Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DB
Oracle VM VirtualBox < 5.0.32 / < 5.1.14 - Local Privilege Escalation
CVE-2017-3316locallinux27 Jan 2017
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: GUI). Supported versions tha
23RISK
open
Exploit-DB
Radisys MRF - Command Injection
CVE-2016-10043webappscgi27 Jan 2017
An issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was dis
23RISK
open
Exploit-DBVexDay Proof
Apple macOS 10.12.1 / iOS 10.2 - Kernel Userspace Pointer Memory Corruption
CVE-2017-2370dosmultiple26 Jan 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RISK
open
Exploit-DBVexDay Proof
Apple macOS 10.12.1 / iOS Kernel - 'host_self_trap' Use-After-Free
CVE-2017-2360dosmultiple26 Jan 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
23RISK
open
Exploit-DB
OpenSSL 1.1.0 - Remote Client Denial of Service
CVE-2017-3730dosmultiple26 Jan 2017
Bad (EC)DHE parameters cause a client crash
35RISK
open
Exploit-DB
OpenSSH 6.8 < 6.9 - 'PTY' Local Privilege Escalation
CVE-2015-6565locallinux26 Jan 2017
sshd in OpenSSH 6.8 and 6.9 uses world-writable permissions for TTY devices, which allows local users to cause a denial
23RISK
open
Exploit-DBVexDay Proof
Apple macOS 10.12.1 / iOS Kernel - 'IOService::matchPassive' Use-After-Free
CVE-2017-2353dosmultiple26 Jan 2017
An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Bluetooth"
23RISK
open
Exploit-DBVexDay Proof
Palo Alto Networks Terminal Services Agent 7.0.3-13 - Integer Overflow
CVE-2017-5329localwindows26 Jan 2017
Palo Alto Networks Terminal Services Agent before 7.0.7 allows local users to gain privileges via vectors that trigger a
23RISK
open
Exploit-DB
Systemd 228 (SUSE 12 SP2 / Ubuntu Touch 15.04) - Local Privilege Escalation
CVE-2016-10156locallinux24 Jan 2017
A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd tim
23RISK
open
Exploit-DBVexDay Proof
Mozilla Firefox < 50.0.2 - 'nsSMILTimeContainer::NotifyTimeChange()' Remote Code Execution (Metasploit)
CVE-2016-9079HIGHunder attackremotewindows24 Jan 2017
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RISK
open
Exploit-DB
Geutebrueck GCore 1.3.8.42/1.4.2.37 - Remote Code Execution (Metasploit)
CVE-2017-11517remotewindows24 Jan 2017
Stack-based buffer overflow in GCoreServer.exe in the server in Geutebrueck Gcore 1.3.8.42 and 1.4.2.37 allows remote at
43RISK
open
Exploit-DBVexDay Proof
Oracle OpenJDK Runtime Environment 1.8.0_112-b15 - Java Serialization Denial Of Service
CVE-2017-3241dosmultiple23 Jan 2017
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versi
35RISK
open
Exploit-DB
NTOPNG 2.4 Web Interface - Cross-Site Request Forgery
CVE-2017-5473webappslinux22 Jan 2017
Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authenticati
23RISK
open
Exploit-DBVexDay Proof
PageKit 1.0.10 - Password Reset
CVE-2017-5594webappsphp21 Jan 2017
An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the reg
23RISK
open
Exploit-DB
Joomla! < 2.5.2 - Admin Creation
CVE-2012-1563webappsphp20 Jan 2017
Joomla! before 2.5.3 allows Admin Account Creation.
23RISK
open
Exploit-DB
Joomla! < 3.6.4 - Admin Takeover
CVE-2016-9838webappsphp20 Jan 2017
An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of
28RISK
open
Exploit-DB
Apple macOS Sierra 10.12.1 - 'physmem' Local Privilege Escalation
CVE-2016-1825localmacos16 Jan 2017
IOHIDFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a d
23RISK
open
Exploit-DB
Apple macOS Sierra 10.12.1 - 'physmem' Local Privilege Escalation
CVE-2016-7617localmacos16 Jan 2017
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth"
23RISK
open
Exploit-DBVexDay Proof
Cisco Firepower Management Console 6.0 - Post Authentication UserAdd (Metasploit)
CVE-2016-6433remotelinux13 Jan 2017
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users
60RISK
open
Exploit-DB
Mozilla Firefox < 50.1.0 - Use-After-Free
CVE-2016-9899doswindows13 Jan 2017
Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption.
28RISK
open
Exploit-DBVexDay Proof
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities
CVE-2017-6340webappshardware12 Jan 2017
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/repor
23RISK
open
Exploit-DBVexDay Proof
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities
CVE-2017-6339webappshardware12 Jan 2017
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate d
23RISK
open
Exploit-DBVexDay Proof
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities
CVE-2017-6338webappshardware12 Jan 2017
Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow
23RISK
open
Exploit-DBVexDay Proof
Adobe Flash Player 24.0.0.186 - 'ActionGetURL2' Out-of-Bounds Memory Corruption (1)
CVE-2017-2930dosmultiple11 Jan 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurre
28RISK
open
Exploit-DBVexDay Proof
Adobe Flash Player 24.0.0.186 - 'ActionGetURL2' Out-of-Bounds Memory Corruption (2)
CVE-2017-2930dosmultiple11 Jan 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurre
28RISK
open
Exploit-DB
Apple OS X Yosemite - 'flow_divert-heap-overflow' Kernel Panic
CVE-2016-1827dososx10 Jan 2017
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RISK
open
Exploit-DB
Ansible 2.1.4/2.2.1 - Command Execution
CVE-2016-9587MEDIUMremotelinux09 Jan 2017
Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent fr
38RISK
open
Exploit-DB
Microsoft Windows Kernel - 'win32k.sys NtSetWindowLongPtr' Local Privilege Escalation (MS16-135) (2)
CVE-2016-7255HIGHunder attacklocalwindows08 Jan 2017
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RISK
open
Exploit-DB
Splunk 6.1.1 - 'Referer' Header Cross-Site Scripting
CVE-2014-8380webappsphp07 Jan 2017
Cross-site scripting (XSS) vulnerability in Splunk 6.1.1 allows remote attackers to inject arbitrary web script or HTML
23RISK
open
Exploit-DB
Microsoft Edge (Windows 10) - 'chakra.dll' Information Leak / Type Confusion Remote Code Execution
CVE-2016-7201HIGHunder attackremotewindows05 Jan 2017
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RISK
open
previouspage 153 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.