::nextSibling' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open ↗Exploit-DB
WebKit - 'WebCore::getCachedWrapper' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open ↗Exploit-DB
WebKit - 'WebCore::InputType::element' Use-After-Free (1)
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.