Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,980cataloged exploits
36,899CVEs with public exploitation
24,695lab-tested
24,476 exploits
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k!NtGdiGetGlyphOutline' Pool Memory Disclosure
CVE-2017-8680doswindows18 Sep 2017
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k!NtGdiEngCreatePalette' Stack Memory Disclosure
CVE-2017-8685doswindows18 Sep 2017
Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows information disclosure by the way
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k!NtGdiDoBanding' Stack Memory Disclosure
CVE-2017-8687doswindows18 Sep 2017
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k!NtGdiGetFontResourceInfoInternalW' Stack Memory Disclosure
CVE-2017-8684doswindows18 Sep 2017
Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k!NtGdiGetPhysicalMonitorDescription' Stack Memory Disclosure
CVE-2017-8681doswindows18 Sep 2017
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RISK
open
Exploit-DB
Apache < 2.2.34 / < 2.4.27 - OPTIONS Memory Leak
CVE-2017-9798webappslinux18 Sep 2017
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user
60RISK
open
Exploit-DB
iBall ADSL2+ Home Router - Authentication Bypass
CVE-2017-14244webappshardware18 Sep 2017
An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k!NtQueryCompositionSurfaceBinding' Stack Memory Disclosure
CVE-2017-8678doswindows18 Sep 2017
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RISK
open
Exploit-DB
WordPress Plugin Content Timeline - SQL Injection
CVE-2017-14507webappsphp16 Sep 2017
Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to exec
23RISK
open
Exploit-DB
Netdecision 5.8.2 - Local Privilege Escalation
CVE-2017-14311localwindows16 Sep 2017
The Winring0x32.sys driver in NetMechanica NetDecision 5.8.2 allows local users to gain privileges via a crafted 0x9C402
23RISK
open
Exploit-DB
UTStar WA3002G4 ADSL Broadband Modem - Authentication Bypass
CVE-2017-14243webappshardware15 Sep 2017
An authentication bypass vulnerability on UTStar WA3002G4 ADSL Broadband Modem WA3002G4-0021.01 devices allows attackers
28RISK
open
Exploit-DB
EMC AlphaStor Library Manager < 4.0 build 910 - Opcode 0x4f Buffer Overflow (Metasploit)
CVE-2013-0946remotewindows14 Sep 2017
Buffer overflow in the Library Control Program (LCP) in EMC AlphaStor 4.0 before build 910 allows remote attackers to ex
28RISK
open
Exploit-DB
Humax Wi-Fi Router HG100R 2.0.6 - Authentication Bypass
CVE-2017-11435webappshardware14 Sep 2017
The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted req
28RISK
open
Exploit-DB
KingScada AlarmServer 3.1.2.13 - Remote Stack Buffer Overflow (Metasploit)
CVE-2014-0787remotewindows14 Sep 2017
WellinTech KingSCADA Stack-based Buffer Overflow
53RISK
open
Exploit-DBVexDay Proof
Infinite Automation Mango Automation - Command Injection (Metasploit)
CVE-2015-7901remotejsp13 Sep 2017
Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to execut
23RISK
open
Exploit-DB
EMC CMCNE Inmservlets.war FileUploadController 11.2.1 - Remote Code Execution (Metasploit)
CVE-2013-6810remotejava13 Sep 2017
The server in Brocade Network Advisor before 12.1.0, as used in EMC Connectrix Manager Converged Network Edition (CMCNE)
28RISK
open
Exploit-DB
Alienvault OSSIM av-centerd - Util.pm sync_rserver Command Execution (Metasploit)
CVE-2014-3804remotelinux13 Sep 2017
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a
60RISK
open
Exploit-DB
Carel PlantVisor 2.4.4 - Directory Traversal Information Disclosure (Metasploit)
CVE-2011-3487webappswindows13 Sep 2017
Directory traversal vulnerability in CarelDataServer.exe in Carel PlantVisor 2.4.4 and earlier allows remote attackers t
23RISK
open
Exploit-DB
Alienvault OSSIM av-centerd 4.7.0 - 'get_log_line' Command Injection (Metasploit)
CVE-2014-3805remotelinux13 Sep 2017
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a
28RISK
open
Exploit-DB
Fatek Automation PLC WinProladder 3.11 Build 14701 - Stack Buffer Overflow (Metasploit)
CVE-2016-8377remotewindows13 Sep 2017
An issue was discovered in Fatek Automation PLC WinProladder Version 3.11 Build 14701. A stack-based buffer overflow vul
23RISK
open
Exploit-DB
Viap Automation WinPLC7 5.0.45.5921 - Recv Buffer Overflow (Metasploit)
CVE-2017-5177remotewindows13 Sep 2017
A Stack Buffer Overflow issue was discovered in VIPA Controls WinPLC7 5.0.45.5921 and prior. A stack-based buffer overfl
28RISK
open
Exploit-DB
Dameware Mini Remote Control 4.0 - Username Stack Buffer Overflow (Metasploit)
CVE-2005-2842remotewindows13 Sep 2017
Buffer overflow in dwrcs.exe in DameWare Mini Remote Control before 4.9.0 allows remote attackers to execute arbitrary c
28RISK
open
Exploit-DB
EMC CMCNE 11.2.1 - FileUploadController Remote Code Execution (Metasploit)
CVE-2013-6810remotejava13 Sep 2017
The server in Brocade Network Advisor before 12.1.0, as used in EMC Connectrix Manager Converged Network Edition (CMCNE)
28RISK
open
Exploit-DB
Indusoft Web Studio - Directory Traversal Information Disclosure (Metasploit)
CVE-2014-0780CRITICALunder attackwebappswindows13 Sep 2017
InduSoft Web Studio Path Traversal
100RISK
open
Exploit-DB
Microsoft Windows .NET Framework - Remote Code Execution
CVE-2017-8759HIGHunder attackremotewindows13 Sep 2017
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RISK
open
Exploit-DB
Astaro Security Gateway 7 - Remote Code Execution
CVE-2017-6315remotehardware13 Sep 2017
Astaro Security Gateway (aka ASG) 7 allows remote attackers to execute arbitrary code via a crafted request to index.plx
28RISK
open
Exploit-DBVexDay Proof
WebKit JSC - 'BytecodeGenerator::emitGetByVal' Incorrect Optimization (1)
CVE-2017-7061dosmultiple12 Sep 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open
Exploit-DB
osTicket 1.10 - SQL Injection (PoC)
CVE-2017-14396webappsphp12 Sep 2017
In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a
23RISK
open
Exploit-DBVexDay Proof
Jungo DriverWizard WinDriver < 12.4.0 - Kernel Pool Overflow / Local Privilege Escalation (2)
CVE-2017-14344localwindows12 Sep 2017
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must
23RISK
open
Exploit-DB
tcprewrite - Heap Buffer Overflow
CVE-2017-14266doslinux11 Sep 2017
tcprewrite in Tcpreplay 3.4.4 has a Heap-Based Buffer Overflow vulnerability triggered by a crafted PCAP file, a related
23RISK
open
previouspage 130 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.