Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DBVexDay Proof
McAfee Virus Scan Enterprise for Linux 1.9.2 < 2.0.2 - Remote Code Execution
CVE-2016-8020remotelinux13 Dec 2016
Improper control of generation of code vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earl
28RISK
open
Exploit-DBVexDay Proof
McAfee Virus Scan Enterprise for Linux 1.9.2 < 2.0.2 - Remote Code Execution
CVE-2016-8025remotelinux13 Dec 2016
SQL injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authen
23RISK
open
Exploit-DBVexDay Proof
McAfee Virus Scan Enterprise for Linux 1.9.2 < 2.0.2 - Remote Code Execution
CVE-2016-8016remotelinux13 Dec 2016
Information exposure in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote
23RISK
open
Exploit-DBVexDay Proof
McAfee Virus Scan Enterprise for Linux 1.9.2 < 2.0.2 - Remote Code Execution
CVE-2016-8022remotelinux13 Dec 2016
Authentication bypass by spoofing vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier)
28RISK
open
Exploit-DBVexDay Proof
McAfee Virus Scan Enterprise for Linux 1.9.2 < 2.0.2 - Remote Code Execution
CVE-2016-8019remotelinux13 Dec 2016
Cross-site scripting (XSS) vulnerability in attributes in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and ea
23RISK
open
Exploit-DBVexDay Proof
McAfee Virus Scan Enterprise for Linux 1.9.2 < 2.0.2 - Remote Code Execution
CVE-2016-8017remotelinux13 Dec 2016
Special element injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows a
23RISK
open
Exploit-DBVexDay Proof
McAfee Virus Scan Enterprise for Linux 1.9.2 < 2.0.2 - Remote Code Execution
CVE-2016-8021remotelinux13 Dec 2016
Improper verification of cryptographic signature vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3
23RISK
open
Exploit-DBVexDay Proof
iOS 10.1.x - Certificate File Memory Corruption
CVE-2016-7626dosios12 Dec 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. tvOS before 10.1 is affected. watchOS be
23RISK
open
Exploit-DBVexDay Proof
Sophos Web Appliance 4.2.1.3 - DiagnosticTools Remote Command Injection (Metasploit)
CVE-2016-9554webappslinux12 Dec 2016
The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injectio
28RISK
open
Exploit-DB
Apache 2.4.23 mod_http2 - Denial of Service
CVE-2016-8740doslinux12 Dec 2016
The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2
45RISK
open
Exploit-DBVexDay Proof
Sophos Web Appliance 4.2.1.3 - block/unblock Remote Command Injection (Metasploit)
CVE-2016-9553webappsphp12 Dec 2016
The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its w
28RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 9 - IEFRAME CSelection­Interact­Button­Behavior::_Update­Button­Location Use-After-Free (MS13-047)
CVE-2013-3111doswindows12 Dec 2016
Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service
35RISK
open
Exploit-DB
OpenSSL 1.1.0a/1.1.0b - Denial of Service
CVE-2016-7054doslinux11 Dec 2016
ChaCha20/Poly1305 heap-buffer-overflow
35RISK
open
Exploit-DB
D-Link DI-524 - Cross-Site Request Forgery
CVE-2017-5633webappshardware09 Dec 2016
Multiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 9 - MSHTML CDisp­Node::Insert­Sibling­Node Use-After-Free (MS13-037) (1)
CVE-2013-1309doswindows09 Dec 2016
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary co
35RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 9 - MSHTML CDisp­Node::Insert­Sibling­Node Use-After-Free (MS13-037) (2)
CVE-2013-1306doswindows09 Dec 2016
Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a cr
35RISK
open
Exploit-DB
Cisco Unified Communications Manager 7/8/9 - Directory Traversal
CVE-2013-5528webappshardware07 Dec 2016
Directory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager all
43RISK
open
Exploit-DB
OpenSSH 7.2 - Denial of Service
CVE-2016-6515doslinux07 Dec 2016
The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password a
35RISK
open
Exploit-DBVexDay Proof
Netgear R7000 - Command Injection
CVE-2016-6277HIGHunder attackwebappscgi07 Dec 2016
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.B
100RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - CMarkup::Ensure­Delete­CFState Use-After-Free (MS15-125)
CVE-2015-6168doswindows06 Dec 2016
Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a
35RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 9 - 'jscript9' Java­Script­Stack­Walker Memory Corruption (MS15-056)
CVE-2015-1730remotewindows06 Dec 2016
Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory cor
28RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 9 - CDoc::Execute­Script­Uri Use-After-Free (MS13-009)
CVE-2013-0019doswindows06 Dec 2016
Use-after-free vulnerability in Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary co
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - JSON.parse Info Leak
CVE-2016-7241doswindows06 Dec 2016
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of
45RISK
open
Exploit-DB
Microsoft Edge - CBase­Scriptable::Private­Query­Interface Memory Corruption (MS16-068)
CVE-2016-3222doswindows06 Dec 2016
Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a
35RISK
open
Exploit-DBVexDay Proof
Google Android - Inter-Process munmap with User-Controlled Size in android.graphics.Bitmap
CVE-2016-6707remoteandroid06 Dec 2016
An elevation of privilege vulnerability in System Server in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 coul
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 4.4.0 (Ubuntu 14.04/16.04 x86-64) - 'AF_PACKET' Race Condition Privilege Escalation
CVE-2016-8655locallinux_x86-6406 Dec 2016
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cau
43RISK
open
Exploit-DBVexDay Proof
Apache CouchDB 2.0.0 - Local Privilege Escalation
CVE-2016-8742localwindows05 Dec 2016
The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in t
23RISK
open
Exploit-DBVexDay Proof
Microsoft Event Viewer 1.0 - XML External Entity Injection
CVE-2019-0948MEDIUMlocalwindows05 Dec 2016
Windows Event Viewer Information Disclosure Vulnerability
38RISK
open
Exploit-DBVexDay Proof
Alcatel Lucent Omnivista 8770 - Remote Code Execution
CVE-2016-9796remotewindows04 Dec 2016
Alcatel-Lucent OmniVista 8770 2.0 through 3.0 exposes different ORBs interfaces, which can be queried using the GIOP pro
28RISK
open
Exploit-DB
Broadcom BCM43xx Wi-Fi - 'BroadPWN' Denial of Service
CVE-2017-9417dosandroid01 Dec 2016
Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn
35RISK
open
previouspage 156 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.