Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
Apple Mac OSX Kernel - Null Pointer Dereference in nvCommandQueue::GetHandleIndex in GeForce.kext
CVE-2016-1846dososx10 Jun 2016
The nvCommandQueue::GetHandleIndex method in the NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows a
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX Kernel - GeForce GPU Driver Stack Buffer Overflow
CVE-2016-1861dososx10 Jun 2016
The NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privi
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX Kernel - Null Pointer Dereference in AppleGraphicsDeviceControl
CVE-2016-1793dososx10 Jun 2016
AppleGraphicsDeviceControlClient in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged
23RISK
open
Exploit-DBVexDay Proof
Google Android - '/system/bin/sdcard' Stack Buffer Overflow (PoC)
CVE-2016-2494dosandroid10 Jun 2016
Off-by-one error in sdcard/sdcard.c in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before
23RISK
open
Exploit-DBVexDay Proof
IPFire - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)
CVE-2014-6271CRITICALunder attackremotecgi10 Jun 2016
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX Kernel - NULL Dereference in CoreCaptureResponder Due to Unchecked Return Value
CVE-2016-1803dososx10 Jun 2016
CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RISK
open
Exploit-DBVexDay Proof
HP Data Protector A.09.00 - Encrypted Communications Arbitrary Command Execution (Metasploit)
CVE-2016-2004remotewindows31 May 2016
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary cod
60RISK
open
Exploit-DBVexDay Proof
VideoLAN VLC Media Player 2.2.1 - 'DecodeAdpcmImaQT' Buffer Overflow
CVE-2016-5108doswindows27 May 2016
Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allo
28RISK
open
Exploit-DBVexDay Proof
HP Data Protector A.09.00 - Arbitrary Command Execution
CVE-2016-2004remotewindows26 May 2016
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary cod
60RISK
open
Exploit-DBVexDay Proof
Oracle Application Testing Suite (ATS) - Arbitrary File Upload (Metasploit)
CVE-2016-0491remotejava25 May 2016
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RISK
open
Exploit-DBVexDay Proof
Oracle Application Testing Suite (ATS) - Arbitrary File Upload (Metasploit)
CVE-2016-0492remotejava25 May 2016
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RISK
open
Exploit-DBVexDay Proof
Apple QuickTime - '.mov' Parsing Memory Corruption
CVE-2016-1848dososx19 May 2016
QuickTime in Apple OS X before 10.11.5 allows remote attackers to execute arbitrary code or cause a denial of service (m
23RISK
open
Exploit-DBVexDay Proof
Magento < 2.0.6 - Arbitrary Unserialize / Arbitrary Write File
CVE-2016-4010webappsphp18 May 2016
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary
60RISK
open
Exploit-DBVexDay Proof
Adobe Flash - JXR Processing Out-of-Bounds Read
CVE-2016-1102dosmultiple17 May 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RISK
open
Exploit-DBVexDay Proof
Adobe Flash - Type Confusion in FileReference Constructor
CVE-2016-1105dosmultiple17 May 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'gdi32.dll' Multiple 'EMF COMMENT_MULTIFORMATS' Record Handling (MS16-055)
CVE-2016-0169doswindows17 May 2016
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
35RISK
open
Exploit-DBVexDay Proof
Adobe Flash - Heap Overflow in ATF Processing Image Reading
CVE-2016-1101dosmultiple17 May 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RISK
open
Exploit-DBVexDay Proof
Adobe Flash - SetNative Use-After-Free
CVE-2016-1106dosmultiple17 May 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RISK
open
Exploit-DBVexDay Proof
Dell SonicWALL Scrutinizer 11.01 - methodDetail SQL Injection (Metasploit)
CVE-2014-4977remotemultiple17 May 2016
Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute
60RISK
open
Exploit-DBVexDay Proof
Adobe Flash - addProperty Use-After-Free
CVE-2016-4108dosmultiple17 May 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RISK
open
Exploit-DBVexDay Proof
Cisco ASA Software 8.x/9.x - IKEv1 / IKEv2 Buffer Overflow
CVE-2016-1287remotehardware17 May 2016
Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0
45RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'gdi32.dll' Heap Buffer Overflow in ExtEscape() Triggerable via EMR_EXTESCAPE EMF Record (MS16-055)
CVE-2016-0170dosmultiple17 May 2016
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
35RISK
open
Exploit-DBVexDay Proof
Adobe Flash - Overflow in Processing Raw 565 Textures
CVE-2016-1103dosmultiple17 May 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RISK
open
Exploit-DBVexDay Proof
Adobe Flash - Out-of-Bounds Read when Placing Object
CVE-2016-1104dosmultiple17 May 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'gdi32.dll' Multiple 'EMF CREATECOLORSPACEW' Record Handling (MS16-055)
CVE-2016-0168doswindows17 May 2016
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
35RISK
open
Exploit-DBVexDay Proof
Symantec/Norton AntiVirus - ASPack Remote Heap/Pool Memory Corruption
CVE-2016-2208dosmultiple17 May 2016
The kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute a
28RISK
open
Exploit-DBVexDay Proof
Adobe Flash - '.MP4' Stack Corruption
CVE-2016-1096dosmultiple17 May 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RISK
open
Exploit-DBVexDay Proof
Web2py 2.14.5 - Multiple Vulnerabilities
CVE-2016-4807webappspython16 May 2016
Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS
23RISK
open
Exploit-DBVexDay Proof
Web2py 2.14.5 - Multiple Vulnerabilities
CVE-2016-4806webappspython16 May 2016
Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended u
28RISK
open
Exploit-DBVexDay Proof
Web2py 2.14.5 - Multiple Vulnerabilities
CVE-2016-4808webappspython16 May 2016
Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attack
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.