Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
22,786 exploits
Exploit-DB
Microsoft Windows Server 2008 R2 (x64) - 'SrvOs2FeaToNt' SMB Remote Code Execution (MS17-010)
CVE-2017-0146HIGHunder attackransomware10 May 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Exploit-DB
Microsoft Windows Server 2008 R2 (x64) - 'SrvOs2FeaToNt' SMB Remote Code Execution (MS17-010)
CVE-2017-0147HIGHunder attackransomware10 May 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Exploit-DB
Microsoft Windows Server 2008 R2 (x64) - 'SrvOs2FeaToNt' SMB Remote Code Execution (MS17-010)
CVE-2017-0143HIGHunder attackransomware10 May 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Exploit-DB
CMS Made Simple 2.1.6 - Multiple Vulnerabilities
CVE-2017-8912HIGH10 May 2017
CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code para
41RISK
open
Exploit-DB
Intel Active Management Technology - System Privileges
CVE-2017-5689CRITICALunder attack10 May 2017
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Mana
100RISK
open
Exploit-DB
Microsoft Windows Server 2008 R2 (x64) - 'SrvOs2FeaToNt' SMB Remote Code Execution (MS17-010)
CVE-2017-0144HIGHunder attackransomware10 May 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Exploit-DB
Microsoft Windows Server 2008 R2 (x64) - 'SrvOs2FeaToNt' SMB Remote Code Execution (MS17-010)
CVE-2017-0148HIGHunder attackransomware10 May 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Exploit-DB
Microsoft Windows Server 2008 R2 (x64) - 'SrvOs2FeaToNt' SMB Remote Code Execution (MS17-010)
CVE-2017-0145HIGHunder attackransomware10 May 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Exploit-DB
Cisco DPC3928 Router - Arbitrary File Disclosure
CVE-2017-1150210 May 2017
Technicolor DPC3928AD DOCSIS devices allow remote attackers to read arbitrary files via a request starting with "GET /..
23RISK
open
Exploit-DB
SAP SAPCAR 721.510 - Heap Buffer Overflow
CVE-2017-885210 May 2017
SAP SAPCAR 721.510 has a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted CAR archive file
23RISK
open
Exploit-DB
wolfSSL 3.10.2 - x509 Certificate Text Parsing Off-by-One
CVE-2017-2800HIGH09 May 2017
A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting
41RISK
open
Exploit-DB
Personify360 7.5.2/7.6.1 - Improper Database Schema Access Restrictions
CVE-2017-731409 May 2017
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, while creating
23RISK
open
Exploit-DB
Microsoft Security Essentials / SCEP (Microsoft Windows 8/8.1/10 / Windows Server) - 'MsMpEng' Remote Type Confusion
CVE-2017-029009 May 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
45RISK
open
Exploit-DB
Personify360 7.5.2/7.6.1 - Improper Access Restrictions
CVE-2017-731209 May 2017
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add
23RISK
open
Exploit-DB
MediaCoder 0.8.48.5888 - Local Buffer Overflow (SEH)
CVE-2017-886908 May 2017
Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RISK
open
Exploit-DB
Gemalto SmartDiag Diagnosis Tool < 2.5 - Local Buffer Overflow (SEH)
CVE-2017-695308 May 2017
Gemalto SmartDiag Diagnosis Tool v2.5 has a stack-based Buffer Overflow with SEH Overwrite via long "Register a new card
23RISK
open
Exploit-DB
RPCBind / libtirpc - Denial of Service
CVE-2017-877908 May 2017
rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider t
60RISK
open
Exploit-DB
CloudBees Jenkins 2.32.1 - Java Deserialization
CVE-2017-1000353CRITICALunder attack05 May 2017
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code exe
100RISK
open
Exploit-DB
ViMbAdmin 3.0.15 - Multiple Cross-Site Request Forgery Vulnerabilities
CVE-2017-608605 May 2017
Multiple cross-site request forgery (CSRF) vulnerabilities in the addAction and purgeAction functions in ViMbAdmin 3.0.1
23RISK
open
Exploit-DB
Technicolor DPC3928SL - SNMP Authentication Bypass
CVE-2017-513505 May 2017
Certain Technicolor devices have an SNMP access-control bypass, possibly involving an ISP customization in some cases. T
28RISK
open
Exploit-DB
Apple Safari 10.0.3 - 'JSC::CachedCall' Use-After-Free
CVE-2017-249104 May 2017
Use after free vulnerability in the String.replace method JavaScriptCore in Apple Safari in iOS before 10.3 allows remot
23RISK
open
Exploit-DB
WordPress Core < 4.7.4 - Unauthorized Password Reset
CVE-2017-829503 May 2017
WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for re
28RISK
open
Exploit-DB
WordPress Core 4.6 - Remote Code Execution
CVE-2016-10033CRITICALunder attack03 May 2017
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
Exploit-DB
Ghostscript 9.21 - Type Confusion Arbitrary Command Execution (Metasploit)
CVE-2017-8291HIGHunder attack02 May 2017
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RISK
open
Exploit-DB
Tuleap Project Wiki 8.3 < 9.6.99.86 - Command Injection
CVE-2017-798101 May 2017
Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project W
28RISK
open
Exploit-DB
MySQL < 5.6.35 / < 5.7.17 - Integer Overflow
CVE-2017-359901 May 2017
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions t
45RISK
open
Exploit-DB
Admidio 3.2.8 - Cross-Site Request Forgery
CVE-2017-838228 Apr 2017
admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user acc
23RISK
open
Exploit-DB
Microsoft Internet Explorer 11.576.14393.0 - 'CStyleSheetArray::BuildListOfMatchedRules' Memory Corruption
CVE-2017-020227 Apr 2017
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerabi
35RISK
open
Exploit-DB
Oracle E-Business Suite 12.2.3 - 'IESFOOTPRINT' SQL Injection
CVE-2017-354925 Apr 2017
Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Scripting Administration). Sup
28RISK
open
Exploit-DB
HPE OpenCall Media Platform (OCMP) 4.3.2 - Cross-Site Scripting / Remote File Inclusion
CVE-2017-579825 Apr 2017
A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP ve
23RISK
open
previouspage 138 / 760next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.