Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
23,288 exploits
Exploit-DB
Adobe Flash AS2 - textfield.filters Use-After-Free (2)
CVE-2015-311819 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows
35RISK
open
Exploit-DB
Adobe Flash - createTextField Use-After-Free
CVE-2015-555619 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RISK
open
Exploit-DB
Adobe Flash - Heap Use-After-Free in SurfaceFilterList::C​reateFromScriptAtom
CVE-2015-556319 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RISK
open
Exploit-DB
Adobe Flash AS2 - DisplacementMapFilter.mapBitmap Use-After-Free (1)
CVE-2015-308019 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows
35RISK
open
Exploit-DB
Adobe Flash - Pointer Crash After Continuing Slow Script
CVE-2015-554519 Aug 2015
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RISK
open
Exploit-DB
Adobe Flash - Pointer Crash in Drawing and Bitmap Handling
CVE-2015-554419 Aug 2015
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RISK
open
Exploit-DB
Adobe Flash AS2 - textfield.filters Use-After-Free (1)
CVE-2015-310619 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows
35RISK
open
Exploit-DB
Flash Boundless Tunes - Universal SOP Bypass Through ActionSctipt's Sound Object
CVE-2015-511619 Aug 2015
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481
28RISK
open
Exploit-DB
Flash Broker-Based - Sandbox Escape via Unexpected Directory Lock
CVE-2015-308319 Aug 2015
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460
35RISK
open
Exploit-DB
Adobe Flash - Pointer Crash in Button Handling
CVE-2015-554719 Aug 2015
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RISK
open
Exploit-DB
Adobe Flash - Pointer Crash in XML Handling
CVE-2015-554819 Aug 2015
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RISK
open
Exploit-DB
Adobe Flash - Out-of-Bounds Read in UTF Conversion
CVE-2015-313419 Aug 2015
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481
28RISK
open
Exploit-DB
Adobe Flash - Heap Buffer Overflow Loading '.FLV' File with Nellymoser Audio Codec
CVE-2015-443219 Aug 2015
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows an
35RISK
open
Exploit-DB
Adobe Flash - XMLSocket Destructor Not Cleared Before Setting User Data in connect
CVE-2015-555419 Aug 2015
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RISK
open
Exploit-DB
Adobe Flash - Shared Object Type Confusion
CVE-2015-556219 Aug 2015
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RISK
open
Exploit-DB
Adobe Flash - Type Confusion in TextRenderer.setAdvancedAntialiasingTable
CVE-2015-555519 Aug 2015
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RISK
open
Exploit-DB
Adobe Flash - FileReference Class Type Confusion
CVE-2015-555819 Aug 2015
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RISK
open
Exploit-DB
Flash Broker-Based - Sandbox Escape via Forward Slash Instead of Backslash
CVE-2015-308219 Aug 2015
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460
35RISK
open
Exploit-DB
Adobe Flash - Heap Buffer Overflow Due to Indexing Error When Loading FLV File
CVE-2015-511819 Aug 2015
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows an
28RISK
open
Exploit-DB
Adobe Flash AS2 - Color.setRGB Use-After-Free
CVE-2015-312819 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows
35RISK
open
Exploit-DB
Adobe Flash - Display List Handling Use-After-Free
CVE-2015-312419 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows
35RISK
open
Exploit-DB
Adobe Flash - Bad Write in XML When Callback Modifies XML Tree During Property Delete
CVE-2015-554919 Aug 2015
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RISK
open
Exploit-DB
Adobe Flash - NetConnection.connect Use-After-Free
CVE-2015-310719 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows
35RISK
open
Exploit-DB
Adobe Flash - Drawing Methods 'this' Use-After-Free
CVE-2015-313719 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows
35RISK
open
Exploit-DB
Symantec Endpoint Protection Manager - Authentication Bypass / Code Execution (Metasploit)
CVE-2015-148918 Aug 2015
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat
43RISK
open
Exploit-DB
Cisco Unified Communications Manager - Multiple Vulnerabilities
CVE-2014-800818 Aug 2015
Absolute path traversal vulnerability in the Real-Time Monitoring Tool (RTMT) API in Cisco Unified Communications Manage
23RISK
open
Exploit-DB
WordPress Plugin WP Symposium 15.1 - 'get_album_item.php' SQL Injection
CVE-2015-652218 Aug 2015
SQL injection vulnerability in the WP Symposium plugin before 15.8 for WordPress allows remote attackers to execute arbi
60RISK
open
Exploit-DB
Symantec Endpoint Protection Manager - Authentication Bypass / Code Execution (Metasploit)
CVE-2015-148718 Aug 2015
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat
50RISK
open
Exploit-DB
Symantec Endpoint Protection Manager - Authentication Bypass / Code Execution (Metasploit)
CVE-2015-148618 Aug 2015
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers t
50RISK
open
Exploit-DB
Cisco Unified Communications Manager - Multiple Vulnerabilities
CVE-2014-6271CRITICALunder attack18 Aug 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
previouspage 181 / 777next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.