Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
8,460 exploits
VulnCheck XDB
local
CVE-2014-4113HIGHunder attack22 Jan 2016
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RISK
open
VulnCheck XDB
initial-access
CVE-2016-072822 Jan 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISK
open
VulnCheck XDB
info-leak
CVE-2016-072820 Jan 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2015-7755CRITICALunder attack09 Jan 2016
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-3153HIGHunder attack08 Nov 2015
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISK
open
VulnCheck XDB
initial-access
CVE-2015-780806 Nov 2015
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH
60RISK
open
VulnCheck XDB
denial-of-service
CVE-2015-1635CRITICALunder attack14 Oct 2015
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open
VulnCheck XDB
local
CVE-2015-363607 Oct 2015
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data str
23RISK
open
VulnCheck XDB
initial-access
CVE-2014-7169CRITICALunder attack30 Sep 2015
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISK
open
VulnCheck XDB
infoleak
CVE-2014-0160HIGHunder attack24 Sep 2015
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2015-363612 Sep 2015
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data str
23RISK
open
VulnCheck XDB
client-side
CVE-2015-5119HIGHunder attack10 Sep 2015
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RISK
open
VulnCheck XDB
initial-access
CVE-2012-1823CRITICALunder attack08 Sep 2015
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISK
open
VulnCheck XDB
initial-access
CVE-2015-363621 Aug 2015
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data str
23RISK
open
VulnCheck XDB
client-side
CVE-2015-4495HIGHunder attack10 Aug 2015
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote
98RISK
open
VulnCheck XDB
denial-of-service
CVE-2015-547709 Aug 2015
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RISK
open
VulnCheck XDB
denial-of-service
CVE-2015-547731 Jul 2015
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack26 Jun 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2014-0160HIGHunder attack09 Jun 2015
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
local
CVE-2010-3904HIGHunder attack09 Jun 2015
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the
91RISK
open
VulnCheck XDB
local
CVE-2015-1701HIGHunder attackransomware12 May 2015
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local
98RISK
open
VulnCheck XDB
denial-of-service
CVE-2015-1635CRITICALunder attack16 Apr 2015
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open
VulnCheck XDB
local
CVE-2015-1130HIGHunder attack15 Apr 2015
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and o
86RISK
open
VulnCheck XDB
local
CVE-2015-1130HIGHunder attack10 Apr 2015
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and o
86RISK
open
VulnCheck XDB
local
CVE-2013-2094HIGHunder attack29 Mar 2015
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack20 Mar 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
infoleak
CVE-2014-0160HIGHunder attack08 Mar 2015
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack22 Feb 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
client-side
CVE-2015-007221 Feb 2015
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass t
60RISK
open
VulnCheck XDB
local
CVE-2014-3153HIGHunder attack12 Jan 2015
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISK
open
previouspage 280 / 282next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.