Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
22,786 exploits
Exploit-DB
Apple macOS/iOS Kernel 10.12.3 (16D32) - 'bpf' Heap Overflow
CVE-2017-248204 Apr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RISK
open
Exploit-DB
Apple macOS/iOS Kernel 10.12.3 (16D32) - Double-Free Due to Bad Locking in fsevents Device
CVE-2017-249004 Apr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RISK
open
Exploit-DB
Apple macOS Kernel 10.12.2 (16C67) - 'AppleIntelCapriController::GetLinkConfig' Code Execution Due to Lack of Bounds Checking
CVE-2017-244304 Apr 2017
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graph
23RISK
open
Exploit-DB
Apple macOS/iOS Kernel 10.12.3 (16D32) - SIOCSIFORDER Socket ioctl Memory Corruption Due to Bad Bounds Checking
CVE-2017-247304 Apr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RISK
open
Exploit-DB
Apple Webkit - 'JSCallbackData' Universal Cross-Site Scripting
CVE-2017-244204 Apr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issu
23RISK
open
Exploit-DB
Apple Webkit - Universal Cross-Site Scripting by Accessing a Named Property from an Unloaded Window
CVE-2017-236704 Apr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open
Exploit-DB
Apple WebKit 10.0.2 - HTMLInputElement Use-After-Free
CVE-2017-245404 Apr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open
Exploit-DB
Apple macOS/iOS Kernel 10.12.3 (16D32) - SIOCGIFORDER Socket ioctl Off-by-One Memory Corruption
CVE-2017-247404 Apr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RISK
open
Exploit-DB
Apple WebKit 10.0.2 (12602.3.12.0.1_ r210800) - 'constructJSReadableStreamDefaultReader' Type Confusion
CVE-2017-245704 Apr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issu
23RISK
open
Exploit-DB
Apple WebKit - 'ComposedTreeIterator::traverseNextInShadowTree' Use-After-Free
CVE-2017-246604 Apr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open
Exploit-DB
Apple macOS Kernel 10.12.3 (16D32) - 'audit_pipe_open' Off-by-One Memory Corruption
CVE-2017-248304 Apr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RISK
open
Exploit-DB
Apple macOS Kernel 10.12.2 (16C67) - Memory Disclosure Due to Lack of Bounds Checking in AppleIntelCapriController::getDisplayPipeCapability
CVE-2017-248904 Apr 2017
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graph
23RISK
open
Exploit-DB
Broadcom Wi-Fi SoC - 'dhd_handle_swc_evt' Heap Overflow
CVE-2017-056904 Apr 2017
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execu
23RISK
open
Exploit-DB
Apple WebKit - 'FormSubmission::create' Use-After-Free
CVE-2017-246004 Apr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open
Exploit-DB
Apple WebKit - 'WebCore::toJS' Use-After-Free
CVE-2017-247604 Apr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open
Exploit-DB
Apple macOS Kernel 10.12.3 (16D32) - Use-After-Free Due to Double-Release in posix_spawn
CVE-2017-247204 Apr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RISK
open
Exploit-DB
Apple WebKit 10.0.2(12602.3.12.0.1) - 'Frame::setDocument (1)' Universal Cross-Site Scripting
CVE-2017-236404 Apr 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. The
23RISK
open
Exploit-DB
Broadcom Wi-Fi SoC - TDLS Teardown Request Remote Heap Overflow
CVE-2017-056104 Apr 2017
A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary
35RISK
open
Exploit-DB
Broadcom Wi-Fi SoC - Heap Overflow 'wlc_tdls_cal_mic_chk' Due to Large RSN IE in TDLS Setup Confirm Frame
CVE-2017-056104 Apr 2017
A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary
35RISK
open
Exploit-DB
Apple WebKit - Negative-Size memmove in HTMLFormElement
CVE-2017-245904 Apr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open
Exploit-DB
Apple macOS/iOS Kernel 10.12.3 (16D32) - Bad Locking in necp_open Use-After-Free
CVE-2017-247804 Apr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RISK
open
Exploit-DB
Apple WebKit 10.0.2 (12602.3.12.0.1) - 'disconnectSubframes' Universal Cross-Site Scripting
CVE-2017-244504 Apr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open
Exploit-DB
Apple WebKit - 'table' Use-After-Free
CVE-2017-247104 Apr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. watchOS
23RISK
open
Exploit-DB
Apache Tomcat 6/7/8/9 - Information Disclosure
CVE-2016-681604 Apr 2017
The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.
35RISK
open
Exploit-DB
Bluecoat ASG 6.6/CAS 1.3 - OS Command Injection (Metasploit)
CVE-2016-909103 Apr 2017
Blue Coat Advanced Secure Gateway (ASG) 6.6 before 6.6.5.4 and Content Analysis System (CAS) 1.3 before 1.3.7.4 are susc
28RISK
open
Exploit-DB
Moxa AWK-3131A 1.4 < 1.7 - 'Username' OS Command Injection
CVE-2017-14459CRITICAL03 Apr 2017
An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK
53RISK
open
Exploit-DB
Bluecoat ASG 6.6/CAS 1.3 - Local Privilege Escalation (Metasploit)
CVE-2016-909103 Apr 2017
Blue Coat Advanced Secure Gateway (ASG) 6.6 before 6.6.5.4 and Content Analysis System (CAS) 1.3 before 1.3.7.4 are susc
28RISK
open
Exploit-DB
BackBox OS - Denial of Service
CVE-2017-739702 Apr 2017
BackBox Linux 4.6 allows remote attackers to cause a denial of service (ksoftirqd CPU consumption) via a flood of packet
28RISK
open
Exploit-DB
Zyxel_ EMG2926 < V1.00(AAQT.4)b8 - OS Command Injection
CVE-2017-6884HIGHunder attackransomware02 Apr 2017
A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vul
83RISK
open
Exploit-DB
Pixie 1.0.4 - Arbitrary File Upload
CVE-2017-740202 Apr 2017
Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/ind
23RISK
open
previouspage 141 / 760next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.