Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DB
Google Android Broadcom Wi-Fi Driver - Memory Corruption
CVE-2016-0801dosandroid11 May 2016
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01
35RISK
open
Exploit-DBVexDay Proof
Adobe Reader DC 15.010.20060 - Memory Corruption
CVE-2016-1077dosmultiple10 May 2016
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acro
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 7 - 'WebDAV' Local Privilege Escalation (MS16-016) (2)
CVE-2016-0051localwindows09 May 2016
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RISK
open
Exploit-DBVexDay Proof
ImageMagick 6.9.3-9 / 7.0.1-0 - 'ImageTragick' Delegate Arbitrary Command Execution (Metasploit)
CVE-2016-3714HIGHunder attacklocalmultiple09 May 2016
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RISK
open
Exploit-DBVexDay Proof
Adobe Flash (Multiple Scripts) - Use-After-Free When Rendering Displays (2)
CVE-2016-1013doswindows06 May 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows
28RISK
open
Exploit-DBVexDay Proof
Adobe Flash - MovieClip.duplicateMovieClip Use-After-Free
CVE-2016-1011doswindows06 May 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows
28RISK
open
Exploit-DBVexDay Proof
DotNetNuke 07.04.00 - Administration Authentication Bypass
CVE-2015-2794webappsasp06 May 2016
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain S
60RISK
open
Exploit-DBVexDay Proof
OpenSSL - Padding Oracle in AES-NI CBC MAC Check
CVE-2016-2107dosmultiple04 May 2016
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a
45RISK
open
Exploit-DB
ImageMagick 7.0.1-0 / 6.9.3-9 - 'ImageTragick ' Multiple Vulnerabilities
CVE-2016-3716dosmultiple04 May 2016
The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via
28RISK
open
Exploit-DBVexDay Proof
Linux Kernel 4.4.x (Ubuntu 16.04) - 'double-fdput()' bpf(BPF_PROG_LOAD) Privilege Escalation
CVE-2016-4557locallinux04 May 2016
The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly mai
43RISK
open
Exploit-DB
NetCommWireless HSPA 3G10WVE Wireless Router - Multiple Vulnerabilities
CVE-2015-6024webappscgi04 May 2016
ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remot
28RISK
open
Exploit-DBVexDay Proof
Linux Kernel (Ubuntu 16.04) - Reference Count Overflow Using BPF Maps
CVE-2016-4558doslinux04 May 2016
The BPF subsystem in the Linux kernel before 4.5.5 mishandles reference counts, which allows local users to cause a deni
23RISK
open
Exploit-DBVexDay Proof
McAfee LiveSafe 14.0 - Relocations Processing Memory Corruption
CVE-2016-4535doswindows04 May 2016
Integer signedness error in the AV engine before DAT 8145, as used in McAfee LiveSafe 14.0, allows remote attackers to c
23RISK
open
Exploit-DBVexDay Proof
WordPress Plugin Ninja Forms 2.9.36 < 2.9.42 - File Upload (Metasploit)
CVE-2016-1209webappsmultiple04 May 2016
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via
50RISK
open
Exploit-DB
ImageMagick 7.0.1-0 / 6.9.3-9 - 'ImageTragick ' Multiple Vulnerabilities
CVE-2016-3717dosmultiple04 May 2016
The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files vi
28RISK
open
Exploit-DB
ImageMagick 7.0.1-0 / 6.9.3-9 - 'ImageTragick ' Multiple Vulnerabilities
CVE-2016-3718MEDIUMunder attackdosmultiple04 May 2016
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct
85RISK
open
Exploit-DB
ImageMagick 7.0.1-0 / 6.9.3-9 - 'ImageTragick ' Multiple Vulnerabilities
CVE-2016-3715MEDIUMunder attackdosmultiple04 May 2016
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary fi
85RISK
open
Exploit-DB
NetCommWireless HSPA 3G10WVE Wireless Router - Multiple Vulnerabilities
CVE-2015-6023webappscgi04 May 2016
ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remot
28RISK
open
Exploit-DB
Zabbix Agent 3.0.1 - 'mysql.size' Shell Command Injection
CVE-2016-4338locallinux04 May 2016
The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x bef
28RISK
open
Exploit-DBVexDay Proof
CMS Made Simple < 1.12.1 / < 2.1.3 - Web Server Cache Poisoning
CVE-2016-2784webappsphp04 May 2016
CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduc
23RISK
open
Exploit-DB
ImageMagick 7.0.1-0 / 6.9.3-9 - 'ImageTragick ' Multiple Vulnerabilities
CVE-2016-3714HIGHunder attackdosmultiple04 May 2016
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RISK
open
Exploit-DB
QSEE - PRDiag* Commands Privilege Escalation
CVE-2015-6639localandroid02 May 2016
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to
23RISK
open
Exploit-DBVexDay Proof
Apache Struts - Dynamic Method Invocation Remote Code Execution (Metasploit)
CVE-2016-3081remotelinux02 May 2016
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, a
60RISK
open
Exploit-DB
PHP 7.0.5 - ZipArchive::getFrom* Integer Overflow
CVE-2016-3078remotephp28 Apr 2016
Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denia
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k.sys' TTF Processing EBLC / EBSC Tables Pool Corruption (MS16-039)
CVE-2016-0145doswindows28 Apr 2016
The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
35RISK
open
Exploit-DB
RomPager 4.34 (Multiple Router Vendors) - 'Misfortune Cookie' Authentication Bypass
CVE-2015-9222webappshardware27 Apr 2016
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W,
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - CSRSS BaseSrvCheckVDM Session 0 Process Creation Privilege Escalation (MS16-048)
CVE-2016-0151HIGHunder attackransomwaredoswindows27 Apr 2016
The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,
83RISK
open
Exploit-DB
Mach Race OSX - Local Privilege Escalation
CVE-2016-1757localosx27 Apr 2016
Race condition in the kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to execute arbitrary code
28RISK
open
Exploit-DBVexDay Proof
EMC ViPR SRM - Cross-Site Request Forgery
CVE-2016-0891webappsmultiple27 Apr 2016
Multiple cross-site request forgery (CSRF) vulnerabilities in administrative pages in EMC ViPR SRM before 3.7 allow remo
23RISK
open
Exploit-DBVexDay Proof
Advantech Webaccess Dashboard Viewer - Arbitrary File Upload (Metasploit)
CVE-2016-0854remotewindows26 Apr 2016
Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess
60RISK
open
previouspage 168 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.