Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
Netgear Routers - Password Disclosure
CVE-2017-5521HIGHunder attackwebappshardware30 Jan 2017
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R
100RISK
open
Exploit-DBVexDay Proof
Palo Alto Networks Terminal Services Agent 7.0.3-13 - Integer Overflow
CVE-2017-5329localwindows26 Jan 2017
Palo Alto Networks Terminal Services Agent before 7.0.7 allows local users to gain privileges via vectors that trigger a
23RISK
open
Exploit-DBVexDay Proof
Apple macOS 10.12.1 / iOS Kernel - 'IOService::matchPassive' Use-After-Free
CVE-2017-2353dosmultiple26 Jan 2017
An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Bluetooth"
23RISK
open
Exploit-DBVexDay Proof
Apple macOS 10.12.1 / iOS 10.2 - Kernel Userspace Pointer Memory Corruption
CVE-2017-2370dosmultiple26 Jan 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RISK
open
Exploit-DBVexDay Proof
Apple macOS 10.12.1 / iOS Kernel - 'host_self_trap' Use-After-Free
CVE-2017-2360dosmultiple26 Jan 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
23RISK
open
Exploit-DBVexDay Proof
Mozilla Firefox < 50.0.2 - 'nsSMILTimeContainer::NotifyTimeChange()' Remote Code Execution (Metasploit)
CVE-2016-9079HIGHunder attackremotewindows24 Jan 2017
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RISK
open
Exploit-DBVexDay Proof
Oracle OpenJDK Runtime Environment 1.8.0_112-b15 - Java Serialization Denial Of Service
CVE-2017-3241dosmultiple23 Jan 2017
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versi
35RISK
open
Exploit-DBVexDay Proof
PageKit 1.0.10 - Password Reset
CVE-2017-5594webappsphp21 Jan 2017
An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the reg
23RISK
open
Exploit-DBVexDay Proof
Cisco Firepower Management Console 6.0 - Post Authentication UserAdd (Metasploit)
CVE-2016-6433remotelinux13 Jan 2017
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users
60RISK
open
Exploit-DBVexDay Proof
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities
CVE-2017-6339webappshardware12 Jan 2017
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate d
23RISK
open
Exploit-DBVexDay Proof
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities
CVE-2017-6338webappshardware12 Jan 2017
Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow
23RISK
open
Exploit-DBVexDay Proof
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities
CVE-2017-6340webappshardware12 Jan 2017
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/repor
23RISK
open
Exploit-DBVexDay Proof
Adobe Flash Player 24.0.0.186 - 'ActionGetURL2' Out-of-Bounds Memory Corruption (2)
CVE-2017-2930dosmultiple11 Jan 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurre
28RISK
open
Exploit-DBVexDay Proof
Adobe Flash Player 24.0.0.186 - 'ActionGetURL2' Out-of-Bounds Memory Corruption (1)
CVE-2017-2930dosmultiple11 Jan 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurre
28RISK
open
Exploit-DBVexDay Proof
Atlassian Confluence < 5.10.6 - Persistent Cross-Site Scripting
CVE-2016-6283webappsjsp04 Jan 2017
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitra
23RISK
open
Exploit-DBVexDay Proof
Google Android - get_user/put_user (Metasploit)
CVE-2013-6282HIGHunder attacklocalandroid29 Dec 2016
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not
98RISK
open
Exploit-DBVexDay Proof
PHPMailer < 5.2.19 - Sendmail Argument Injection (Metasploit)
CVE-2016-1003webappsmultiple26 Dec 2016
20RISK
open
Exploit-DBVexDay Proof
PHPMailer < 5.2.19 - Sendmail Argument Injection (Metasploit)
CVE-2016-1004webappsmultiple26 Dec 2016
20RISK
open
Exploit-DBVexDay Proof
PHPMailer < 5.2.18 - Remote Code Execution
CVE-2016-10033CRITICALunder attackwebappsphp26 Dec 2016
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
Exploit-DBVexDay Proof
Shutter 0.93.1 - Code Execution
CVE-2016-10081locallinux26 Dec 2016
/usr/bin/shutter in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a cra
23RISK
open
Exploit-DBVexDay Proof
Wampserver 3.0.6 - Insecure File Permissions Privilege Escalation
CVE-2016-10031localwindows26 Dec 2016
WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYS
23RISK
open
Exploit-DBVexDay Proof
OpenSSH < 7.4 - agent Protocol Arbitrary Library Loading
CVE-2016-10009HIGHremotelinux23 Dec 2016
Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute
53RISK
open
Exploit-DBVexDay Proof
OpenSSH < 7.4 - 'UsePrivilegeSeparation Disabled' Forwarded Unix Domain Sockets Privilege Escalation
CVE-2016-10010HIGHlocallinux23 Dec 2016
sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which
41RISK
open
Exploit-DBVexDay Proof
Apple macOS 10.12.1 Kernel - Writable Privileged IOKit Registry Properties Code Execution
CVE-2016-7617dosmacos22 Dec 2016
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth"
23RISK
open
Exploit-DBVexDay Proof
Apple macOS 10.12 - Double vm_deallocate in Userspace MIG Code Use-After-Free
CVE-2016-7633dosmacos22 Dec 2016
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Directory S
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11 - MSHTML CPaste­Command::Convert­Bitmapto­Png Heap Buffer Overflow (MS14-056)
CVE-2014-4138doswindows22 Dec 2016
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RISK
open
Exploit-DBVexDay Proof
Apple macOS 10.12.1 / iOS < 10.2 - syslogd Arbitrary Port Replacement
CVE-2016-7660dosmultiple22 Dec 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RISK
open
Exploit-DBVexDay Proof
Apple macOS < 10.12.2 / iOS < 10.2 - Broken Kernel Mach Port Name uref Handling Privileged Port Name Replacement Privilege Escalation
CVE-2016-7637localmacos22 Dec 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RISK
open
Exploit-DBVexDay Proof
Apple macOS < 10.12.2 / iOS < 10.2 - '_kernelrpc_mach_port_insert_right_trap' Kernel Reference Count Leak / Use-After-Free
CVE-2016-7621localmacos22 Dec 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RISK
open
Exploit-DBVexDay Proof
Apple macOS < 10.12.2 / iOS < 10.2 Kernel - ipc_port_t Reference Count Leak Due to Incorrect externalMethod Overrides Use-After-Free
CVE-2016-7612dosmultiple22 Dec 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.