Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,442cataloged exploits
34,431CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DB
Tecnovision DLX Spot - SSH Backdoor Access
CVE-2017-12929remotemultiple19 May 2017
Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users
28RISK
open
Exploit-DB
KDE 4/5 - 'KAuth' Local Privilege Escalation
CVE-2017-8422locallinux18 May 2017
KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and le
23RISK
open
Exploit-DB
KDE 4/5 - 'KAuth' Local Privilege Escalation
CVE-2017-8849locallinux18 May 2017
smb4k before 2.0.1 allows local users to gain root privileges by leveraging failure to verify arguments to the mount hel
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 8/8.1/2012 R2 (x64) - 'EternalBlue' SMB Remote Code Execution (MS17-010)
CVE-2017-0144HIGHunder attackransomwareremotewindows_x86-6417 May 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 7/2008 R2 - 'EternalBlue' SMB Remote Code Execution (MS17-010)
CVE-2017-0144HIGHunder attackransomwareremotewindows17 May 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Exploit-DB
INFOR EAM 11.0 Build 201410 - Persistent Cross-Site Scripting via Comment Fields
CVE-2017-7953webappsxml17 May 2017
INFOR EAM V11.0 Build 201410 has XSS via comment fields.
23RISK
open
Exploit-DBVexDay Proof
Adobe Flash - Out-of-Bounds Read in Getting TextField Width
CVE-2017-3064dosmultiple17 May 2017
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability when parsing a sh
28RISK
open
Exploit-DBVexDay Proof
Adobe Flash - Margin Handling Heap Corruption
CVE-2017-3061dosmultiple17 May 2017
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Running Object Table Register ROTFLAGS_ALLOWANYCLIENT Privilege Escalation
CVE-2017-0214doswindows17 May 2017
Windows COM in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - COM Aggregate Marshaler/IRemUnknown2 Type Confusion Privilege Escalation
CVE-2017-0213HIGHunder attackransomwarelocalwindows17 May 2017
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RISK
open
Exploit-DBVexDay Proof
Apple iOS < 10.3.2 - Notifications API Denial of Service
CVE-2017-6982dosios17 May 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. The issue involves the "Notifications"
23RISK
open
Exploit-DB
Oracle PeopleSoft Enterprise PeopleTools < 8.55 - Remote Code Execution Via Blind XML External Entity
CVE-2017-3548webappsjava17 May 2017
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integratio
35RISK
open
Exploit-DBVexDay Proof
Adobe Flash - AVC Deblocking Out-of-Bounds Read
CVE-2017-3068dosmultiple17 May 2017
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Advanced V
28RISK
open
Exploit-DB
INFOR EAM 11.0 Build 201410 - 'filtervalue' SQL Injection
CVE-2017-7952webappsxml17 May 2017
INFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter.
23RISK
open
Exploit-DBVexDay Proof
WordPress Plugin PHPMailer 4.6 - Host Header Command Injection (Metasploit)
CVE-2016-10033CRITICALunder attackremotephp17 May 2017
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
Exploit-DB
Mailcow 0.14 - Cross-Site Request Forgery
CVE-2017-8928webappsphp15 May 2017
mailcow 0.14, as used in "mailcow: dockerized" and other products, has CSRF.
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 7 Kernel - Pool-Based Out-of-Bounds Reads Due to bind() Implementation Bugs in afd.sys / tcpip.sys
CVE-2017-0175doswindows15 May 2017
The Windows kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows authenticated attackers to obtain sen
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 7 Kernel - Pool-Based Out-of-Bounds Reads Due to bind() Implementation Bugs in afd.sys / tcpip.sys
CVE-2017-0220doswindows15 May 2017
The Windows kernel in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 2012 Gold allows authenticat
23RISK
open
Exploit-DBVexDay Proof
Quest Privilege Manager - pmmasterd Buffer Overflow (Metasploit)
CVE-2017-6553remotelinux15 May 2017
Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full
50RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 7 Kernel - Uninitialized Memory in the Default dacl Descriptor of System Processes Token
CVE-2017-0258doswindows15 May 2017
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 10 Kernel - 'nt!NtTraceControl (EtwpSetProviderTraits)' Pool Memory Disclosure
CVE-2017-0259doswindows15 May 2017
The Windows kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703,
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 7 Kernel - 'win32k!xxxClientLpkDrawTextEx' Stack Memory Disclosure
CVE-2017-0245doswindows15 May 2017
The kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1 and Windows Server 2012 Gold allow a local
23RISK
open
Exploit-DBVexDay Proof
Halliburton LogView Pro 10.0.1 - Local Buffer Overflow (SEH)
CVE-2017-8926doswindows14 May 2017
Buffer overflow in Halliburton LogView Pro 10.0.1 allows attackers to cause a denial of service or possibly have unspeci
23RISK
open
Exploit-DBVexDay Proof
Larson VizEx Reader 9.7.5 - Local Buffer Overflow (SEH)
CVE-2017-8927doswindows14 May 2017
Buffer overflow in Larson VizEx Reader 9.7.5 allows attackers to cause a denial of service or possibly have unspecified
23RISK
open
Exploit-DB
Dive Assistant Template Builder 8.0 - XML External Entity Injection
CVE-2017-8918localwindows12 May 2017
XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 4.8.0-41-generic (Ubuntu) - Packet Socket Local Privilege Escalation
CVE-2017-7308locallinux11 May 2017
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate cer
43RISK
open
Exploit-DB
Vanilla Forums < 2.3 - Remote Code Execution
CVE-2016-10073remotephp11 May 2017
The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the emai
60RISK
open
Exploit-DBVexDay Proof
Microsoft IIS - WebDav 'ScStoragePathFromUrl' Remote Overflow (Metasploit)
CVE-2017-7269CRITICALunder attackremotewindows11 May 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
Exploit-DBVexDay Proof
OpenVPN 2.4.0 - Denial of Service
CVE-2017-7478dosmultiple11 May 2017
OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control
28RISK
open
Exploit-DB
MiniUPnP MiniUPnPc < 2.0 - Remote Denial of Service
CVE-2017-8798dosmultiple11 May 2017
Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of s
28RISK
open
previouspage 142 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.