Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,023GitHub PoC 13,334VulnCheck XDB 8,195Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
22,786 exploits
Exploit-DB
libxml2 - xmlParserPrintFileContextInternal Heap Buffer Overread
The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 1
23RISK
open ↗Exploit-DB
Mambo < 4.5.3h - Multiple Vulnerabilities
SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arb
23RISK
open ↗Exploit-DB
Dell OpenManage Server Administrator 8.2 - (Authenticated) Directory Traversal
Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated adminis
23RISK
open ↗Exploit-DB
libquicktime 1.2.4 - Integer Overflow
Integer overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to caus
23RISK
open ↗Exploit-DB
BlackBerry Enterprise Service < 12.4 (BES12) Self-Service - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server
23RISK
open ↗Exploit-DB
Linux Kernel 3.x (Ubuntu 14.04 / Mint 17.3 / Fedora 22) - Double-free usb-midi SMEP Privilege Escalation
Double free vulnerability in the snd_usbmidi_create function in sound/usb/midi.c in the Linux kernel before 4.5 allows p
23RISK
open ↗Exploit-DB
BlackBerry Enterprise Service < 12.4 (BES12) Self-Service - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4
23RISK
open ↗Exploit-DB
Ubuntu < 15.10 - PT Chown Arbitrary PTs Access Via User Namespace Privilege Escalation
pt_chown in the glibc package before 2.19-18+deb8u4 on Debian jessie; the elibc package before 2.15-0ubuntu10.14 on Ubun
23RISK
open ↗Exploit-DB
PEAR LiveUser < 0.16.8 - Arbitrary File Access
Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Reposito
23RISK
open ↗Exploit-DB
QuickHeal 16.00 - 'webssx.sys' Driver Denial of Service
The webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service.
23RISK
open ↗Exploit-DB
Geeklog < 1.4.0 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in Geeklog 1.4.0 before 1.4.0sr1 and 1.3.11 before 1.3.11sr4 allow remote attacke
23RISK
open ↗Exploit-DB
Adobe Flash - SimpleButton Creation Type Confusion
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on
28RISK
open ↗Exploit-DB
ADOdb < 4.71 - Cross Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow re
23RISK
open ↗Exploit-DB
Adobe Flash - ATF Processing Heap Overflow
Heap-based buffer overflow in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS
35RISK
open ↗Exploit-DB
Adobe Flash - LoadVars.decode Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and
35RISK
open ↗Exploit-DB
Adobe Flash - Sound.loadPCMFromByteArray Dangling Pointer
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and
83RISK
open ↗Exploit-DB
Inductive Automation Ignition 7.8.1 - Remote Leakage Of Shared Buffers
The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive informat
60RISK
open ↗Exploit-DB
Adobe Flash - textfield Constructor Type Confusion
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on
28RISK
open ↗Exploit-DB
Adobe Flash - BitmapData.drawWithQuality Heap Overflow
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on
28RISK
open ↗Exploit-DB
Adobe Flash - Out-of-Bounds Image Read
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on
28RISK
open ↗Exploit-DB
Adobe Flash - H264 File Stack Corruption
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on
28RISK
open ↗Exploit-DB
Flash ActiveX 28.0.0.137 - Code Execution (1)
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISK
open ↗Exploit-DB
glibc - 'getaddrinfo' Stack Buffer Overflow (PoC)
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RISK
open ↗Exploit-DB
Microsoft Windows 7 (x86) - 'afd.sys' Dangling Pointer Privilege Escalation (MS14-040)
Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Wind
28RISK
open ↗Exploit-DB
Microsoft Windows - Kerberos Security Feature Bypass (MS16-014)
Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
28RISK
open ↗Exploit-DB
Flash ActiveX 28.0.0.137 - Code Execution (2)
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISK
open ↗Exploit-DB
Yeager CMS 1.2.1 - Multiple Vulnerabilities
SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the a
23RISK
open ↗Exploit-DB
Yeager CMS 1.2.1 - Multiple Vulnerabilities
Unrestricted file upload vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary code by uploadin
23RISK
open ↗Exploit-DB
Microsoft Windows 7 SP1 (x86) - 'WebDAV' Local Privilege Escalation (MS16-016) (1)
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RISK
open ↗Exploit-DB
Apache Sling Framework (Adobe AEM) 2.3.6 - Information Disclosure
The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows r
35RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.