Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,023GitHub PoC 13,334VulnCheck XDB 8,195Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
22,786 exploits
Exploit-DB
Symantec AntiVirus - Heap Overflow Modifying MIME Messages
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS
28RISK
open ↗Exploit-DB
Symantec AntiVirus - Missing Bounds Checks in dec2zip ALPkOldFormatDecompressor::UnShrink
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS
28RISK
open ↗Exploit-DB
Symantec AntiVirus - Unpacking RAR Multiple Remote Memory Corruptions
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS
28RISK
open ↗Exploit-DB
Microsoft Windows 7 SP1 (x86) - Local Privilege Escalation (MS16-014)
CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0
23RISK
open ↗Exploit-DB
Symantec AntiVirus - PowerPoint Misaligned Stream-cache Remote Stack Buffer Overflow (PoC)
Buffer overflow in Dec2SS.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec
28RISK
open ↗Exploit-DB
Symantec AntiVirus - TNEF Decoder Integer Overflow
Integer overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); S
28RISK
open ↗Exploit-DB
Wolf CMS 0.8.2 - Arbitrary File Upload (Metasploit)
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/
28RISK
open ↗Exploit-DB
Microsoft Internet Explorer 11 (Windows 10) - VBScript Memory Corruption (MS16-051)
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other
100RISK
open ↗Exploit-DB
Wolf CMS 0.8.2 - Arbitrary File Upload (Metasploit)
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/
28RISK
open ↗Exploit-DB
SAP NetWeaver AS JAVA 7.1 < 7.5 - Directory Traversal
Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary fil
83RISK
open ↗Exploit-DB
Microsoft Windows - 'gdi32.dll' Multiple DIB-Related EMF Record Handlers Heap Out-of-Bounds Reads/Memory Disclosure (MS16-074)
GDI32.dll in the Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, W
28RISK
open ↗Exploit-DB
SAP NetWeaver AS JAVA 7.1 < 7.5 - 'ctcprotocol Servlet' XML External Entity
XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remo
28RISK
open ↗Exploit-DB
Linux Kernel - 'ecryptfs' '/proc/$pid/environ' Local Privilege Escalation
The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to ga
23RISK
open ↗Exploit-DB
Microsoft Internet Explorer 11 - Garbage Collector Attribute Type Confusion (MS16-063)
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
35RISK
open ↗Exploit-DB
Microsoft Windows Kernel - 'ATMFD.dll' NamedEscape 0x250C Pool Corruption (MS16-074)
atmfd.dll in the Adobe Type Manager Font Driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Wind
23RISK
open ↗Exploit-DB
Microsoft Windows - Custom Font Disable Policy Bypass
The kernel-mode driver in Microsoft Windows 10 Gold and 1511 allows local users to gain privileges via a crafted applica
23RISK
open ↗Exploit-DB
Symphony CMS 2.6.7 - Session Fixation
Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers
23RISK
open ↗Exploit-DB
SolarWinds Virtualization Manager - Local Privilege Escalation
SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguratio
71RISK
open ↗Exploit-DB
Microsoft Windows 7 - win32k Bitmap Use-After-Free (MS16-062) (1)
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
23RISK
open ↗Exploit-DB
Microsoft Windows 7 - win32k Bitmap Use-After-Free (MS16-062) (2)
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
23RISK
open ↗Exploit-DB
Bomgar Remote Support - Code Execution (Metasploit)
Bomgar Remote Support before 15.1.1 allows remote attackers to execute arbitrary PHP code via crafted serialized data to
23RISK
open ↗Exploit-DB
Easy RM to MP3 Converter 2.7.3.700 - '.m3u' File (Universal ASLR + DEP Bypass)
Stack-based buffer overflow in Easy RM to MP3 Converter allows remote attackers to execute arbitrary code via a long fil
28RISK
open ↗Exploit-DB
Apache Struts - REST Plugin With Dynamic Method Invocation Remote Code Execution (Metasploit)
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, a
60RISK
open ↗Exploit-DB
Apple Mac OSX Kernel - Null Pointer Dereference in AppleGraphicsDeviceControl
AppleGraphicsDeviceControlClient in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged
23RISK
open ↗Exploit-DB
Apple Mac OSX Kernel - NULL Dereference in IOAccelSharedUserClient2::page_off_resource
The IOAccelSharedUserClient2::page_off_resource method in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1
23RISK
open ↗Exploit-DB
Apple Mac OSX Kernel - Out-of-Bounds Read of Object Pointer Due to Insufficient Checks in Raw Cast to enum Type
The IOHIDDevice::handleReportWithTime function in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and wa
23RISK
open ↗Exploit-DB
Apple Mac OSX Kernel - Null Pointer Dereference in AppleMuxControl.kext
The AppleGraphicsControlClient::checkArguments method in AppleGraphicsControl in Apple OS X before 10.11.5 allows attack
23RISK
open ↗Exploit-DB
Apple Mac OSX Kernel - NULL Dereference in CoreCaptureResponder Due to Unchecked Return Value
CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RISK
open ↗Exploit-DB
Apple Mac OSX Kernel - Null Pointer Dereference in IOAudioEngine
IOAudioFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a
23RISK
open ↗Exploit-DB
Apple Mac OSX Kernel - GeForce GPU Driver Stack Buffer Overflow
The NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privi
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.