Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
22,786 exploits
Exploit-DB
ImageMagick 7.0.1-0 / 6.9.3-9 - 'ImageTragick ' Multiple Vulnerabilities
CVE-2016-3715MEDIUMunder attack04 May 2016
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary fi
85RISK
open
Exploit-DB
WordPress Plugin Ninja Forms 2.9.36 < 2.9.42 - File Upload (Metasploit)
CVE-2016-120904 May 2016
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via
50RISK
open
Exploit-DB
Linux Kernel 4.4.x (Ubuntu 16.04) - 'double-fdput()' bpf(BPF_PROG_LOAD) Privilege Escalation
CVE-2016-455704 May 2016
The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly mai
43RISK
open
Exploit-DB
McAfee LiveSafe 14.0 - Relocations Processing Memory Corruption
CVE-2016-453504 May 2016
Integer signedness error in the AV engine before DAT 8145, as used in McAfee LiveSafe 14.0, allows remote attackers to c
23RISK
open
Exploit-DB
ImageMagick 7.0.1-0 / 6.9.3-9 - 'ImageTragick ' Multiple Vulnerabilities
CVE-2016-371704 May 2016
The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files vi
28RISK
open
Exploit-DB
CMS Made Simple < 1.12.1 / < 2.1.3 - Web Server Cache Poisoning
CVE-2016-278404 May 2016
CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduc
23RISK
open
Exploit-DB
Apache Struts - Dynamic Method Invocation Remote Code Execution (Metasploit)
CVE-2016-308102 May 2016
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, a
60RISK
open
Exploit-DB
QSEE - PRDiag* Commands Privilege Escalation
CVE-2015-663902 May 2016
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to
23RISK
open
Exploit-DB
PHP 7.0.5 - ZipArchive::getFrom* Integer Overflow
CVE-2016-307828 Apr 2016
Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denia
35RISK
open
Exploit-DB
Microsoft Windows Kernel - 'win32k.sys' TTF Processing EBLC / EBSC Tables Pool Corruption (MS16-039)
CVE-2016-014528 Apr 2016
The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
35RISK
open
Exploit-DB
Microsoft Windows - CSRSS BaseSrvCheckVDM Session 0 Process Creation Privilege Escalation (MS16-048)
CVE-2016-0151HIGHunder attackransomware27 Apr 2016
The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,
83RISK
open
Exploit-DB
RomPager 4.34 (Multiple Router Vendors) - 'Misfortune Cookie' Authentication Bypass
CVE-2015-922227 Apr 2016
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W,
23RISK
open
Exploit-DB
EMC ViPR SRM - Cross-Site Request Forgery
CVE-2016-089127 Apr 2016
Multiple cross-site request forgery (CSRF) vulnerabilities in administrative pages in EMC ViPR SRM before 3.7 allow remo
23RISK
open
Exploit-DB
Mach Race OSX - Local Privilege Escalation
CVE-2016-175727 Apr 2016
Race condition in the kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to execute arbitrary code
28RISK
open
Exploit-DB
Advantech Webaccess Dashboard Viewer - Arbitrary File Upload (Metasploit)
CVE-2016-085426 Apr 2016
Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess
60RISK
open
Exploit-DB
libgd 2.1.1 - Signedness Heap Overflow
CVE-2016-307426 Apr 2016
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of
35RISK
open
Exploit-DB
Microsoft Windows 7 < 10 / 2008 < 2012 (x86/x64) - Local Privilege Escalation (MS16-032)
CVE-2016-0099HIGHunder attackransomware25 Apr 2016
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RISK
open
Exploit-DB
Sony Playstation 4 (PS4) < 2.50 - WebKit Code Execution (PoC)
CVE-2014-130321 Apr 2016
Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox
35RISK
open
Exploit-DB
Symantec Brightmail 10.6.0-7 - LDAP Credentials Disclosure (Metasploit)
CVE-2016-220321 Apr 2016
The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discove
38RISK
open
Exploit-DB
Microsoft Windows 7 < 10 / 2008 < 2012 R2 (x86/x64) - Local Privilege Escalation (MS16-032) (PowerShell)
CVE-2016-0099HIGHunder attackransomware21 Apr 2016
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RISK
open
Exploit-DB
Microsoft Windows Kernel - DrawMenuBarTemp Wild-Write (MS16-039)
CVE-2016-014320 Apr 2016
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, W
23RISK
open
Exploit-DB
modified eCommerce Shopsoftware 2.0.0.0 rev 9678 - Blind SQL Injection
CVE-2016-369419 Apr 2016
Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, when the easybill-modul
23RISK
open
Exploit-DB
Novell ServiceDesk - (Authenticated) Arbitrary File Upload (Metasploit)
CVE-2016-159318 Apr 2016
Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remot
50RISK
open
Exploit-DB
Exim - 'perl_startup' Local Privilege Escalation (Metasploit)
CVE-2016-153115 Apr 2016
Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.
38RISK
open
Exploit-DB
AirOS 6.x - Arbitrary File Upload
CVE-2015-9266CRITICAL15 Apr 2016
Ubiquiti airOS HTTP(S) unauthenticated arbitrary file upload
85RISK
open
Exploit-DB
Microsoft Internet Explorer 9/10/11 - 'CDOMStringDataList::InitFromString' Out-of-Bounds Read (MS15-112)
CVE-2015-608614 Apr 2016
Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via
28RISK
open
Exploit-DB
Microsoft Excel - Out-of-Bounds Read Code Execution (MS16-042)
CVE-2016-012214 Apr 2016
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Word 2016 for Mac, Office Compa
35RISK
open
Exploit-DB
Oracle Application Testing Suite (ATS) 12.4.0.2.0 - Authentication Bypass / Arbitrary File Upload
CVE-2016-049213 Apr 2016
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RISK
open
Exploit-DB
Oracle Application Testing Suite (ATS) 12.4.0.2.0 - Authentication Bypass / Arbitrary File Upload
CVE-2016-049113 Apr 2016
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RISK
open
Exploit-DB
Novell ServiceDesk 6.5/7.0.3/7.1.0 - Multiple Vulnerabilities
CVE-2016-159311 Apr 2016
Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remot
50RISK
open
previouspage 163 / 760next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.