Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,023GitHub PoC 13,334VulnCheck XDB 8,195Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
22,786 exploits
Exploit-DB
iOS Kernel - IOHIDEventService Use-After-Free
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri
23RISK
open ↗Exploit-DB
iOS Kernel - AppleOscarCMA Use-After-Free
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri
23RISK
open ↗Exploit-DB
Apple Mac OSX - 'IntelAccelerator::gstqConfigure' Kernel NULL Dereference
The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial
23RISK
open ↗Exploit-DB
Apple Mac OSX / iOS Kernel - iokit Registry Iterator Manipulation Double-Free
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISK
open ↗Exploit-DB
Apple Mac OSX - IOBluetoothHCIPacketLogUserClient Memory Corruption
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISK
open ↗Exploit-DB
Apple Mac OSX - 'IOBluetoothHCIUserClient' Arbitrary Kernel Code Execution
The Bluetooth HCI interface in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial of serv
23RISK
open ↗Exploit-DB
Apple Mac OSX Kernel - IOAccelDisplayPipeUserClient2 Use-After-Free
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISK
open ↗Exploit-DB
Apple Mac OSX / iOS - Unsandboxable Kernel Code Exection Due to iokit Double Release in IOKit
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISK
open ↗Exploit-DB
Apple Mac OSX - 'gst_configure' Kernel Buffer Overflow
The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial
23RISK
open ↗Exploit-DB
Apple Mac OSX Kernel - IOAccelMemoryInfoUserClient Use-After-Free
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISK
open ↗Exploit-DB
iOS Kernel - AppleOscarAccelerometer Use-After-Free
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri
23RISK
open ↗Exploit-DB
Apple Mac OSX / iOS - Unsandboxable Kernel Use-After-Free in Mach Vouchers
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISK
open ↗Exploit-DB
Apple Mac OSX - IOSCSIPeripheralDeviceType00 Userclient Type 12 Kernel NULL Dereference
IOKit SCSI in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to exe
23RISK
open ↗Exploit-DB
Linux Kernel 3.x/4.x - prima WLAN Driver Heap Overflow
Heap-based buffer overflow in the private wireless extensions IOCTL implementation in wlan_hdd_wext.c in the WLAN (aka W
23RISK
open ↗Exploit-DB
Microsoft Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux (MS16-008) (2)
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,
23RISK
open ↗Exploit-DB
Microsoft Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux (MS16-008) (1)
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,
23RISK
open ↗Exploit-DB
Microsoft Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux (MS16-008) (1)
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,
23RISK
open ↗Exploit-DB
FreeBSD SCTP ICMPv6 - Error Processing
The Stream Control Transmission Protocol (SCTP) module in FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9, w
28RISK
open ↗Exploit-DB
Huawei Mate 7 - '/dev/hifi_misc' Privilege Escalation
Heap-based buffer overflow in the HIFI driver in Huawei Mate 7 phones with software MT7-UL00 before MT7-UL00C17B354, MT7
23RISK
open ↗Exploit-DB
NTP - Local Privilege Escalation
The crontab script in the ntp package before 1:4.2.6.p3+dfsg-1ubuntu3.11 on Ubuntu 12.04 LTS, before 1:4.2.6.p5+dfsg-3ub
23RISK
open ↗Exploit-DB
Linux Kernel 4.4.1 - REFCOUNT Overflow Use-After-Free in Keyrings Local Privilege Escalation (1)
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISK
open ↗Exploit-DB
Linux Kernel 4.4.1 - REFCOUNT Overflow Use-After-Free in Keyrings Local Privilege Escalation (2)
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISK
open ↗Exploit-DB
CesarFTP 0.99g - XCWD Denial of Service
Stack-based buffer overflow in CesarFTP 0.99g and earlier allows remote attackers to cause a denial of service (applicat
50RISK
open ↗Exploit-DB
SeaWell Networks Spectrum - Multiple Vulnerabilities
SeaWell Networks Spectrum SDC 02.05.00 has a default password of "admin" for the "admin" account.
23RISK
open ↗Exploit-DB
SeaWell Networks Spectrum - Multiple Vulnerabilities
Directory traversal vulnerability in configure_manage.php in SeaWell Networks Spectrum SDC 02.05.00.
23RISK
open ↗Exploit-DB
SeaWell Networks Spectrum - Multiple Vulnerabilities
SeaWell Networks Spectrum SDC 02.05.00 allows remote viewer users to perform administrative functions.
23RISK
open ↗Exploit-DB
mcart.xls Bitrix Module 6.5.2 - SQL Injection
Multiple SQL injection vulnerabilities in the mcart.xls module 6.5.2 and earlier for Bitrix allow remote authenticated u
23RISK
open ↗Exploit-DB
Roundcube Webmail 1.1.3 - Directory Traversal
Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before
28RISK
open ↗Exploit-DB
Microsoft Office / COM Object - 'WMALFXGFXDSP.dll' DLL Planting (MS16-007)
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
35RISK
open ↗Exploit-DB
WhatsUp Gold 16.3 - Remote Code Execution
The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.