Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
80,292cataloged exploits
37,129CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,476Referência 23,614GitHub PoC 15,329VulnCheck XDB 8,970Nuclei 4,401Metasploit 3,502✓ verified onlyrecentpopularrisk
24,476 exploits
Exploit-DB
Netsweeper 2.6.29.8 - SQL Injection
Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL co
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'win32k.sys' TTF Font Processing IUP[] Program Instruction Pool-Based Buffer Overflow
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
35RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla - Maintenance Service Log File Overwrite Privilege Escalation
Race condition in the Mozilla Maintenance Service in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Win
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'ATMFD.DLL' Out-of-Bounds Read Due to Malformed FDSelect Offset in the CFF Table
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'ATMFD.DLL' Out-of-Bounds Read Due to Malformed Name INDEX in the CFF Table
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
35RISK
open ↗Exploit-DB✓ VexDay Proof
Konica Minolta FTP Utility 1.0 - Remote Denial of Service (PoC)
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code or cause a denial of
23RISK
open ↗Exploit-DB
Netsweeper 4.0.8 - Arbitrary File Upload / Execution
Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'win32k.sys' TTF Font Processing win32k!fsc_BLTHoriz Out-of-Bounds Pool Write
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
35RISK
open ↗Exploit-DB
Netsweeper 4.0.8 - Authentication Bypass (via New Profile Creation)
The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote att
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Office 2007 - 'OGL.dll' DpOutputSpanStretch::OutputSpan Out of Bounds Write (MS15-080)
Microsoft Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, and Lyn
28RISK
open ↗Exploit-DB
Netsweeper 4.0.8 - SQL Injection / Authentication Bypass
WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass aut
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'ATMFD.dll' CFF table (ATMFD+0x3440b / ATMFD+0x3440e) Invalid Memory Access
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Office 2007 - MSPTLS Heap Index Integer Underflow (MS15-081)
Integer underflow in Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office for Mac 201
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'ATMFD.dll' CharString Stream Out-of-Bounds Reads (MS15-021)
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'win32k.sys' TTF Font Processing win32k!scl_ApplyTranslation Pool-Based Buffer Overflow
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
35RISK
open ↗Exploit-DB
Netsweeper 4.0.4 - SQL Injection
SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1
23RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash - swapDepths Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash - XMLSocket Destructor Not Cleared Before Setting User Data in connect
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Setting Value Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash AS2 - textfield.filters Use-After-Free (2)
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows
35RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Pointer Crash in Drawing and Bitmap Handling
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RISK
open ↗Exploit-DB✓ VexDay Proof
Flash Broker-Based - Sandbox Escape via Unexpected Directory Lock
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460
35RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash - FileReference Class Type Confusion
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash - createTextField Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Bad Write in XML When Callback Modifies XML Tree During Property Delete
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Heap Buffer Overflow Loading '.FLV' File with Nellymoser Audio Codec
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows an
35RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash - 'Setting' Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash - '.SWF' Out-of-Bounds Memory Read (1)
Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR
35RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash AS2 - DisplacementMapFilter.mapBitmap Use-After-Free (2)
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.