Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'TryUndeleteProperty' Incorrect Usage (Denial of Service)
CVE-2017-8635doswindows17 Aug 2017
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - Out-of-Bounds Access when Fetching Source
CVE-2017-8657doswindows17 Aug 2017
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge 40.15063.0.0 Chakra - Incorrect JIT Optimization with TypedArray Setter #3
CVE-2017-8601doswindows17 Aug 2017
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge 38.14393.1066.0 - 'CInputDateTimeScrollerElement::_SelectValueInternal' Out-of-Bounds Read
CVE-2017-8644doswindows16 Aug 2017
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose in
28RISK
open
Exploit-DBVexDay Proof
Xamarin Studio for Mac 6.2.1 (build 3) / 6.3 (build 863) - Local Privilege Escalation
CVE-2017-8665localmacos14 Aug 2017
The Xamarin.iOS update component on systems running macOS allows an attacker to run arbitrary code as root, aka "Xamarin
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel < 4.4.0-83 / < 4.8.0-58 (Ubuntu 14.04/16.04) - Local Privilege Escalation (KASLR / SMEP)
CVE-2017-1000112locallinux13 Aug 2017
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE
43RISK
open
Exploit-DBVexDay Proof
Microsoft Edge 38.14393.1066.0 - 'textarea.defaultValue' Memory Disclosure
CVE-2017-8652doswindows_x86-6410 Aug 2017
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose in
28RISK
open
Exploit-DBVexDay Proof
Symantec Messaging Gateway < 10.6.3-267 - Cross-Site Request Forgery
CVE-2017-6328webappsmultiple09 Aug 2017
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one
23RISK
open
Exploit-DBVexDay Proof
Unitrends UEB 9.1 - Privilege Escalation
CVE-2017-12479webappsphp08 Aug 2017
It was discovered that an issue in the session logic in Unitrends Backup (UB) before 10.0.0 allowed using the LOGDIR env
28RISK
open
Exploit-DBVexDay Proof
Unitrends UEB 9.1 - 'Unitrends bpserverd' Remote Command Execution
CVE-2017-12477remotelinux08 Aug 2017
It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xin
50RISK
open
Exploit-DBVexDay Proof
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
CVE-2017-11151webappshardware08 Aug 2017
A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers
28RISK
open
Exploit-DBVexDay Proof
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
CVE-2017-11155webappshardware08 Aug 2017
An information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remot
35RISK
open
Exploit-DBVexDay Proof
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
CVE-2017-11153webappshardware08 Aug 2017
Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allo
28RISK
open
Exploit-DBVexDay Proof
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
CVE-2017-11152webappshardware08 Aug 2017
Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 all
28RISK
open
Exploit-DBVexDay Proof
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
CVE-2017-11154webappshardware08 Aug 2017
Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-296
23RISK
open
Exploit-DBVexDay Proof
Unitrends UEB 9.1 - Authentication Bypass / Remote Command Execution
CVE-2017-12478remotelinux08 Aug 2017
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of
60RISK
open
Exploit-DBVexDay Proof
VirtualBox 5.1.22 - Windows Process DLL Signature Bypass Privilege Escalation
CVE-2017-10204localwindows03 Aug 2017
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version
23RISK
open
Exploit-DBVexDay Proof
VirtualBox 5.1.22 - Windows Process DLL UNC Path Signature Bypass Privilege Escalation
CVE-2017-10129localwindows03 Aug 2017
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version
23RISK
open
Exploit-DBVexDay Proof
Nitro Pro PDF Reader 11.0.3.173 - Javascript API Code Execution (Metasploit)
CVE-2017-7442localwindows02 Aug 2017
Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory tra
50RISK
open
Exploit-DBVexDay Proof
Apple macOS/iOS - 'xpc_data' Objects Sandbox Escape Privilege Escalation
CVE-2017-7047localmultiple01 Aug 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS
23RISK
open
Exploit-DBVexDay Proof
Jenkins < 1.650 - Java Deserialization
CVE-2016-0792remotejava30 Jul 2017
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to ex
60RISK
open
Exploit-DBVexDay Proof
Fortinet FortiOS < 5.6.0 - Cross-Site Scripting
CVE-2017-3131webappshardware28 Jul 2017
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to exec
38RISK
open
Exploit-DBVexDay Proof
Fortinet FortiOS < 5.6.0 - Cross-Site Scripting
CVE-2017-3132webappshardware28 Jul 2017
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthor
38RISK
open
Exploit-DBVexDay Proof
Fortinet FortiOS < 5.6.0 - Cross-Site Scripting
CVE-2017-3133webappshardware28 Jul 2017
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthor
43RISK
open
Exploit-DBVexDay Proof
GNU libiberty - Buffer Overflow
CVE-2016-2226doslinux27 Jul 2017
Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
AudioCoder 0.8.46 - Local Buffer Overflow (SEH)
CVE-2017-8870localwindows26 Jul 2017
Buffer overflow in AudioCoder 0.8.46 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RISK
open
Exploit-DBVexDay Proof
WebKit JSC - 'JSObject::putInlineSlow' / 'JSValue::putToPrimitive' Universal Cross-Site Scripting
CVE-2017-7037webappsmultiple25 Jul 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open
Exploit-DBVexDay Proof
WebKit JSC - 'JSArray::appendMemcpy' Uninitialized Memory Copy
CVE-2017-7064dosmultiple25 Jul 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open
Exploit-DBVexDay Proof
WebKit JSC - 'DFG::ByteCodeParser::flush(InlineStackEntry* inlineStackEntry)' Incorrect Scope Register Handling
CVE-2017-7018dosmultiple25 Jul 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open
Exploit-DBVexDay Proof
WebKit JSC - 'ArgumentsEliminationPhase::transform' Incorrect LoadVarargs Handling
CVE-2017-7056dosmultiple25 Jul 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.