Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
GNU binutils - 'bfd_get_string' Stack Buffer Overflow
CVE-2017-9747doslinux19 Jun 2017
The ieee_archive_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GN
23RISK
open
Exploit-DBVexDay Proof
GNU binutils - 'ieee_object_p' Stack Buffer Overflow
CVE-2017-9748doslinux19 Jun 2017
The ieee_object_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU
23RISK
open
Exploit-DBVexDay Proof
GNU binutils - 'aarch64_ext_ldst_reglist' Buffer Overflow
CVE-2017-9756doslinux19 Jun 2017
The aarch64_ext_ldst_reglist function in opcodes/aarch64-dis.c in GNU Binutils 2.28 allows remote attackers to cause a d
23RISK
open
Exploit-DBVexDay Proof
GNU binutils - 'rx_decode_opcode' Buffer Overflow
CVE-2017-9750doslinux19 Jun 2017
opcodes/rx-decode.opc in GNU Binutils 2.28 lacks bounds checks for certain scale arrays, which allows remote attackers t
23RISK
open
Exploit-DBVexDay Proof
GNU binutils - 'decode_pseudodbg_assert_0' Buffer Overflow
CVE-2017-9749doslinux19 Jun 2017
The *regs* macros in opcodes/bfin-dis.c in GNU Binutils 2.28 allow remote attackers to cause a denial of service (buffer
23RISK
open
Exploit-DBVexDay Proof
WebKit JSC - 'Intl.getCanonicalLocales' Heap Buffer Overflow
CVE-2017-6984dosmultiple16 Jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. iTun
23RISK
open
Exploit-DBVexDay Proof
WebKit JSC - JSGlobalObject::haveABadTime Causes Type Confusions
CVE-2017-7005dosmultiple16 Jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RISK
open
Exploit-DBVexDay Proof
WebKit JSC - JIT Optimization Check Failed in IntegerCheckCombiningPhase::handleBlock
CVE-2017-2547dosmultiple16 Jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
28RISK
open
Exploit-DBVexDay Proof
WebKit JSC - arrayProtoFuncSplice does not Initialize all Indices
CVE-2017-6980dosmultiple16 Jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RISK
open
Exploit-DBVexDay Proof
GStreamer gst-plugins-bad Plugin - NULL Pointer Dereference
CVE-2016-9813doslinux12 Jun 2017
The _parse_pat function in the mpegts parser in GStreamer before 1.10.2 allows remote attackers to cause a denial of ser
23RISK
open
Exploit-DBVexDay Proof
VMware vSphere Data Protection 5.x/6.x - Java Deserialization
CVE-2017-4914remotemultiple10 Jun 2017
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of th
23RISK
open
Exploit-DBVexDay Proof
Apple macOS - Disk Arbitration Daemon Race Condition
CVE-2017-2533localmacos09 Jun 2017
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "DiskArbitra
23RISK
open
Exploit-DBVexDay Proof
Apple macOS 10.12.3 / iOS < 10.3.2 - Userspace Entitlement Checking Race Condition
CVE-2017-7004localmultiple09 Jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The
23RISK
open
Exploit-DBVexDay Proof
VMware Workstation 12 Pro - Denial of Service
CVE-2017-4916doswindows08 Jun 2017
VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Succes
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel - 'ping' Local Denial of Service
CVE-2017-2671dosandroid07 Jun 2017
The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock a
23RISK
open
Exploit-DBVexDay Proof
PuTTY < 0.68 - 'ssh_agent_channel_data' Integer Overflow Heap Corruption
CVE-2017-6542doslinux07 Jun 2017
The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large
28RISK
open
Exploit-DBVexDay Proof
Artifex MuPDF - Null Pointer Dereference
CVE-2017-5991doslinux07 Jun 2017
An issue was discovered in Artifex MuPDF before 1912de5f08e90af1d9d0a9791f58ba3afdb9d465. The pdf_run_xobject function i
28RISK
open
Exploit-DBVexDay Proof
Linux Kernel < 4.10.13 - 'keyctl_set_reqkey_keyring' Local Denial of Service
CVE-2017-7472doslinux07 Jun 2017
The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumptio
23RISK
open
Exploit-DBVexDay Proof
Subsonic 6.1.1 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2017-9414webappswindows05 Jun 2017
Cross-site request forgery (CSRF) vulnerability in the Subscribe to Podcast feature in Subsonic 6.1.1 allows remote atta
28RISK
open
Exploit-DBVexDay Proof
Wireshark 2.2.0 < 2.2.12 - ROS Dissector Denial of Service
CVE-2017-9347dosmultiple05 Jun 2017
In Wireshark 2.2.0 to 2.2.6, the ROS dissector could crash with a NULL pointer dereference. This was addressed in epan/d
28RISK
open
Exploit-DBVexDay Proof
Wireshark 2.2.6 - IPv6 Dissector Denial of Service
CVE-2017-9353dosmultiple05 Jun 2017
In Wireshark 2.2.0 to 2.2.6, the IPv6 dissector could crash. This was addressed in epan/dissectors/packet-ipv6.c by vali
28RISK
open
Exploit-DBVexDay Proof
DNSTracer 1.8.1 - Buffer Overflow (PoC)
CVE-2017-9430doslinux05 Jun 2017
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) o
28RISK
open
Exploit-DBVexDay Proof
Subsonic 6.1.1 - XML External Entity Injection
CVE-2017-9355localwindows05 Jun 2017
XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to
28RISK
open
Exploit-DBVexDay Proof
WebKit JSC - Incorrect Check in emitPutDerivedConstructorToArrowFunctionContextScope
CVE-2017-2531dosmultiple01 Jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RISK
open
Exploit-DBVexDay Proof
WebKit - CachedFrame does not Detach Openers Universal Cross-Site Scripting
CVE-2017-2528webappsmultiple01 Jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RISK
open
Exploit-DBVexDay Proof
WebKit JSC - 'JSObject::ensureLength' ensureLengthSlow Check Failure
CVE-2017-2521doslinux01 Jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RISK
open
Exploit-DBVexDay Proof
Microsoft MsMpEng - Use-After-Free via Saved Callers
CVE-2017-8541doswindows30 May 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
35RISK
open
Exploit-DBVexDay Proof
Microsoft MsMpEng - Remote Use-After-Free Due to Design Issue in GC Engine
CVE-2017-8540HIGHunder attackdoswindows30 May 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
93RISK
open
Exploit-DBVexDay Proof
IBM Informix Dynamic Server / Informix Open Admin Tool - DLL Injection / Remote Code Execution / Heap Buffer Overflow
CVE-2017-1092webappswindows30 May 2017
IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system a
60RISK
open
Exploit-DBVexDay Proof
Microsoft MsMpEng - Multiple Crashes While Scanning Malformed Files
CVE-2017-8536doswindows29 May 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
28RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.