Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,184cataloged exploits
37,029CVEs with public exploitation
24,695lab-tested
24,476 exploits
Exploit-DB
vTiger CRM 6.3.0 - (Authenticated) Remote Code Execution
CVE-2015-6000webappsphp28 Sep 2015
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger
50RISK
open
Exploit-DBVexDay Proof
Watchguard XCS - Remote Command Execution (Metasploit)
CVE-2015-5453remotebsd28 Sep 2015
Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell
50RISK
open
Exploit-DB
Adobe Flash - 'uint' Capacity Field
CVE-2015-5568doswindows28 Sep 2015
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Ad
28RISK
open
Exploit-DB
Mango Automation 2.6.0 - Multiple Vulnerabilities
CVE-2015-7902webappsjsp28 Sep 2015
Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 provides different error messages for failed
23RISK
open
Exploit-DB
Mango Automation 2.6.0 - Multiple Vulnerabilities
CVE-2015-7901webappsjsp28 Sep 2015
Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to execut
23RISK
open
Exploit-DB
BMC Track-It! 11.4 - Multiple Vulnerabilities
CVE-2016-6599webappswindows28 Sep 2015
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService)
28RISK
open
Exploit-DB
BMC Track-It! 11.4 - Multiple Vulnerabilities
CVE-2016-6598webappswindows28 Sep 2015
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on
28RISK
open
Exploit-DBVexDay Proof
Watchguard XCS - Remote Command Execution (Metasploit)
CVE-2015-5452remotebsd28 Sep 2015
SQL injection vulnerability in Watchguard XCS 9.2 and 10.0 before build 150522 allows remote attackers to execute arbitr
23RISK
open
Exploit-DB
BisonWare BisonFTP Server 3.5 - Directory Traversal
CVE-2015-7602remotewindows28 Sep 2015
Directory traversal vulnerability in BisonWare BisonFTP 3.5 allows remote attackers to read arbitrary files via a ../ (d
50RISK
open
Exploit-DB
Mango Automation 2.6.0 - Multiple Vulnerabilities
CVE-2015-6493webappsjsp28 Sep 2015
Cross-site request forgery (CSRF) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 bu
23RISK
open
Exploit-DB
vTiger CRM 6.3.0 - (Authenticated) Remote Code Execution
CVE-2016-1713webappsphp28 Sep 2015
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger
43RISK
open
Exploit-DB
FortiManager 5.2.2 - Persistent Cross-Site Scripting
CVE-2015-8038webappscgi25 Sep 2015
Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager befor
23RISK
open
Exploit-DB
FortiManager 5.2.2 - Persistent Cross-Site Scripting
CVE-2015-8037webappscgi25 Sep 2015
Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager befor
23RISK
open
Exploit-DB
X2Engine 4.2 - Arbitrary File Upload
CVE-2015-5074webappsphp25 Sep 2015
Incomplete blacklist vulnerability in the FileUploadsFilter class in protected/components/filters/FileUploadsFilter.php
23RISK
open
Exploit-DB
X2Engine 4.2 - Cross-Site Request Forgery
CVE-2015-5075webappsphp25 Sep 2015
Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authe
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'NtGdiBitBlt' Buffer Overflow (MS15-097)
CVE-2015-2512doswindows_x8624 Sep 2015
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
23RISK
open
Exploit-DB
SMF (Simple Machine Forum) 2.0.10 - Remote Memory Exfiltration
CVE-2015-4148webappsphp24 Sep 2015
The do_soap_call function in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not
28RISK
open
Exploit-DB
refbase 0.9.6 - Multiple Vulnerabilities
CVE-2015-6009webappsphp23 Sep 2015
Multiple SQL injection vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to e
23RISK
open
Exploit-DB
refbase 0.9.6 - Multiple Vulnerabilities
CVE-2015-7381webappsphp23 Sep 2015
Multiple PHP remote file inclusion vulnerabilities in install.php in Web Reference Database (aka refbase) through 0.9.6
23RISK
open
Exploit-DB
refbase 0.9.6 - Multiple Vulnerabilities
CVE-2015-7382webappsphp23 Sep 2015
SQL injection vulnerability in install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers
23RISK
open
Exploit-DB
Cisco AnyConnect 3.1.08009 - Local Privilege Escalation (via DMG Install Script)
CVE-2015-6306localosx23 Sep 2015
Cisco AnyConnect Secure Mobility Client 4.1(8) on OS X and Linux does not verify pathnames before installation actions,
23RISK
open
Exploit-DB
refbase 0.9.6 - Multiple Vulnerabilities
CVE-2015-6008webappsphp23 Sep 2015
install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary commands
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX Regex Engine (TRE) - Stack Buffer Overflow (PoC)
CVE-2015-3796dososx22 Sep 2015
The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent attackers to execute
28RISK
open
Exploit-DB
SAP NetWeaver < 7.01 - XML External Entity Injection
CVE-2015-7241webappsxml22 Sep 2015
XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Use-After-Free with Printer Device Contexts (MS15-097)
CVE-2015-2507doswindows_x8622 Sep 2015
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
23RISK
open
Exploit-DBVexDay Proof
Cisco AnyConnect Secure Mobility Client 3.1.08009 - Local Privilege Escalation
CVE-2015-6305localwindows22 Sep 2015
Untrusted search path vulnerability in the CMainThread::launchDownloader function in vpndownloader.exe in Cisco AnyConne
23RISK
open
Exploit-DB
h5ai < 0.25.0 - Unrestricted Arbitrary File Upload
CVE-2015-3203webappsphp22 Sep 2015
Unrestricted file upload vulnerability in h5ai before 0.25.0 allows remote attackers to execute arbitrary code by upload
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'NtGdiStretchBlt' Pool Buffer Overflow (MS15-097)
CVE-2015-2512doswindows_x8622 Sep 2015
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
23RISK
open
Exploit-DB
Konica Minolta FTP Utility 1.0 - Directory Traversal
CVE-2015-7603remotewindows22 Sep 2015
Directory traversal vulnerability in Konica Minolta FTP Utility 1.0 allows remote attackers to read arbitrary files via
50RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Use-After-Free with Cursor Object (MS15-097)
CVE-2015-2517doswindows_x8622 Sep 2015
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
23RISK
open
previouspage 183 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.