Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
80,095cataloged exploits
36,945CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,476Referência 23,442GitHub PoC 15,312VulnCheck XDB 8,970Nuclei 4,393Metasploit 3,502✓ verified onlyrecentpopularrisk
24,476 exploits
Exploit-DB✓ VexDay Proof
Apple macOS 10.12.1 / iOS < 10.2 - powerd Arbitrary Port Replacement
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The is
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS < 10.12.2 / iOS < 10.2 - Broken Kernel Mach Port Name uref Handling Privileged Port Name Replacement Privilege Escalation
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RISK
open ↗Exploit-DB
IBM AIX 6.1/7.1/7.2 - 'Bellmail' Local Privilege Escalation
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS 10.12.1 Kernel - Writable Privileged IOKit Registry Properties Code Execution
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth"
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS 10.12 - Double vm_deallocate in Userspace MIG Code Use-After-Free
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Directory S
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 11 - MSHTML CPasteCommand::ConvertBitmaptoPng Heap Buffer Overflow (MS14-056)
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS < 10.12.2 / iOS < 10.2 - '_kernelrpc_mach_port_insert_right_trap' Kernel Reference Count Leak / Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS < 10.12.2 / iOS < 10.2 Kernel - ipc_port_t Reference Count Leak Due to Incorrect externalMethod Overrides Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Edge - Internationalization Initialization Type Confusion (MS16-144)
The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary c
35RISK
open ↗Exploit-DB
Netgear WNR2000v5 - Remote Code Execution
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cg
100RISK
open ↗Exploit-DB
Netgear WNR2000v5 - Remote Code Execution
The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the w
60RISK
open ↗Exploit-DB
Netgear WNR2000v5 - Remote Code Execution
The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. Thi
50RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Edge - SIMD.toLocaleString Uninitialized Memory (MS16-145)
The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (m
35RISK
open ↗Exploit-DB✓ VexDay Proof
Google Android - WifiNative::setHotlist Stack Overflow
An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to execute arbitrary code wi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 11 - MSHTML CSpliceTreeEngine::RemoveSplice Use-After-Free (MS14-035)
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RISK
open ↗Exploit-DB✓ VexDay Proof
Google Chrome < 31.0.1650.48 - HTTP 1xx base::StringTokenizerT<...>::QuickGetNext Out-of-Bounds Read
net/http/http_stream_parser.cc in Google Chrome before 31.0.1650.48 does not properly process HTTP Informational (aka 1x
23RISK
open ↗Exploit-DB✓ VexDay Proof
Naenara Browser 3.5 (RedStar 3.0 Desktop) - 'JACKRABBIT' Client-Side Command Execution
js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1
50RISK
open ↗Exploit-DB✓ VexDay Proof
RedStar 3.0 Server - 'Shellshock' 'BEAM' / 'RSSMON' Command Injection
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS 10.12 16A323 XNU Kernel / iOS 10.1.1 - 'set_dp_control_port' Lack of Locking Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The is
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS 10.12 16A323 XNU Kernel / iOS 10.1.1 - 'set_dp_control_port' Lack of Locking Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS 10.12 16A323 XNU Kernel / iOS 10.1.1 - 'set_dp_control_port' Lack of Locking Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 9 - IEFRAME CView::EnsureSize Use-After-Free (MS13-021)
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary co
53RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 9 - IEFRAME CMarkup::RemovePointerPos Use-After-Free (MS13-055)
Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (mem
35RISK
open ↗Exploit-DB✓ VexDay Proof
Nagios < 4.2.4 - Local Privilege Escalation
base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root
23RISK
open ↗Exploit-DB✓ VexDay Proof
Nagios < 4.2.2 - Arbitrary Code Execution
MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write
28RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Animate 15.2.1.95 - Memory Corruption
Adobe Animate versions 15.2.1.95 and earlier have an exploitable memory corruption vulnerability. Successful exploitatio
28RISK
open ↗Exploit-DB
Apport 2.x (Ubuntu Desktop 12.10 < 16.04) - Local Code Execution
An issue was discovered in Apport before 2.20.4. A malicious Apport crash file can contain a restart command in `Respawn
23RISK
open ↗Exploit-DB
Apport 2.x (Ubuntu Desktop 12.10 < 16.04) - Local Code Execution
An issue was discovered in Apport before 2.20.4. There is a path traversal issue in the Apport crash file "Package" and
23RISK
open ↗Exploit-DB
Apport 2.x (Ubuntu Desktop 12.10 < 16.04) - Local Code Execution
An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates t
28RISK
open ↗Exploit-DB✓ VexDay Proof
APT - Repository Signing Bypass via Memory Allocation Failure
The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.