Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,184cataloged exploits
37,029CVEs with public exploitation
24,695lab-tested
24,476 exploits
Exploit-DBVexDay Proof
HTML Compiler - Remote Code Execution
CVE-2014-6332HIGHunder attackremotewindows20 Oct 2015
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RISK
open
Exploit-DBVexDay Proof
Nibbleblog 4.0.3 - Arbitrary File Upload (Metasploit)
CVE-2015-6967remotephp19 Oct 2015
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RISK
open
Exploit-DBVexDay Proof
Adobe Flash - 'IExternalizable.writeExternal' Type Confusion
CVE-2015-7645HIGHunder attackransomwaredosmultiple19 Oct 2015
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535
83RISK
open
Exploit-DB
Belkin N150 Router 1.00.08/1.00.09 - Directory Traversal
CVE-2014-2962webappshardware19 Oct 2015
Absolute path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware befor
50RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 10 - Sandboxed Mount Reparse Point Creation Mitigation Bypass (MS15-111)
CVE-2015-2553localwindows15 Oct 2015
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RISK
open
Exploit-DB
Linux/MIPS Kernel 2.6.36 - 'NetUSB' Remote Code Execution
CVE-2015-3036remotemultiple14 Oct 2015
Stack-based buffer overflow in the run_init_sbus function in the KCodes NetUSB module for the Linux kernel, as used in c
28RISK
open
Exploit-DB
ZYXEL PMG5318-B20A - OS Command Injection
CVE-2015-6018webappshardware14 Oct 2015
The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attac
28RISK
open
Exploit-DB
libsndfile 1.0.25 - Local Heap Overflow
CVE-2015-7805localmultiple13 Oct 2015
Heap-based buffer overflow in libsndfile 1.0.25 allows remote attackers to have unspecified impact via the headindex val
28RISK
open
Exploit-DB
ZHONE < S3.0.501 - Multiple Vulnerabilities
CVE-2014-9118remotehardware13 Oct 2015
The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary comm
35RISK
open
Exploit-DB
F5 Big-IP 10.2.4 Build 595.0 Hotfix HF3 - Directory Traversal
CVE-2015-4040webappshardware13 Oct 2015
Directory traversal vulnerability in the configuration utility in F5 BIG-IP before 12.0.0 and Enterprise Manager 3.0.0 t
23RISK
open
Exploit-DB
ZHONE < S3.0.501 - Multiple Vulnerabilities
CVE-2014-8357remotehardware13 Oct 2015
backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a
23RISK
open
Exploit-DB
ZHONE < S3.0.501 - Multiple Vulnerabilities
CVE-2014-8356remotehardware13 Oct 2015
The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended a
23RISK
open
Exploit-DB
Kallithea 0.2.9 - 'came_from' HTTP Response Splitting
CVE-2015-5285webappsmultiple08 Oct 2015
CRLF injection vulnerability in Kallithea before 0.3 allows remote attackers to inject arbitrary HTTP headers and conduc
23RISK
open
Exploit-DB
Zope Management Interface 4.3.7 - Cross-Site Request Forgery
CVE-2015-7293webappspython07 Oct 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone bef
23RISK
open
Exploit-DBVexDay Proof
TrueCrypt 7 / VeraCrypt 1.13 - Drive Letter Symbolic Link Creation Privilege Escalation
CVE-2015-7358localwindows_x8605 Oct 2015
The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when run
23RISK
open
Exploit-DBVexDay Proof
Kaseya Virtual System Administrator (VSA) - 'uploader.aspx' Arbitrary File Upload (Metasploit)
CVE-2015-6922remotewindows05 Oct 2015
Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before
60RISK
open
Exploit-DB
ElasticSearch 1.6.0 - Arbitrary File Download
CVE-2015-5531webappslinux02 Oct 2015
Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unsp
60RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX 10.9.5/10.10.5 - 'rsh/libmalloc' Local Privilege Escalation
CVE-2015-5889localosx01 Oct 2015
rsh in the remote_cmds component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors inv
38RISK
open
Exploit-DB
Bosch Security Systems Dinion NBN-498 - Web Interface XML Injection
CVE-2015-6970webappshardware01 Oct 2015
The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows r
23RISK
open
Exploit-DBVexDay Proof
ManageEngine EventLog Analyzer - Remote Code Execution (Metasploit)
CVE-2015-7387remotewindows29 Sep 2015
ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions
60RISK
open
Exploit-DBVexDay Proof
Kaseya Virtual System Administrator (VSA) - Multiple Vulnerabilities (2)
CVE-2015-6922webappsasp29 Sep 2015
Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before
60RISK
open
Exploit-DB
Apport 2.19 (Ubuntu 15.04) - Local Privilege Escalation
CVE-2015-1338locallinux29 Sep 2015
kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly ga
23RISK
open
Exploit-DBVexDay Proof
Kaseya Virtual System Administrator (VSA) - Multiple Vulnerabilities (2)
CVE-2015-6589webappsasp29 Sep 2015
Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before
28RISK
open
Exploit-DB
Mango Automation 2.6.0 - Multiple Vulnerabilities
CVE-2015-7900webappsjsp28 Sep 2015
Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote attackers to obtain sensitive
23RISK
open
Exploit-DB
Mango Automation 2.6.0 - Multiple Vulnerabilities
CVE-2015-7902webappsjsp28 Sep 2015
Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 provides different error messages for failed
23RISK
open
Exploit-DB
PCMan FTP Server 2.0.7 - Directory Traversal
CVE-2015-7601remotewindows28 Sep 2015
Directory traversal vulnerability in PCMan's FTP Server 2.0.7 allows remote attackers to read arbitrary files via a ..//
50RISK
open
Exploit-DB
Mango Automation 2.6.0 - Multiple Vulnerabilities
CVE-2015-7901webappsjsp28 Sep 2015
Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to execut
23RISK
open
Exploit-DB
BisonWare BisonFTP Server 3.5 - Directory Traversal
CVE-2015-7602remotewindows28 Sep 2015
Directory traversal vulnerability in BisonWare BisonFTP 3.5 allows remote attackers to read arbitrary files via a ../ (d
50RISK
open
Exploit-DB
vTiger CRM 6.3.0 - (Authenticated) Remote Code Execution
CVE-2015-6000webappsphp28 Sep 2015
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger
50RISK
open
Exploit-DB
Mango Automation 2.6.0 - Multiple Vulnerabilities
CVE-2015-7903webappsjsp28 Sep 2015
SQL injection vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote
23RISK
open
previouspage 182 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.