Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DBVexDay Proof
Microsoft Windows - 'ATMFD.DLL' Write to Uninitialized Address Due to Malformed CFF Table
CVE-2015-2432doswindows21 Aug 2015
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'ATMFD.dll' CharString Stream Out-of-Bounds Reads (MS15-021)
CVE-2015-2458doswindows21 Aug 2015
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
35RISK
open
Exploit-DB
Netsweeper 4.0.8 - Arbitrary File Upload / Execution
CVE-2014-9619webappsphp21 Aug 2015
Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'ATMFD.dll' CFF table (ATMFD+0x3440b / ATMFD+0x3440e) Invalid Memory Access
CVE-2015-2460doswindows21 Aug 2015
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
35RISK
open
Exploit-DBVexDay Proof
Microsoft Office 2007 - 'wwlib.dll' Type Confusion (MS15-081)
CVE-2015-2469doswindows21 Aug 2015
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, and Office for Mac 2011 allow remote attackers to execute arbit
28RISK
open
Exploit-DBVexDay Proof
Microsoft Office 2007 - 'mso.dll' Use-After-Free (MS15-081)
CVE-2015-2467doswindows21 Aug 2015
Microsoft Office 2007 SP3 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Offic
28RISK
open
Exploit-DB
Netsweeper 2.6.29.8 - SQL Injection
CVE-2014-9613webappsphp21 Aug 2015
Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL co
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'ATMFD.DLL' Out-of-Bounds Read Due to Malformed FDSelect Offset in the CFF Table
CVE-2015-2462doswindows21 Aug 2015
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
35RISK
open
Exploit-DBVexDay Proof
Konica Minolta FTP Utility 1.0 - Remote Denial of Service (PoC)
CVE-2015-7767doswindows21 Aug 2015
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code or cause a denial of
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'ATMFD.DLL' CFF table (ATMFD+0x34072 / ATMFD+0x3407b) Invalid Memory Access
CVE-2015-2459doswindows21 Aug 2015
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
35RISK
open
Exploit-DB
Netsweeper 4.0.4 - SQL Injection
CVE-2014-9612webappsphp21 Aug 2015
SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'win32k.sys' TTF Font Processing win32k!fsc_BLTHoriz Out-of-Bounds Pool Write
CVE-2015-2464doswindows21 Aug 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
35RISK
open
Exploit-DBVexDay Proof
Microsoft Office 2007 - MSPTLS Heap Index Integer Underflow (MS15-081)
CVE-2015-2470doswindows21 Aug 2015
Integer underflow in Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office for Mac 201
28RISK
open
Exploit-DB
Aruba Mobility Controller 6.4.2.8 - Multiple Vulnerabilities
CVE-2015-5437webappsxml20 Aug 2015
20RISK
open
Exploit-DBVexDay Proof
Adobe Flash - Type Confusion in TextRenderer.setAdvancedAntialiasingTable
CVE-2015-5555dosmultiple19 Aug 2015
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RISK
open
Exploit-DBVexDay Proof
Adobe Flash - FileReference Class Type Confusion
CVE-2015-5558dosmultiple19 Aug 2015
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RISK
open
Exploit-DBVexDay Proof
Adobe Flash - Bad Write in XML When Callback Modifies XML Tree During Property Delete
CVE-2015-5549dosmultiple19 Aug 2015
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RISK
open
Exploit-DBVexDay Proof
Adobe Flash AS2 - textfield.filters Use-After-Free (3)
CVE-2015-5561doswindows19 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RISK
open
Exploit-DBVexDay Proof
Adobe Flash - Shared Object Type Confusion
CVE-2015-5562doswindows_x8619 Aug 2015
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RISK
open
Exploit-DBVexDay Proof
Adobe Flash - XML.childNodes Use-After-Free
CVE-2015-5540dosmultiple19 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RISK
open
Exploit-DBVexDay Proof
Adobe Flash - Pointer Crash in XML Handling
CVE-2015-5548doslinux19 Aug 2015
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RISK
open
Exploit-DBVexDay Proof
Flash Broker-Based - Sandbox Escape via Timing Attack Against File Moving
CVE-2015-3081remotewindows19 Aug 2015
Race condition in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and b
28RISK
open
Exploit-DBVexDay Proof
Adobe Flash AS2 - DisplacementMapFilter.mapBitmap Use-After-Free (2)
CVE-2015-5127doswindows19 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RISK
open
Exploit-DBVexDay Proof
Adobe Flash - NetConnection.connect Use-After-Free
CVE-2015-3107dosmultiple19 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows
35RISK
open
Exploit-DBVexDay Proof
Adobe Flash AS2 - Color.setRGB Use-After-Free
CVE-2015-3128doswindows19 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows
35RISK
open
Exploit-DBVexDay Proof
Adobe Flash - Out-of-Bounds Memory Read While Parsing a Mutated '.TTF' File Embedded in SWF
CVE-2015-5133doswindows19 Aug 2015
Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR
35RISK
open
Exploit-DBVexDay Proof
Adobe Flash - 'Setting' Use-After-Free
CVE-2015-5134dosmultiple19 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RISK
open
Exploit-DBVexDay Proof
Flash Boundless Tunes - Universal SOP Bypass Through ActionSctipt's Sound Object
CVE-2015-5116remotemultiple19 Aug 2015
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481
28RISK
open
Exploit-DBVexDay Proof
Adobe Flash - '.SWF' Out-of-Bounds Memory Read (2)
CVE-2015-5132doswindows19 Aug 2015
Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR
35RISK
open
Exploit-DBVexDay Proof
Adobe Flash AS2 - textfield.filters Use-After-Free (2)
CVE-2015-3118doswindows19 Aug 2015
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows
35RISK
open
previouspage 186 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.