Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
Adobe Photoshop CC / Bridge CC - '.png' Parsing Memory Corruption (2)
CVE-2016-0952doswindows09 Feb 2016
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to exec
28RISK
open
Exploit-DBVexDay Proof
GE Industrial Solutions UPS SNMP Adapter < 4.8 - Multiple Vulnerabilities
CVE-2016-0862webappshardware04 Feb 2016
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authentica
23RISK
open
Exploit-DBVexDay Proof
GE Industrial Solutions UPS SNMP Adapter < 4.8 - Multiple Vulnerabilities
CVE-2016-0861webappshardware04 Feb 2016
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authentica
28RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX Kernel - no-more-senders Use-After-Free
CVE-2015-7047dososx28 Jan 2016
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX - 'gst_configure' Kernel Buffer Overflow
CVE-2015-7077dososx28 Jan 2016
The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX / iOS Kernel - IOHDIXControllUserClient::clientClose Use-After-Free/Double-Free
CVE-2015-7110dosmultiple28 Jan 2016
The Disk Images component in Apple OS X before 10.11.2 and tvOS before 9.1 allows local users to gain privileges or caus
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX - IOBluetoothHCIPacketLogUserClient Memory Corruption
CVE-2015-7047dososx28 Jan 2016
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX / iOS Kernel - iokit Registry Iterator Manipulation Double-Free
CVE-2015-7084dosmultiple28 Jan 2016
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX Kernel - IOAccelMemoryInfoUserClient Use-After-Free
CVE-2015-7047dososx28 Jan 2016
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX - 'IOHDIXControllerUserClient::convertClient' Buffer Integer Overflow
CVE-2015-6995dososx28 Jan 2016
The Disk Images component in Apple iOS before 9.1 and OS X before 10.11.1 misparses images, which allows attackers to ex
23RISK
open
Exploit-DBVexDay Proof
iOS Kernel - IOReportHub Use-After-Free
CVE-2016-1719dosios28 Jan 2016
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX - IOSCSIPeripheralDeviceType00 Userclient Type 12 Kernel NULL Dereference
CVE-2015-7068dososx28 Jan 2016
IOKit SCSI in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to exe
23RISK
open
Exploit-DBVexDay Proof
iOS Kernel - AppleOscarGyro Use-After-Free
CVE-2016-1719dosios28 Jan 2016
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri
23RISK
open
Exploit-DBVexDay Proof
iOS Kernel - IOHIDEventService Use-After-Free
CVE-2016-1719dosios28 Jan 2016
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX - OSMetaClassBase::safeMetaCast in IOAccelContext2::connectClient NULL Dereference
CVE-2015-6996dososx28 Jan 2016
IOAcceleratorFamily in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX - io_service_close Use-After-Free
CVE-2016-1720dososx28 Jan 2016
IOKit in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cau
23RISK
open
Exploit-DBVexDay Proof
iOS Kernel - AppleOscarAccelerometer Use-After-Free
CVE-2016-1719dosios28 Jan 2016
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri
23RISK
open
Exploit-DBVexDay Proof
iOS Kernel - AppleOscarCMA Use-After-Free
CVE-2016-1719dosios28 Jan 2016
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri
23RISK
open
Exploit-DBVexDay Proof
iOS Kernel - AppleOscarCompass Use-After-Free
CVE-2016-1719dosios28 Jan 2016
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX Kernel - IOAccelDisplayPipeUserClient2 Use-After-Free
CVE-2015-7047dososx28 Jan 2016
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX - 'IOBluetoothHCIUserClient' Arbitrary Kernel Code Execution
CVE-2015-7108dososx28 Jan 2016
The Bluetooth HCI interface in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial of serv
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX / iOS - Unsandboxable Kernel Use-After-Free in Mach Vouchers
CVE-2015-7047dosmultiple28 Jan 2016
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX - 'IntelAccelerator::gstqConfigure' Kernel NULL Dereference
CVE-2015-7106dososx28 Jan 2016
The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX / iOS - NECP System Control Socket Packet Parsing Kernel Code Execution Integer Overflow
CVE-2015-7083dosmultiple28 Jan 2016
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX / iOS - Multiple Kernel Uninitialized Variable Bugs Leading to Code Execution Vulnerabilities
CVE-2016-1721dosmultiple28 Jan 2016
The kernel in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges o
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX / iOS - Unsandboxable Kernel Code Exection Due to iokit Double Release in IOKit
CVE-2015-7084dososx28 Jan 2016
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX Kernel - Hypervisor Driver Use-After-Free
CVE-2015-7078dososx28 Jan 2016
Use-after-free vulnerability in Hypervisor in Apple OS X before 10.11.2 allows local users to gain privileges via vector
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX / iOS - Double-Delete IOHIDEventQueue::start Code Execution
CVE-2015-7112dosmultiple28 Jan 2016
The IOHIDFamily API in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attacke
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux (MS16-008) (1)
CVE-2016-0006localwindows25 Jan 2016
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux (MS16-008) (2)
CVE-2016-0007localwindows25 Jan 2016
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.