Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DBVexDay Proof
Cisco AnyConnect Secure Mobility Client 3.1.08009 - Local Privilege Escalation
CVE-2015-6305localwindows22 Sep 2015
Untrusted search path vulnerability in the CMainThread::launchDownloader function in vpndownloader.exe in Cisco AnyConne
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Null Pointer Dereference with Window Station and Clipboard (MS15-061)
CVE-2015-1721doswindows_x8622 Sep 2015
The kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Pool Buffer Overflow Drawing Caption Bar (MS15-061)
CVE-2015-1727doswindows_x8622 Sep 2015
Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows S
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX Regex Engine (TRE) - Integer Signedness / Overflow
CVE-2015-3798dososx22 Sep 2015
The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent attackers to execute
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Use-After-Free with Cursor Object (MS15-097)
CVE-2015-2517doswindows_x8622 Sep 2015
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'DeferWindowPos' Use-After-Free (MS15-073)
CVE-2015-2366doswindows_x8622 Sep 2015
win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Wi
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'HmgAllocateObjectAttr' Use-After-Free (MS15-061)
CVE-2015-1726doswindows_x8622 Sep 2015
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Use-After-Free with Printer Device Contexts (MS15-097)
CVE-2015-2507doswindows_x8622 Sep 2015
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'FlashWindowEx​' Memory Corruption (MS15-097)
CVE-2015-2511doswindows_x8622 Sep 2015
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'NtGdiStretchBlt' Pool Buffer Overflow (MS15-097)
CVE-2015-2512doswindows_x8622 Sep 2015
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'bGetRealizedBrush' Use-After-Free (MS15-097)
CVE-2015-2518doswindows_x8622 Sep 2015
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
23RISK
open
Exploit-DB
SAP NetWeaver < 7.01 - XML External Entity Injection
CVE-2015-7241webappsxml22 Sep 2015
XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.
28RISK
open
Exploit-DBVexDay Proof
Konica Minolta FTP Utility 1.00 - (Authenticated) CWD Command Overflow (SEH) (Metasploit)
CVE-2015-7768remotewindows21 Sep 2015
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD comma
50RISK
open
Exploit-DB
Konica Minolta FTP Utility 1.0 - Remote Command Execution
CVE-2015-7767remotewindows20 Sep 2015
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code or cause a denial of
23RISK
open
Exploit-DB
VBox Satellite Express 2.3.17.3 - Arbitrary Write
CVE-2015-6923doswindows17 Sep 2015
The ndvbs module in VBox Communications Satellite Express Protocol 2.3.17.3 allows local users to write to arbitrary phy
23RISK
open
Exploit-DBVexDay Proof
ManageEngine OpManager - Remote Code Execution (Metasploit)
CVE-2015-7766remotejava17 Sep 2015
PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL q
60RISK
open
Exploit-DBVexDay Proof
ManageEngine OpManager - Remote Code Execution (Metasploit)
CVE-2015-7765remotejava17 Sep 2015
ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser a
50RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Font Driver Buffer Overflow (MS15-078) (Metasploit)
CVE-2015-2433localwindows_x86-6417 Sep 2015
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
43RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Font Driver Buffer Overflow (MS15-078) (Metasploit)
CVE-2015-2426HIGHunder attacklocalwindows_x86-6417 Sep 2015
Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2
100RISK
open
Exploit-DBVexDay Proof
Google Android - libstagefright Integer Overflow Remote Code Execution
CVE-2015-3864remoteandroid17 Sep 2015
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RISK
open
Exploit-DBVexDay Proof
Microsoft Office 2007 - 'OGL.dll' ValidateBitmapInfo Bounds Check Failure (MS15-097)
CVE-2015-2510doswindows16 Sep 2015
Buffer overflow in the Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2, Office 2007 S
35RISK
open
Exploit-DBVexDay Proof
Microsoft Office 2007 - BIFFRecord Length Use-After-Free
CVE-2015-2520doswindows16 Sep 2015
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel for Mac 2011 and 2016, Office Compatibility Pack SP3, and Excel Viewer a
28RISK
open
Exploit-DBVexDay Proof
Microsoft Office 2007 - OLESSDirectyEntry.CreateTime Type Confusion
CVE-2015-2521doswindows16 Sep 2015
Microsoft Excel 2007 SP3, Excel 2010 SP2, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to exec
28RISK
open
Exploit-DB
FAROL - SQL Injection
CVE-2015-6962webappsphp16 Sep 2015
SQL injection vulnerability in the web application in Farol allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
Exploit-DBVexDay Proof
Microsoft Excel 2007/2010/2013 - BIFFRecord Use-After-Free
CVE-2015-2523doswindows16 Sep 2015
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel for Mac 2011 and 2016, Office Compati
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Task Scheduler - 'DeleteExpiredTaskAfter' File Deletion Privilege Escalation
CVE-2015-2525localwindows15 Sep 2015
Task Scheduler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 10 (Build 10130) - User Mode Font Driver Thread Permissions Privilege Escalation
CVE-2015-2508localwindows15 Sep 2015
The Adobe Type Manager Library in Microsoft Windows 10 allows local users to gain privileges via a crafted application,
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - NtUserGetClipboardAccessToken Token Leak (MS15-023)
CVE-2015-2527localwindows15 Sep 2015
The process-initialization implementation in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1,
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - CreateObjectTask SettingsSyncDiagnostics Privilege Escalation
CVE-2015-2524localwindows15 Sep 2015
Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not proper
23RISK
open
Exploit-DB
Openfire 3.10.2 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2015-6972webappsjsp15 Sep 2015
Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to inject
23RISK
open
previouspage 183 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.