Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
22,786 exploits
Exploit-DB
dotCMS 3.6.1 - Blind Boolean SQL Injection
CVE-2017-534416 Feb 2017
An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessib
23RISK
open
Exploit-DB
OpenText Documentum D2 - Remote Code Execution
CVE-2017-558615 Feb 2017
OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a craf
28RISK
open
Exploit-DB
Geutebruck 5.02024 G-Cam/EFD-2250 - 'testaction.cgi' Remote Command Execution (Metasploit)
CVE-2017-517415 Feb 2017
An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authenticatio
35RISK
open
Exploit-DB
GOM Player 2.3.10.5266 - '.fpx' Denial of Service
CVE-2017-588115 Feb 2017
GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspeci
23RISK
open
Exploit-DB
Geutebruck 5.02024 G-Cam/EFD-2250 - 'testaction.cgi' Remote Command Execution (Metasploit)
CVE-2017-517315 Feb 2017
An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD
28RISK
open
Exploit-DB
Microsoft Windows - 'gdi32.dll' EMR_SETDIBITSTODEVICE Heap Out-of-Bounds Reads / Memory Disclosure
CVE-2017-003815 Feb 2017
gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
45RISK
open
Exploit-DB
NVIDIA Driver 375.70 - Buffer Overflow in Command Buffer Submission
CVE-2017-031315 Feb 2017
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) implem
23RISK
open
Exploit-DB
Cisco ASA - WebVPN CIFS Handling Buffer Overflow
CVE-2017-380715 Feb 2017
A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software,
28RISK
open
Exploit-DB
NVIDIA Driver 375.70 - DxgkDdiEscape 0x100008b Out-of-Bounds Read/Write
CVE-2017-031215 Feb 2017
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handle
23RISK
open
Exploit-DB
Google Android - Inter-process munmap in android.util.MemoryIntArray
CVE-2017-041114 Feb 2017
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
23RISK
open
Exploit-DB
F5 BIG-IP 11.6 SSL Virtual Server - 'Ticketbleed' Memory Disclosure
CVE-2016-924414 Feb 2017
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may
45RISK
open
Exploit-DB
Microsoft Edge - TypedArray.sort Use-After-Free (MS16-145)
CVE-2016-728814 Feb 2017
The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (m
45RISK
open
Exploit-DB
ntfs-3g - Unsanitized modprobe Environment Privilege Escalation
CVE-2017-0358HIGH14 Feb 2017
ntfs-3g: Modprobe influence vulnerability via environment variables
56RISK
open
Exploit-DB
Google Android - android.util.MemoryIntArray Ashmem Race Conditions
CVE-2017-041214 Feb 2017
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
23RISK
open
Exploit-DB
Linux Kernel 3.10.0 (CentOS 7) - Denial of Service
CVE-2017-597212 Feb 2017
The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fa
28RISK
open
Exploit-DB
F5 BIG-IP SSL Virtual Server - 'Ticketbleed' Memory Disclosure
CVE-2016-924410 Feb 2017
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may
45RISK
open
Exploit-DB
HP Smart Storage Administrator 2.30.6.0 - Remote Command Injection (Metasploit)
CVE-2016-852310 Feb 2017
A Remote Arbitrary Code Execution vulnerability in HPE Smart Storage Administrator version before v2.60.18.0 was found.
28RISK
open
Exploit-DB
Node.JS - 'node-serialize' Remote Code Execution
CVE-2017-594108 Feb 2017
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISK
open
Exploit-DB
OpenBSD HTTPd < 6.0 - Memory Exhaustion Denial of Service
CVE-2017-585007 Feb 2017
httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for
28RISK
open
Exploit-DB
CUPS < 2.0.3 - Remote Command Execution
CVE-2015-115803 Feb 2017
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-va
28RISK
open
Exploit-DB
ntfs-3g (Debian 9) - Local Privilege Escalation
CVE-2017-0358HIGH03 Feb 2017
ntfs-3g: Modprobe influence vulnerability via environment variables
56RISK
open
Exploit-DB
Apple WebKit - 'HTMLFormElement::reset()' Use-After Free
CVE-2017-236201 Feb 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISK
open
Exploit-DB
Apple WebKit - 'HTMLKeygenElement' Type Confusion
CVE-2017-236901 Feb 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISK
open
Exploit-DB
Apple WebKit - Type Confusion in RenderBox with Accessibility Enabled
CVE-2017-237301 Feb 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISK
open
Exploit-DB
AlienVault OSSIM/USM < 5.3.1 - Remote Code Execution (Metasploit)
CVE-2016-858031 Jan 2017
PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vuln
23RISK
open
Exploit-DB
PHP PEAR 1.10.1 - Arbitrary File Download
CVE-2017-563030 Jan 2017
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenam
28RISK
open
Exploit-DB
Netgear Routers - Password Disclosure
CVE-2017-5521HIGHunder attack30 Jan 2017
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R
100RISK
open
Exploit-DB
Oracle VM VirtualBox < 5.0.32 / < 5.1.14 - Local Privilege Escalation
CVE-2017-331627 Jan 2017
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: GUI). Supported versions tha
23RISK
open
Exploit-DB
Radisys MRF - Command Injection
CVE-2016-1004327 Jan 2017
An issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was dis
23RISK
open
Exploit-DB
OpenSSL 1.1.0 - Remote Client Denial of Service
CVE-2017-373026 Jan 2017
Bad (EC)DHE parameters cause a client crash
35RISK
open
previouspage 147 / 760next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.