Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
22,786 exploits
Exploit-DB
Wireshark - find_signature Stack Out-of-Bounds Read
CVE-2015-872616 Dec 2015
wiretap/vwr.c in the VeriWave file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate cer
23RISK
open
Exploit-DB
Wireshark - dissect_diameter_base_framed_ipv6_prefix Stack Buffer Overflow
CVE-2015-872516 Dec 2015
The dissect_diameter_base_framed_ipv6_prefix function in epan/dissectors/packet-diameter.c in the DIAMETER dissector in
23RISK
open
Exploit-DB
Wireshark - dissect_diameter_base_framed_ipv6_prefix Stack Buffer Overflow
CVE-2015-874016 Dec 2015
The dissect_tds7_colmetadata_token function in epan/dissectors/packet-tds.c in the TDS dissector in Wireshark 2.0.x befo
23RISK
open
Exploit-DB
Wireshark - addresses_equal 'dissect_rsvp_common' Use-After-Free
CVE-2015-872716 Dec 2015
The dissect_rsvp_common function in epan/dissectors/packet-rsvp.c in the RSVP dissector in Wireshark 1.12.x before 1.12.
23RISK
open
Exploit-DB
Wireshark - AirPDcapPacketProcess Stack Buffer Overflow
CVE-2015-872316 Dec 2015
The AirPDcapPacketProcess function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before 1.12.9 an
23RISK
open
Exploit-DB
Wireshark - dissect_zcl_pwr_prof_pwrprofstatersp Static Out-of-Bounds Read
CVE-2015-873216 Dec 2015
The dissect_zcl_pwr_prof_pwrprofstatersp function in epan/dissectors/packet-zbee-zcl-general.c in the ZigBee ZCL dissect
23RISK
open
Exploit-DB
Wireshark - my_dgt_tbcd_unpack Static Buffer Overflow
CVE-2015-872816 Dec 2015
The Mobile Identity parser in (1) epan/dissectors/packet-ansi_a.c in the ANSI A dissector and (2) epan/dissectors/packet
23RISK
open
Exploit-DB
Joomla! 1.5 < 3.4.5 - Object Injection Remote Command Execution
CVE-2015-856215 Dec 2015
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISK
open
Exploit-DB
ManageEngine Desktop Central 9 - FileUploadServlet ConnectionId (Metasploit)
CVE-2015-824915 Dec 2015
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and e
60RISK
open
Exploit-DB
Jenkins CLI - RMI Java Deserialization (Metasploit)
CVE-2015-810315 Dec 2015
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary co
60RISK
open
Exploit-DB
Microsoft Office / COM Object - DLL Planting with 'comsvcs.dll' Delay Load of 'mqrt.dll' (MS15-132)
CVE-2015-613214 Dec 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
60RISK
open
Exploit-DB
Microsoft Internet Explorer 11 - MSHTML!CObjectElement Use-After-Free (MS15-124)
CVE-2015-615214 Dec 2015
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RISK
open
Exploit-DB
Adobe Flash - Type Confusion in Serialization with ObjectEncoder.dynamicPropertyWriter
CVE-2015-764814 Dec 2015
Adobe Flash Player before 18.0.0.255 and 19.x before 19.0.0.226 on Windows and OS X and before 11.2.202.540 on Linux all
28RISK
open
Exploit-DB
Adobe Flash - Type Confusion in IExternalizable.readExternal When Performing Local Serialization
CVE-2015-764714 Dec 2015
Adobe Flash Player before 18.0.0.255 and 19.x before 19.0.0.226 on Windows and OS X and before 11.2.202.540 on Linux all
28RISK
open
Exploit-DB
Bitrix bitrix.xscan Module 1.0.3 - Directory Traversal
CVE-2015-835714 Dec 2015
Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users t
23RISK
open
Exploit-DB
Bitrix bitrix.mpbuilder Module 1.0.10 - Local File Inclusion
CVE-2015-835814 Dec 2015
Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators t
23RISK
open
Exploit-DB
Apple Mac OSX 10.11 - FTS Deep Structure of the FileSystem Buffer Overflow
CVE-2015-703909 Dec 2015
Buffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows rem
28RISK
open
Exploit-DB
Microsoft Windows Media Center - '.Link' File Incorrectly Resolved Reference (MS15-134)
CVE-2015-612709 Dec 2015
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows remote attackers t
50RISK
open
Exploit-DB
Microsoft Office / COM Object - 'els.dll' DLL Planting (MS15-134)
CVE-2015-612809 Dec 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandle library loading, which allo
60RISK
open
Exploit-DB
Microsoft Windows Media Center Library - Parsing Remote Code Execution aka 'self-executing' MCL File
CVE-2015-613109 Dec 2015
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows remote attackers t
35RISK
open
Exploit-DB
Atlassian HipChat for Jira Plugin - Velocity Template Injection (Metasploit)
CVE-2015-560308 Dec 2015
The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java
50RISK
open
Exploit-DB
Microsoft Office - OLE Multiple DLL Side Loading Vulnerabilities (MS15-132/MS16-014/MS16-025/MS16-041/MS16-070) (Metasploit)
CVE-2015-613208 Dec 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
60RISK
open
Exploit-DB
Microsoft Office - OLE Multiple DLL Side Loading Vulnerabilities (MS15-132/MS16-014/MS16-025/MS16-041/MS16-070) (Metasploit)
CVE-2016-010008 Dec 2015
Microsoft Windows Vista SP2 and Server 2008 SP2 mishandle library loading, which allows local users to gain privileges v
50RISK
open
Exploit-DB
Microsoft Office - OLE Multiple DLL Side Loading Vulnerabilities (MS15-132/MS16-014/MS16-025/MS16-041/MS16-070) (Metasploit)
CVE-2016-3235HIGHunder attack08 Dec 2015
Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 misha
98RISK
open
Exploit-DB
Microsoft Office - OLE Multiple DLL Side Loading Vulnerabilities (MS15-132/MS16-014/MS16-025/MS16-041/MS16-070) (Metasploit)
CVE-2016-004108 Dec 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold an
60RISK
open
Exploit-DB
Microsoft Office - OLE Multiple DLL Side Loading Vulnerabilities (MS15-132/MS16-014/MS16-025/MS16-041/MS16-070) (Metasploit)
CVE-2015-613308 Dec 2015
Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511
50RISK
open
Exploit-DB
Microsoft Office - OLE Multiple DLL Side Loading Vulnerabilities (MS15-132/MS16-014/MS16-025/MS16-041/MS16-070) (Metasploit)
CVE-2015-612808 Dec 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandle library loading, which allo
60RISK
open
Exploit-DB
WordPress Plugin Gwolle Guestbook 1.5.3 - Remote File Inclusion
CVE-2015-835103 Dec 2015
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ
35RISK
open
Exploit-DB
Oracle BeeHive 2 - 'voice-servlet processEvaluation()' Write File (Metasploit)
CVE-2010-441703 Dec 2015
Unspecified vulnerability in the Services for Beehive component in Oracle Fusion Middleware 2.0.1.0, 2.0.1.1, 2.0.1.2, 2
60RISK
open
Exploit-DB
Advantech Switch - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)
CVE-2014-6271CRITICALunder attack02 Dec 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
previouspage 172 / 760next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.