Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
22,786 exploits
Exploit-DB
Microsoft Windows - 'ATMFD.DLL' Out-of-Bounds Read Due to Malformed FDSelect Offset in the CFF Table
CVE-2015-246221 Aug 2015
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
35RISK
open
Exploit-DB
Microsoft Windows - 'win32k.sys' TTF Font Processing win32k!fsc_BLTHoriz Out-of-Bounds Pool Write
CVE-2015-246421 Aug 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
35RISK
open
Exploit-DB
Netsweeper 4.0.8 - Authentication Bypass (via New Profile Creation)
CVE-2014-961821 Aug 2015
The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote att
60RISK
open
Exploit-DB
Microsoft Windows - 'win32k.sys' TTF Font Processing IUP[] Program Instruction Pool-Based Buffer Overflow
CVE-2015-245521 Aug 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
35RISK
open
Exploit-DB
Netsweeper 4.0.4 - SQL Injection
CVE-2014-961221 Aug 2015
SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1
23RISK
open
Exploit-DB
Microsoft Office 2007 - 'mso.dll' Use-After-Free (MS15-081)
CVE-2015-246721 Aug 2015
Microsoft Office 2007 SP3 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Offic
28RISK
open
Exploit-DB
Microsoft Windows - 'win32k.sys' TTF Font Processing win32k!scl_ApplyTranslation Pool-Based Buffer Overflow
CVE-2015-245621 Aug 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
35RISK
open
Exploit-DB
Netsweeper 4.0.8 - Authentication Bypass (via Disabling of IP Quarantine)
CVE-2014-961021 Aug 2015
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication an
23RISK
open
Exploit-DB
WordPress Plugin MDC Private Message 1.0.0 - Persistent Cross-Site Scripting
CVE-2015-680521 Aug 2015
Cross-site scripting (XSS) vulnerability in the MDC Private Message plugin 1.0.0 for WordPress allows remote authenticat
23RISK
open
Exploit-DB
Adobe Flash AS2 - MovieClip.scrollRect Use-After-Free
CVE-2015-513019 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RISK
open
Exploit-DB
Adobe Flash (Linux x64) - Bad Dereference at 0x23c
CVE-2015-554619 Aug 2015
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RISK
open
Exploit-DB
Adobe Flash AS2 - DisplacementMapFilter.mapBitmap Use-After-Free (1)
CVE-2015-308019 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows
35RISK
open
Exploit-DB
Adobe Flash - Overflow in ID3 Tag Parsing
CVE-2015-556019 Aug 2015
Integer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR
35RISK
open
Exploit-DB
Adobe Flash - textfield.gridFitType Use-After-Free
CVE-2015-555719 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RISK
open
Exploit-DB
Adobe Flash - Setting Value Use-After-Free
CVE-2015-553919 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RISK
open
Exploit-DB
Adobe Flash - XML.childNodes Use-After-Free
CVE-2015-554019 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RISK
open
Exploit-DB
Flash Broker-Based - Sandbox Escape via Timing Attack Against File Moving
CVE-2015-308119 Aug 2015
Race condition in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and b
28RISK
open
Exploit-DB
Adobe Flash - swapDepths Use-After-Free
CVE-2015-555019 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RISK
open
Exploit-DB
Adobe Flash AS2 - textfield.filters Use-After-Free (3)
CVE-2015-556119 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RISK
open
Exploit-DB
Adobe Flash - attachMovie Use-After-Free
CVE-2015-555119 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RISK
open
Exploit-DB
Adobe Flash - createTextField Use-After-Free
CVE-2015-555619 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RISK
open
Exploit-DB
Flash Boundless Tunes - Universal SOP Bypass Through ActionSctipt's Sound Object
CVE-2015-511619 Aug 2015
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481
28RISK
open
Exploit-DB
Adobe Flash AS2 - textfield.filters Use-After-Free (1)
CVE-2015-310619 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows
35RISK
open
Exploit-DB
Flash - Issues in DefineBitsLossless and DefineBitsLossless2 Leads to Using Uninitialized Memory
CVE-2015-309319 Aug 2015
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460
35RISK
open
Exploit-DB
Adobe Flash - Pointer Crash in XML Handling
CVE-2015-554819 Aug 2015
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RISK
open
Exploit-DB
Adobe Flash - Out-of-Bounds Read in UTF Conversion
CVE-2015-313419 Aug 2015
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481
28RISK
open
Exploit-DB
Adobe Flash - Pointer Crash in Button Handling
CVE-2015-554719 Aug 2015
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RISK
open
Exploit-DB
Adobe Flash - Heap Buffer Overflow Loading '.FLV' File with Nellymoser Audio Codec
CVE-2015-443219 Aug 2015
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows an
35RISK
open
Exploit-DB
Adobe Flash - Pointer Crash in Drawing and Bitmap Handling
CVE-2015-554419 Aug 2015
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RISK
open
Exploit-DB
Adobe Flash - Heap Use-After-Free in SurfaceFilterList::C​reateFromScriptAtom
CVE-2015-556319 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RISK
open
previouspage 180 / 760next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.