Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
22,786 exploits
Exploit-DB
Splunk Enterprise - Information Disclosure
CVE-2017-560731 Mar 2017
Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3
23RISK
open
Exploit-DB
Apple macOS/IOS 10.12.2 (16C67) - 'mach_msg' Heap Overflow
CVE-2017-245630 Mar 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RISK
open
Exploit-DB
Sync Breeze Enterprise 9.5.16 - 'Import Command' Local Buffer Overflow
CVE-2017-731029 Mar 2017
A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9
50RISK
open
Exploit-DB
MikroTik RouterBoard 6.38.5 - Denial of Service
CVE-2017-728528 Mar 2017
A vulnerability in the network stack of MikroTik Version 6.38.5 released 2017-03-09 could allow an unauthenticated remot
28RISK
open
Exploit-DB
Intermec PM43 Industrial Printer - Local Privilege Escalation
CVE-2017-567128 Mar 2017
Honeywell Intermec PM23, PM42, PM43, PC23, PC43, PD43, and PC42 industrial printers before 10.11.013310 and 10.12.x befo
23RISK
open
Exploit-DB
EyesOfNetwork (EON) 5.0 - Remote Code Execution
CVE-2017-608727 Mar 2017
EyesOfNetwork ("EON") 5.0 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacte
23RISK
open
Exploit-DB
QNAP QTS < 4.2.4 - Domain Privilege Escalation
CVE-2017-522727 Mar 2017
QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by
23RISK
open
Exploit-DB
Apple Safari - Out-of-Bounds Read when Calling Bound Function
CVE-2017-244727 Mar 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open
Exploit-DB
Microsoft IIS 6.0 - WebDAV 'ScStoragePathFromUrl' Remote Buffer Overflow
CVE-2017-7269CRITICALunder attack27 Mar 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
Exploit-DB
EyesOfNetwork (EON) 5.0 - SQL Injection
CVE-2017-608827 Mar 2017
Multiple SQL injection vulnerabilities in EyesOfNetwork (aka EON) 5.0 and earlier allow remote authenticated users to ex
23RISK
open
Exploit-DB
Nuxeo 6.0/7.1/7.2/7.3 - Remote Code Execution (Metasploit)
CVE-2017-586927 Mar 2017
Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote auth
35RISK
open
Exploit-DB
Samba 4.5.2 - Symlink Race Permits Opening Files Outside Share Directory
CVE-2017-261927 Mar 2017
Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access
28RISK
open
Exploit-DB
Apple Safari - Builtin JavaScript Allows Function.caller to be Used in Strict Mode
CVE-2017-244627 Mar 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open
Exploit-DB
Apple Safari - 'DateTimeFormat.format' Type Confusion
CVE-2017-244627 Mar 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open
Exploit-DB
D-Link DCS-936L Network Camera - Cross-Site Request Forgery
CVE-2017-785126 Mar 2017
D-Link DCS-936L devices with firmware before 1.05.07 have an inadequate CSRF protection mechanism that requires the devi
23RISK
open
Exploit-DB
Fortinet FortiClient 5.2.3 (Windows 10 x64 Post-Anniversary) - Local Privilege Escalation
CVE-2015-573625 Mar 2017
The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel
23RISK
open
Exploit-DB
Fortinet FortiClient 5.2.3 (Windows 10 x64 Pre-Anniversary) - Local Privilege Escalation
CVE-2015-573625 Mar 2017
The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel
23RISK
open
Exploit-DB
Miele Professional PG 8528 - Directory Traversal
CVE-2017-724024 Mar 2017
An issue was discovered on Miele Professional PST10 devices. The corresponding embedded webserver "PST10 WebServer" typi
28RISK
open
Exploit-DB
Netgear WNR2000v5 - 'hidden_lang_avi' Remote Stack Overflow (Metasploit)
CVE-2016-10174CRITICALunder attack24 Mar 2017
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cg
100RISK
open
Exploit-DB
Linux Kernel 3.11 < 4.8 0 - 'SO_SNDBUFFORCE' / 'SO_RCVBUFFORCE' Local Privilege Escalation
CVE-2016-979322 Mar 2017
The sock_setsockopt function in net/core/sock.c in the Linux kernel before 4.8.14 mishandles negative values of sk_sndbu
23RISK
open
Exploit-DB
Microsoft GDI+ - 'gdiplus!GetRECTSForPlayback' Out-of-Bounds Read (MS17-013)
CVE-2017-006020 Mar 2017
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; W
28RISK
open
Exploit-DB
Microsoft Windows - Uniscribe Heap Out-of-Bounds Read in 'USP10!ScriptApplyLogicalWidth' Triggered via EMF (MS17-013)
CVE-2017-006220 Mar 2017
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; W
28RISK
open
Exploit-DB
D-Link DGS-1510 - Multiple Vulnerabilities
CVE-2017-620620 Mar 2017
D-Link DGS-1510-28XMP, DGS-1510-28X, DGS-1510-52X, DGS-1510-52, DGS-1510-28P, DGS-1510-28, and DGS-1510-20 Websmart devi
28RISK
open
Exploit-DB
Microsoft Windows - Uniscribe Font Processing Heap Memory Corruption in 'USP10!otlCacheManager::GlyphsSubstituted' (MS17-011)
CVE-2017-008620 Mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
35RISK
open
Exploit-DB
Mozilla Firefox - 'table' Use-After-Free
CVE-2017-540420 Mar 2017
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and
28RISK
open
Exploit-DB
Microsoft Windows - Uniscribe Font Processing Multiple Heap Out-of-Bounds and Wild Reads (MS17-011)
CVE-2017-011820 Mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
28RISK
open
Exploit-DB
Microsoft Windows Kernel - Registry Hive Loading Crashes in nt!nt!HvpGetBinMemAlloc / nt!ExpFindAndRemoveTagBigPages (MS17-017)
CVE-2017-010320 Mar 2017
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 201
23RISK
open
Exploit-DB
Microsoft Windows - Uniscribe Font Processing Heap Out-of-Bounds Write in 'USP10!UpdateGlyphFlags' (MS17-011)
CVE-2017-008920 Mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
35RISK
open
Exploit-DB
Microsoft Internet Explorer 11 - 'textarea.defaultValue' Memory Disclosure (MS17-006)
CVE-2017-0059MEDIUMunder attack20 Mar 2017
Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via
75RISK
open
Exploit-DB
Microsoft Windows - 'USP10!otlList::insertAt' Uniscribe Font Processing Heap Buffer Overflow (MS17-011)
CVE-2017-010820 Mar 2017
The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 20
35RISK
open
previouspage 142 / 760next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.