Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
Microsoft Edge - 'CText­Extractor::Get­Block­Text' Out-of-Bounds Read (MS16-104)
CVE-2016-3247doswindows21 Nov 2016
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of
45RISK
open
Exploit-DBVexDay Proof
D-Link DIR-Series Routers - HNAP Login Stack Buffer Overflow (Metasploit)
CVE-2016-6563remotemultiple21 Nov 2016
D-Link DIR routers contain a stack-based buffer overflow in the HNAP Login action
60RISK
open
Exploit-DBVexDay Proof
Palo Alto Networks PanOS - 'root_trace' Local Privilege Escalation
CVE-2016-9151locallinux18 Nov 2016
Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0
23RISK
open
Exploit-DBVexDay Proof
Palo Alto Networks PanOS - 'root_reboot' Local Privilege Escalation
CVE-2016-9151locallinux18 Nov 2016
Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0
23RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - 'FillFromPrototypes' Type Confusion
CVE-2016-7201HIGHunder attackdoswindows18 Nov 2016
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RISK
open
Exploit-DBVexDay Proof
Palo Alto Networks PanOS - appweb3 Stack Buffer Overflow
CVE-2016-9150doslinux18 Nov 2016
Buffer overflow in the management web interface in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x b
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - 'Array.filter' Information Leak
CVE-2016-7200HIGHunder attackdoswindows18 Nov 2016
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - 'Array.splice' Heap Overflow
CVE-2016-7203doswindows18 Nov 2016
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - 'Array.reverse' Overflow
CVE-2016-7202doswindows18 Nov 2016
The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute a
45RISK
open
Exploit-DBVexDay Proof
Nagios 4.2.2 - Local Privilege Escalation
CVE-2016-8641MEDIUMlocallinux18 Nov 2016
A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary fil
33RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - 'eval' Type Confusion
CVE-2016-7240doswindows17 Nov 2016
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - VHDMP Arbitrary Physical Disk Cloning Privilege Escalation (MS16-138)
CVE-2016-7224localwindows15 Nov 2016
Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 151
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - VHDMP Arbitrary File Creation Privilege Escalation (MS16-138)
CVE-2016-7226localwindows15 Nov 2016
Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Registry Hive Loading 'nt!RtlEqualSid' Out-of-Bounds Read (MS16-138)
CVE-2016-7216doswindows15 Nov 2016
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandles permissi
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - VHDMP ZwDeleteFile Arbitrary File Deletion Privilege Escalation (MS16-138)
CVE-2016-7225localwindows15 Nov 2016
Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11 - MSHTML CMap­Element::Notify Use-After-Free (MS15-009)
CVE-2015-0040doswindows14 Nov 2016
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RISK
open
Exploit-DBVexDay Proof
Linux Kernel 4.4 (Ubuntu 16.04) - 'BPF' Local Privilege Escalation (Metasploit)
CVE-2016-4557locallinux14 Nov 2016
The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly mai
43RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11/10/9 - MSHTML 'PROPERTYDESC::Handle­Style­Component­Property' Out-of-Bounds Read (MS16-104)
CVE-2016-3324doswindows10 Nov 2016
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
28RISK
open
Exploit-DBVexDay Proof
Microsoft WININET.dll - 'CHttp­Header­Parser::Parse­Status­Line' Out-of-Bounds Read (MS16-104/MS16-105)
CVE-2016-3325doswindows10 Nov 2016
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted w
35RISK
open
Exploit-DBVexDay Proof
Adobe Connect 9.5.7 - Cross-Site Scripting
CVE-2016-7851webappswindows09 Nov 2016
Adobe Connect version 9.5.6 and earlier does not adequately validate input in the events registration module. This vulne
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - LSASS SMB NTLM Exchange Null-Pointer Dereference (MS16-137)
CVE-2016-7237doswindows09 Nov 2016
Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, W
35RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 8/9/10/11 / IIS / CScript.exe/WScript.exe VBScript - CRegExp..Execute Use of Uninitialized Memory (MS14-080/MS14-084)
CVE-2014-6363remotewindows07 Nov 2016
vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 6 through 11 and other products, allo
28RISK
open
Exploit-DBVexDay Proof
IBM AIX 5.3/6.1/7.1/7.2 - 'lquerylv' Local Privilege Escalation
CVE-2016-6079localaix04 Nov 2016
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to ob
23RISK
open
Exploit-DBVexDay Proof
IBM AIX 6.1/7.1/7.2.0.2 - 'lsmcode' Local Privilege Escalation
CVE-2016-3053localaix04 Nov 2016
IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privile
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel (Ubuntu / Fedora / RedHat) - 'Overlayfs' Local Privilege Escalation (Metasploit)
CVE-2015-8660locallinux02 Nov 2016
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RISK
open
Exploit-DBVexDay Proof
Linux Kernel (Ubuntu / Fedora / RedHat) - 'Overlayfs' Local Privilege Escalation (Metasploit)
CVE-2015-1328locallinux02 Nov 2016
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open
Exploit-DBVexDay Proof
Alienvault OSSIM/USM 5.3.1 - Persistent Cross-Site Scripting
CVE-2016-8581webappsphp02 Nov 2016
A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5
43RISK
open
Exploit-DBVexDay Proof
Bassmaster 1.5.1 - Batch Arbitrary JavaScript Injection Remote Code Execution (Metasploit)
CVE-2014-7205remotelinux02 Nov 2016
Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for t
60RISK
open
Exploit-DBVexDay Proof
Alienvault OSSIM/USM 5.3.1 - SQL Injection
CVE-2016-8582webappsphp02 Nov 2016
A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbit
50RISK
open
Exploit-DBVexDay Proof
Alienvault OSSIM/USM 5.3.1 - PHP Object Injection
CVE-2016-8580webappsphp02 Nov 2016
PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vuln
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.