Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
Oracle VM VirtualBox - Environment and ioctl Unprivileged Host User to Host Kernel Privilege Escalation
CVE-2017-3561dosmultiple20 Apr 2017
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RISK
open
Exploit-DBVexDay Proof
Oracle VM VirtualBox 5.1.14 r112924 - Unprivileged Host User to Host Kernel Privilege Escalation via ALSA config
CVE-2017-3576locallinux20 Apr 2017
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RISK
open
Exploit-DBVexDay Proof
Oracle VM VirtualBox - Guest-to-Host Privilege Escalation via Broken Length Handling in slirp Copy
CVE-2017-3558localmultiple20 Apr 2017
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RISK
open
Exploit-DBVexDay Proof
Oracle VM VirtualBox 5.0.32 r112930 (x64) - Windows Process COM Injection Privilege Escalation
CVE-2017-3563localwindows_x86-6420 Apr 2017
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 10 (Build 10586) - 'IEETWCollector' Arbitrary Directory/File Deletion Privilege Escalation
CVE-2017-0165localwindows20 Apr 2017
An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - ManagementObject Arbitrary .NET Serialization Remote Code Execution
CVE-2017-0160remotewindows20 Apr 2017
Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system t
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 10 - Runtime Broker ClipboardBroker Privilege Escalation
CVE-2017-0211localwindows20 Apr 2017
An elevation of privilege vulnerability exists in Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows
28RISK
open
Exploit-DBVexDay Proof
Dmitry 1.3a - Local Buffer Overflow (PoC)
CVE-2017-7938MEDIUMdoslinux19 Apr 2017
Stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows attackers to cau
33RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)
CVE-2017-0144HIGHunder attackransomwaredoswindows17 Apr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)
CVE-2017-0148HIGHunder attackransomwaredoswindows17 Apr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)
CVE-2017-0147HIGHunder attackransomwaredoswindows17 Apr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)
CVE-2017-0145HIGHunder attackransomwaredoswindows17 Apr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)
CVE-2017-0143HIGHunder attackransomwaredoswindows17 Apr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)
CVE-2017-0146HIGHunder attackransomwaredoswindows17 Apr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Exploit-DBVexDay Proof
Mantis Bug Tracker 1.3.0/2.3.0 - Password Reset
CVE-2017-7615webappsphp16 Apr 2017
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value
60RISK
open
Exploit-DBVexDay Proof
Concrete5 CMS 8.1.0 - 'Host' Header Injection
CVE-2017-7725webappsphp14 Apr 2017
concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "ca
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32kfull!SfnINLPUAHDRAWMENUITEM' Stack Memory Disclosure
CVE-2017-0167doswindows13 Apr 2017
An information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 10, and W
23RISK
open
Exploit-DBVexDay Proof
Adobe Creative Cloud Desktop Application < 4.0.0.185 - Local Privilege Escalation
CVE-2017-3006localwindows13 Apr 2017
Adobe Thor versions 3.9.5.353 and earlier have a vulnerability related to the use of improper resource permissions durin
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k.sys' Multiple 'NtGdiGetDIBitsInternal' System Call
CVE-2017-0058doswindows13 Apr 2017
A Win32k information disclosure vulnerability exists in Microsoft Windows when the win32k component improperly provides
23RISK
open
Exploit-DBVexDay Proof
Xen - Broken Check in 'memory_exchange()' Permits PV Guest Breakout
CVE-2017-7228localmultiple11 Apr 2017
An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The e
23RISK
open
Exploit-DBVexDay Proof
Apple WebKit - 'JSC::B3::Procedure::resetReachability' Use-After-Free
CVE-2017-2470dosmultiple11 Apr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open
Exploit-DBVexDay Proof
Apple WebKit - 'Document::adoptNode' Use-After-Free
CVE-2017-2468dosmultiple11 Apr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open
Exploit-DBVexDay Proof
Apple WebKit - 'JSC::SymbolTableEntry::isWatchable' Heap Buffer Overflow
CVE-2017-2469dosmultiple11 Apr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open
Exploit-DBVexDay Proof
Apple WebKit / Safari 10.0.3 (12602.4.8) - Synchronous Page Load Universal Cross-Site Scripting
CVE-2017-2480webappsmultiple11 Apr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud b
23RISK
open
Exploit-DBVexDay Proof
Apple WebKit / Safari 10.0.3 (12602.4.8) - Universal Cross-Site Scripting via a Focus Event and a Link Element
CVE-2017-2479webappsmultiple11 Apr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud b
23RISK
open
Exploit-DBVexDay Proof
QNAP TVS-663 QTS < 4.2.4 build 20170313 - Command Injection
CVE-2017-6360webappscgi07 Apr 2017
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information
35RISK
open
Exploit-DBVexDay Proof
QNAP TVS-663 QTS < 4.2.4 build 20170313 - Command Injection
CVE-2017-6359webappscgi07 Apr 2017
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands vi
28RISK
open
Exploit-DBVexDay Proof
QNAP TVS-663 QTS < 4.2.4 build 20170313 - Command Injection
CVE-2017-6361webappscgi07 Apr 2017
QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.
35RISK
open
Exploit-DBVexDay Proof
Faveo Helpdesk Community 1.9.3 - Cross-Site Request Forgery
CVE-2017-7571webappsphp05 Apr 2017
public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.
23RISK
open
Exploit-DBVexDay Proof
Apple macOS Kernel 10.12.2 (16C67) - 'AppleIntelCapriController::GetLinkConfig' Code Execution Due to Lack of Bounds Checking
CVE-2017-2443dosmacos04 Apr 2017
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graph
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.