Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
8,410 exploits
VulnCheck XDB
client-side
CVE-2018-4878HIGHunder attackransomware09 Feb 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISK
open
VulnCheck XDB
denial-of-service
CVE-2018-010107 Feb 2018
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Softw
45RISK
open
VulnCheck XDB
local
CVE-2018-100000107 Feb 2018
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISK
open
VulnCheck XDB
client-side
CVE-2006-477706 Feb 2018
Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) fo
60RISK
open
VulnCheck XDB
initial-access
CVE-2016-10033CRITICALunder attack06 Feb 2018
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2017-1254205 Feb 2018
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RISK
open
VulnCheck XDB
initial-access
CVE-2009-1151CRITICALunder attack03 Feb 2018
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALunder attackransomware28 Jan 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
VulnCheck XDB
local
CVE-2018-100000122 Jan 2018
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISK
open
VulnCheck XDB
client-side
CVE-2017-11882HIGHunder attackransomware16 Jan 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-9248CRITICALunder attack16 Jan 2018
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-10271HIGHunder attackransomware16 Jan 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
VulnCheck XDB
client-side
CVE-2018-0802HIGHunder attack12 Jan 2018
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RISK
open
VulnCheck XDB
client-side
CVE-2017-11882HIGHunder attackransomware12 Jan 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
VulnCheck XDB
client-side
CVE-2017-11882HIGHunder attackransomware11 Jan 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
VulnCheck XDB
client-side
CVE-2018-0802HIGHunder attack11 Jan 2018
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RISK
open
VulnCheck XDB
client-side
CVE-2018-0802HIGHunder attack11 Jan 2018
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RISK
open
VulnCheck XDB
initial-access
CVE-2016-2386CRITICALunder attack10 Jan 2018
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbi
100RISK
open
VulnCheck XDB
infoleak
CVE-2016-2388MEDIUMunder attack10 Jan 2018
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user infor
75RISK
open
VulnCheck XDB
initial-access
CVE-2017-11317CRITICALunder attack09 Jan 2018
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RISK
open
VulnCheck XDB
client-side
CVE-2017-8570HIGHunder attack09 Jan 2018
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RISK
open
VulnCheck XDB
local
CVE-2012-4681CRITICALunder attackransomware05 Jan 2018
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-10271HIGHunder attackransomware05 Jan 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-10271HIGHunder attackransomware03 Jan 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-3881CRITICALunder attack02 Jan 2018
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RISK
open
VulnCheck XDB
local
CVE-2017-1315629 Dec 2017
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RISK
open
VulnCheck XDB
initial-access
CVE-2017-10271HIGHunder attackransomware28 Dec 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-10271HIGHunder attackransomware28 Dec 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-17562HIGHunder attack27 Dec 2017
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-12615HIGHunder attackransomware26 Dec 2017
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open
previouspage 271 / 281next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.