Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
22,786 exploits
Exploit-DB
PHPMailer < 5.2.20 / SwiftMailer < 5.4.5-DEV / Zend Framework / zend-mail < 2.4.11 - 'AIO' 'PwnScriptum' Remote Code Execution
CVE-2016-1007402 Jan 2017
The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass
35RISK
open
Exploit-DB
PHPMailer < 5.2.20 / SwiftMailer < 5.4.5-DEV / Zend Framework / zend-mail < 2.4.11 - 'AIO' 'PwnScriptum' Remote Code Execution
CVE-2016-1004502 Jan 2017
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail comman
60RISK
open
Exploit-DB
Zend Framework / zend-mail < 2.4.11 - Remote Code Execution
CVE-2016-1003430 Dec 2016
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.
35RISK
open
Exploit-DB
Google Android - get_user/put_user (Metasploit)
CVE-2013-6282HIGHunder attack29 Dec 2016
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not
98RISK
open
Exploit-DB
PHPMailer < 5.2.18 - Remote Code Execution
CVE-2016-10033CRITICALunder attack29 Dec 2016
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
Exploit-DB
SwiftMailer < 5.4.5-DEV - Remote Code Execution
CVE-2016-1007428 Dec 2016
The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass
35RISK
open
Exploit-DB
SapLPD 7.40 - Denial of Service
CVE-2016-1007928 Dec 2016
SAPlpd through 7400.3.11.33 in SAP GUI 7.40 on Windows has a Denial of Service vulnerability (service crash) with a long
23RISK
open
Exploit-DB
PHPMailer < 5.2.20 - Remote Code Execution
CVE-2016-1004527 Dec 2016
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail comman
60RISK
open
Exploit-DB
PHPMailer < 5.2.20 - Remote Code Execution
CVE-2016-10033CRITICALunder attack27 Dec 2016
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
Exploit-DB
PHPMailer < 5.2.18 - Remote Code Execution
CVE-2016-10033CRITICALunder attack26 Dec 2016
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
Exploit-DB
Shutter 0.93.1 - Code Execution
CVE-2016-1008126 Dec 2016
/usr/bin/shutter in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a cra
23RISK
open
Exploit-DB
Wampserver 3.0.6 - Insecure File Permissions Privilege Escalation
CVE-2016-1003126 Dec 2016
WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYS
23RISK
open
Exploit-DB
Sonicwall 8.1.0.2-14sv - 'extensionsettings.cgi' Remote Command Injection (Metasploit)
CVE-2016-968325 Dec 2016
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerabili
28RISK
open
Exploit-DB
PHPMailer < 5.2.18 - Remote Code Execution
CVE-2016-10033CRITICALunder attack25 Dec 2016
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
Exploit-DB
Sonicwall 8.1.0.2-14sv - 'viewcert.cgi' Remote Command Injection (Metasploit)
CVE-2016-968424 Dec 2016
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerabili
23RISK
open
Exploit-DB
Freepbx < 2.11.1.5 - Remote Code Execution
CVE-2014-723523 Dec 2016
htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9,
35RISK
open
Exploit-DB
Apache mod_session_crypto - Padding Oracle
CVE-2016-073623 Dec 2016
In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured c
35RISK
open
Exploit-DB
OpenSSH < 7.4 - 'UsePrivilegeSeparation Disabled' Forwarded Unix Domain Sockets Privilege Escalation
CVE-2016-10010HIGH23 Dec 2016
sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which
41RISK
open
Exploit-DB
OpenSSH < 7.4 - agent Protocol Arbitrary Library Loading
CVE-2016-10009HIGH23 Dec 2016
Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute
53RISK
open
Exploit-DB
Apple macOS < 10.12.2 / iOS < 10.2 Kernel - ipc_port_t Reference Count Leak Due to Incorrect externalMethod Overrides Use-After-Free
CVE-2016-761222 Dec 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RISK
open
Exploit-DB
Microsoft Internet Explorer 11 - MSHTML CPaste­Command::Convert­Bitmapto­Png Heap Buffer Overflow (MS14-056)
CVE-2014-413822 Dec 2016
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RISK
open
Exploit-DB
Apple macOS 10.12 - Double vm_deallocate in Userspace MIG Code Use-After-Free
CVE-2016-763322 Dec 2016
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Directory S
23RISK
open
Exploit-DB
Apple macOS < 10.12.2 / iOS < 10.2 - '_kernelrpc_mach_port_insert_right_trap' Kernel Reference Count Leak / Use-After-Free
CVE-2016-762122 Dec 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RISK
open
Exploit-DB
Apple macOS 10.12.1 Kernel - Writable Privileged IOKit Registry Properties Code Execution
CVE-2016-761722 Dec 2016
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth"
23RISK
open
Exploit-DB
Apple macOS 10.12.1 / iOS < 10.2 - syslogd Arbitrary Port Replacement
CVE-2016-766022 Dec 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RISK
open
Exploit-DB
IBM AIX 6.1/7.1/7.2 - 'Bellmail' Local Privilege Escalation
CVE-2016-897222 Dec 2016
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the
23RISK
open
Exploit-DB
Apple macOS 10.12.1 / iOS < 10.2 - powerd Arbitrary Port Replacement
CVE-2016-766122 Dec 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The is
23RISK
open
Exploit-DB
Apple macOS < 10.12.2 / iOS < 10.2 - Broken Kernel Mach Port Name uref Handling Privileged Port Name Replacement Privilege Escalation
CVE-2016-763722 Dec 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RISK
open
Exploit-DB
Netgear WNR2000v5 - Remote Code Execution
CVE-2016-1017521 Dec 2016
The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. Thi
50RISK
open
Exploit-DB
Netgear WNR2000v5 - Remote Code Execution
CVE-2016-1017621 Dec 2016
The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the w
60RISK
open
previouspage 149 / 760next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.