Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,095cataloged exploits
36,945CVEs with public exploitation
24,695lab-tested
24,476 exploits
Exploit-DBVexDay Proof
Microsoft MsMpEng - Multiple Crashes While Scanning Malformed Files
CVE-2017-8535doswindows29 May 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
28RISK
open
Exploit-DBVexDay Proof
Samba 3.5.0 < 4.4.14/4.5.10/4.6.4 - 'is_known_pipename()' Arbitrary Module Load (Metasploit)
CVE-2017-7494CRITICALunder attackransomwareremotelinux29 May 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open
Exploit-DBVexDay Proof
Microsoft MsMpEng - Multiple Crashes While Scanning Malformed Files
CVE-2017-8538doswindows29 May 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
35RISK
open
Exploit-DBVexDay Proof
Microsoft MsMpEng - Multiple Crashes While Scanning Malformed Files
CVE-2017-8536doswindows29 May 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
28RISK
open
Exploit-DB
Sophos Cyberoam - Cross-site scripting
CVE-2016-9834webappshardware25 May 2017
An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Soph
23RISK
open
Exploit-DBVexDay Proof
Mozilla Firefox < 53 - 'gfxTextRun' Out-of-Bounds Read
CVE-2017-5447dosmultiple25 May 2017
An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitabl
28RISK
open
Exploit-DBVexDay Proof
Mozilla Firefox < 53 - 'ConvolvePixel' Memory Disclosure
CVE-2017-5465dosmultiple25 May 2017
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for other
28RISK
open
Exploit-DBVexDay Proof
WebKit - 'enqueuePageshowEvent' / 'enqueuePopstateEvent' Universal Cross-Site Scripting
CVE-2017-2510webappsmultiple25 May 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RISK
open
Exploit-DBVexDay Proof
Apple WebKit / Safari 10.0.3(12602.4.8) - 'Editor::Command::execute' Universal Cross-Site Scripting
CVE-2017-2504webappsmultiple25 May 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RISK
open
Exploit-DBVexDay Proof
Apple WebKit / Safari 10.0.3(12602.4.8) - 'WebCore::FrameView::scheduleRelayout' Use-After-Free
CVE-2017-2514dosmultiple25 May 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'ContainerNode::parserInsertBefore' Universal Cross-Site Scripting
CVE-2017-2508webappsmultiple25 May 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'FrameLoader::clear' Stealing Variables via Page Navigation
CVE-2017-2515webappsmultiple25 May 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RISK
open
Exploit-DBVexDay Proof
Samba 3.5.0 - Remote Code Execution
CVE-2017-7494CRITICALunder attackransomwareremotelinux24 May 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open
Exploit-DBVexDay Proof
Apple macOS/iOS - 'CAMediaTimingFunctionBuiltin' NSKeyedArchiver Memory Corruption Due to Lack of Bounds Checking
CVE-2017-2527dosmultiple23 May 2017
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "CoreAnimati
23RISK
open
Exploit-DBVexDay Proof
Apple macOS/iOS - NSUnarchiver Heap Corruption Due to Lack of Bounds Checking in [NSBuiltinCharacterSet initWithCoder:]
CVE-2017-2523dosmultiple23 May 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
28RISK
open
Exploit-DBVexDay Proof
Apple macOS - Lack of Bounds Checking in HIServices Custom CFObject Serialization Local Privilege Escalation
CVE-2017-6978dosmacos23 May 2017
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Accessibili
23RISK
open
Exploit-DBVexDay Proof
Apple macOS/iOS - Memory Corruption Due to Bad Bounds Checking in NSCharacterSet Coding for NSKeyedUnarchiver
CVE-2017-2522dosmultiple23 May 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RISK
open
Exploit-DBVexDay Proof
Apple macOS/iOS - 'TIKeyboardLayout initWithCoder:' NSKeyedArchiver Heap Corruption Due to Rounding Error
CVE-2017-2524dosmultiple23 May 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RISK
open
Exploit-DBVexDay Proof
Apple macOS/iOS Kernel - Use-After-Free Due to Bad Locking in Unix Domain Socket File Descriptor Externalization
CVE-2017-2501dosmultiple23 May 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RISK
open
Exploit-DBVexDay Proof
VMware Workstation for Linux 12.5.2 build-4638234 - ALSA Configuration Host Local Privilege Escalation
CVE-2017-4915locallinux22 May 2017
VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration fil
38RISK
open
Exploit-DBVexDay Proof
Apple macOS - 'stackshot' Raw Frame Pointers
CVE-2017-2516dosmacos22 May 2017
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" com
23RISK
open
Exploit-DBVexDay Proof
Apple macOS - '32-bit syscall exit' Kernel Register Leak
CVE-2017-2509dosmacos22 May 2017
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" com
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 4.11 - eBPF Verifier Log Leaks Lower Half of map Pointer
CVE-2017-9150doslinux22 May 2017
The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allow_ptr_leaks value
23RISK
open
Exploit-DBVexDay Proof
PlaySMS 1.4 - 'import.php' Remote Code Execution
CVE-2017-9101webappsphp21 May 2017
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RISK
open
Exploit-DB
Secure Auditor 3.0 - Directory Traversal
CVE-2017-9024remotewindows20 May 2017
Secure Bytes Cisco Configuration Manager, as bundled in Secure Bytes Secure Cisco Auditor (SCA) 3.0, has a Directory Tra
28RISK
open
Exploit-DB
Mantis Bug Tracker 1.3.10/2.3.0 - Cross-Site Request Forgery
CVE-2017-7620webappsphp20 May 2017
MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequen
23RISK
open
Exploit-DB
KMCIS CaseAware - Cross-Site Scripting
CVE-2017-5631webappsphp20 May 2017
An issue was discovered in KMCIS CaseAware. Reflected cross site scripting is present in the user parameter (i.e., "usr"
38RISK
open
Exploit-DB
Tecnovision DLX Spot - SSH Backdoor Access
CVE-2017-12929remotemultiple19 May 2017
Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users
28RISK
open
Exploit-DB
Joomla! 3.7.0 - 'com_fields' SQL Injection
CVE-2017-8917webappsphp19 May 2017
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISK
open
Exploit-DB
Tecnovision DLX Spot - SSH Backdoor Access
CVE-2017-12930remotemultiple19 May 2017
SQL Injection in the admin interface in TecnoVISION DLX Spot Player4 version >1.5.10 allows remote unauthenticated users
23RISK
open
previouspage 142 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.