Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DB
WordPress Plugin Mail Masta 1.0 - SQL Injection
CVE-2017-6095webappsphp18 Feb 2017
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/list
23RISK
open
Exploit-DB
Netgear DGN2200v1/v2/v3/v4 - 'ping.cgi' Remote Command Execution
CVE-2017-6077CRITICALunder attackwebappshardware18 Feb 2017
ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitra
90RISK
open
Exploit-DBVexDay Proof
Artifex MuPDF mujstest 1.10a - Null Pointer Dereference
CVE-2017-6060doslinux17 Feb 2017
Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, Inc. MuPDF 1.10a allows remote attackers t
23RISK
open
Exploit-DBVexDay Proof
dotCMS 3.6.1 - Blind Boolean SQL Injection
CVE-2017-5344webappsphp16 Feb 2017
An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessib
23RISK
open
Exploit-DBVexDay Proof
Geutebruck 5.02024 G-Cam/EFD-2250 - 'testaction.cgi' Remote Command Execution (Metasploit)
CVE-2017-5173webappshardware15 Feb 2017
An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD
28RISK
open
Exploit-DBVexDay Proof
Geutebruck 5.02024 G-Cam/EFD-2250 - 'testaction.cgi' Remote Command Execution (Metasploit)
CVE-2017-5174webappshardware15 Feb 2017
An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authenticatio
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'gdi32.dll' EMR_SETDIBITSTODEVICE Heap Out-of-Bounds Reads / Memory Disclosure
CVE-2017-0038doswindows15 Feb 2017
gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
45RISK
open
Exploit-DBVexDay Proof
GOM Player 2.3.10.5266 - '.fpx' Denial of Service
CVE-2017-5881doswindows15 Feb 2017
GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspeci
23RISK
open
Exploit-DBVexDay Proof
Cisco ASA - WebVPN CIFS Handling Buffer Overflow
CVE-2017-3807doshardware15 Feb 2017
A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software,
28RISK
open
Exploit-DB
OpenText Documentum D2 - Remote Code Execution
CVE-2017-5586remotejava15 Feb 2017
OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a craf
28RISK
open
Exploit-DBVexDay Proof
NVIDIA Driver 375.70 - Buffer Overflow in Command Buffer Submission
CVE-2017-0313doswindows15 Feb 2017
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) implem
23RISK
open
Exploit-DBVexDay Proof
NVIDIA Driver 375.70 - DxgkDdiEscape 0x100008b Out-of-Bounds Read/Write
CVE-2017-0312doswindows15 Feb 2017
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handle
23RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - TypedArray.sort Use-After-Free (MS16-145)
CVE-2016-7288doswindows14 Feb 2017
The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (m
45RISK
open
Exploit-DBVexDay Proof
Google Android - Inter-process munmap in android.util.MemoryIntArray
CVE-2017-0411dosandroid14 Feb 2017
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
23RISK
open
Exploit-DBVexDay Proof
Google Android - android.util.MemoryIntArray Ashmem Race Conditions
CVE-2017-0412dosandroid14 Feb 2017
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
23RISK
open
Exploit-DB
F5 BIG-IP 11.6 SSL Virtual Server - 'Ticketbleed' Memory Disclosure
CVE-2016-9244remotehardware14 Feb 2017
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may
45RISK
open
Exploit-DBVexDay Proof
ntfs-3g - Unsanitized modprobe Environment Privilege Escalation
CVE-2017-0358HIGHlocallinux14 Feb 2017
ntfs-3g: Modprobe influence vulnerability via environment variables
56RISK
open
Exploit-DB
Linux Kernel 3.10.0 (CentOS 7) - Denial of Service
CVE-2017-5972doslinux12 Feb 2017
The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fa
28RISK
open
Exploit-DBVexDay Proof
HP Smart Storage Administrator 2.30.6.0 - Remote Command Injection (Metasploit)
CVE-2016-8523remotemultiple10 Feb 2017
A Remote Arbitrary Code Execution vulnerability in HPE Smart Storage Administrator version before v2.60.18.0 was found.
28RISK
open
Exploit-DB
F5 BIG-IP SSL Virtual Server - 'Ticketbleed' Memory Disclosure
CVE-2016-9244remotehardware10 Feb 2017
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may
45RISK
open
Exploit-DB
Node.JS - 'node-serialize' Remote Code Execution
CVE-2017-5941remotelinux08 Feb 2017
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISK
open
Exploit-DB
OpenBSD HTTPd < 6.0 - Memory Exhaustion Denial of Service
CVE-2017-5850dosopenbsd07 Feb 2017
httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for
28RISK
open
Exploit-DB
CUPS < 2.0.3 - Remote Command Execution
CVE-2015-1158remotelinux03 Feb 2017
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-va
28RISK
open
Exploit-DB
ntfs-3g (Debian 9) - Local Privilege Escalation
CVE-2017-0358HIGHlocallinux03 Feb 2017
ntfs-3g: Modprobe influence vulnerability via environment variables
56RISK
open
Exploit-DBVexDay Proof
Apple WebKit - Type Confusion in RenderBox with Accessibility Enabled
CVE-2017-2373dosmultiple01 Feb 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISK
open
Exploit-DBVexDay Proof
Apple WebKit - 'HTMLFormElement::reset()' Use-After Free
CVE-2017-2362dososx01 Feb 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISK
open
Exploit-DBVexDay Proof
Apple WebKit - 'HTMLKeygenElement' Type Confusion
CVE-2017-2369dosmultiple01 Feb 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISK
open
Exploit-DB
AlienVault OSSIM/USM < 5.3.1 - Remote Code Execution (Metasploit)
CVE-2016-8580webappsphp31 Jan 2017
PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vuln
23RISK
open
Exploit-DB
PHP PEAR 1.10.1 - Arbitrary File Download
CVE-2017-5630webappsphp30 Jan 2017
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenam
28RISK
open
Exploit-DBVexDay Proof
Netgear Routers - Password Disclosure
CVE-2017-5521HIGHunder attackwebappshardware30 Jan 2017
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R
100RISK
open
previouspage 152 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.