Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DBVexDay Proof
Microsoft Windows - Uniscribe Font Processing Multiple Heap Out-of-Bounds and Wild Reads (MS17-011)
CVE-2017-0125doswindows20 Mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Uniscribe Heap Out-of-Bounds Read in 'USP10!ScriptApplyLogicalWidth' Triggered via EMF (MS17-013)
CVE-2017-0062doswindows20 Mar 2017
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; W
28RISK
open
Exploit-DB
DIGISOL DG-HR1400 1.00.02 Wireless Router - Privilege Escalation
CVE-2017-6896webappshardware18 Mar 2017
Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from
23RISK
open
Exploit-DB
Cisco IOS 12.2 < 12.4 / 15.0 < 15.6 - Security Association Negotiation Request Device Memory
CVE-2016-6415HIGHunder attackremotehardware17 Mar 2017
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x
100RISK
open
Exploit-DB
AXIS (Multiple Products) - Cross-Site Request Forgery
CVE-2015-8255webappshardware17 Mar 2017
AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.
23RISK
open
Exploit-DB
AXIS Communications - Cross-Site Scripting / Content Injection
CVE-2015-8258webappshardware17 Mar 2017
AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via v
23RISK
open
Exploit-DB
Oracle Knowledge Management 12.1.1 < 12.2.5 - XML External Entity Leading To Remote Code Execution
CVE-2016-3542webappsmultiple17 Mar 2017
Unspecified vulnerability in the Oracle Knowledge Management component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3
23RISK
open
Exploit-DB
Microsoft Windows DVD Maker 6.1.7 - XML External Entity Injection
CVE-2017-0045localwindows16 Mar 2017
Windows DVD Maker in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2 does not properly parse cr
23RISK
open
Exploit-DB
Cerberus FTP Server 8.0.10.3 - 'MLST' Buffer Overflow (PoC)
CVE-2017-6880doswindows16 Mar 2017
Buffer overflow in Cerberus FTP Server 8.0.10.3 allows remote attackers to cause a denial of service (daemon crash) or p
28RISK
open
Exploit-DB
CommVault Edge 11 SP6 - Stack Buffer Overflow (PoC)
CVE-2017-3195doswindows16 Mar 2017
Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack
28RISK
open
Exploit-DB
WordPress Plugin Membership Simplified 1.58 - Arbitrary File Download
CVE-2017-1002008webappsphp16 Mar 2017
Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membe
28RISK
open
Exploit-DBVexDay Proof
Microsoft Edge 38.14393.0.0 - JavaScript Engine Use-After-Free
CVE-2017-0070doswindows16 Mar 2017
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object
45RISK
open
Exploit-DBVexDay Proof
Adobe Flash - ATF Planar Decompression Heap Overflow
CVE-2017-2934dosmultiple15 Mar 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when parsing Adobe Te
28RISK
open
Exploit-DBVexDay Proof
Adobe Flash - AVC Header Slicing Heap Overflow
CVE-2017-2935dosmultiple15 Mar 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when processing the F
28RISK
open
Exploit-DBVexDay Proof
Adobe Flash - Metadata Parsing Out-of-Bounds Read
CVE-2017-2931dosmultiple15 Mar 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability related to the pa
28RISK
open
Exploit-DBVexDay Proof
Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - 'Jakarta' Multipart Parser OGNL Injection (Metasploit)
CVE-2017-5638CRITICALunder attackransomwareremotemultiple15 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - COM Session Moniker Privilege Escalation (MS17-012)
CVE-2017-0100localwindows15 Mar 2017
A DCOM object in Helppane.exe in Microsoft Windows 7 SP1; Windows Server 2008 R2; Windows 8.1; Windows Server 2012 Gold
23RISK
open
Exploit-DBVexDay Proof
Adobe Flash - ATF Thumbnailing Heap Overflow
CVE-2017-2933dosmultiple15 Mar 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability related to texture co
28RISK
open
Exploit-DB
Microsoft Windows - 'LoadUvsTable()' Heap Buffer Overflow
CVE-2016-7274doswindows15 Mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
35RISK
open
Exploit-DB
Sitecore CMS 8.1 Update-3 - Cross-Site Scripting
CVE-2016-8855webappsaspx15 Mar 2017
Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience
23RISK
open
Exploit-DBVexDay Proof
IBM WebSphere - RCE Java Deserialization (Metasploit)
CVE-2015-7450CRITICALunder attackremotewindows15 Mar 2017
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and
100RISK
open
Exploit-DBVexDay Proof
Adobe Flash - MovieClip Attach init Object Use-After-Free
CVE-2017-2932dosmultiple15 Mar 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable use after free vulnerability in the ActionScript
28RISK
open
Exploit-DB
APNGDis 2.8 - 'chunk size descriptor' Heap Buffer Overflow
CVE-2017-6192dosmultiple14 Mar 2017
Buffer overflow in APNGDis 2.8 and earlier allows a remote attackers to cause denial of service and possibly execute arb
23RISK
open
Exploit-DB
APNGDis 2.8 - 'image width / height chunk' Heap Buffer Overflow
CVE-2017-6193dosmultiple14 Mar 2017
Buffer overflow in APNGDis 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arb
23RISK
open
Exploit-DB
APNGDis 2.8 - 'filename' Stack Buffer Overflow (PoC)
CVE-2017-6191dosmultiple14 Mar 2017
Buffer overflow in APNGDis 2.8 and below allows a remote attacker to execute arbitrary code via a crafted filename.
23RISK
open
Exploit-DB
Cerberus FTP Server 8.0.10.1 - Denial of Service
CVE-2017-6367doswindows13 Mar 2017
In Cerberus FTP Server 8.0.10.1, a crafted HTTP request causes the Windows service to crash. The attack methodology invo
23RISK
open
Exploit-DBVexDay Proof
Netgear R7000 / R6400 - 'cgi-bin' Command Injection (Metasploit)
CVE-2016-6277HIGHunder attackremotecgi13 Mar 2017
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.B
100RISK
open
Exploit-DB
Nintendo Switch - WebKit Code Execution (PoC)
CVE-2016-4657HIGHunder attackdoshardware12 Mar 2017
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RISK
open
Exploit-DBVexDay Proof
MobaXterm Personal Edition 9.4 - Directory Traversal
CVE-2017-6805remotewindows11 Mar 2017
Directory traversal vulnerability in the TFTP server in MobaXterm Personal Edition 9.4 allows remote attackers to read a
23RISK
open
Exploit-DB
Fiyo CMS 2.0.6.1 - Privilege Escalation
CVE-2017-6823webappsphp11 Mar 2017
Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app
23RISK
open
previouspage 149 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.