Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DBVexDay Proof
Joomla! 3.4.4 Component Content History - SQL Injection / Remote Code Execution (Metasploit)
CVE-2015-7857remotephp23 Nov 2015
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.p
60RISK
open
Exploit-DB
Acrobat Reader DC 15.008.20082.15957 - '.PDF' Parsing Memory Corruption
CVE-2015-7622doswindows23 Nov 2015
Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Cursor Object Memory Leak (MS15-115)
CVE-2015-6102doswindows23 Nov 2015
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Device Contexts and NtGdiSelectBitmap Use-After-Free (MS15-115)
CVE-2015-6100doswindows23 Nov 2015
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RISK
open
Exploit-DBVexDay Proof
Joomla! 3.4.4 Component Content History - SQL Injection / Remote Code Execution (Metasploit)
CVE-2015-7297remotephp23 Nov 2015
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'ndis.sys' IOCTL 0x170034 (ndis!ndisNsiGetIfNameForIfIndex) Pool Buffer Overflow (MS15-117)
CVE-2015-6098doswindows23 Nov 2015
Buffer overflow in the Network Driver Interface Standard (NDIS) implementation in Microsoft Windows Vista SP2, Windows S
23RISK
open
Exploit-DB
Oracle Outside In PDF 8.5.2 - Parsing Memory Corruption (2)
CVE-2015-4878doswindows23 Nov 2015
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.
23RISK
open
Exploit-DBVexDay Proof
vBulletin 5.x - Remote Code Execution
CVE-2015-7808webappsphp23 Nov 2015
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH
60RISK
open
Exploit-DB
Oracle Outside In PDF 8.5.2 - Parsing Memory Corruption (1)
CVE-2015-4877doswindows23 Nov 2015
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Race Condition DestroySMWP Use-After-Free (MS15-115)
CVE-2015-6101doswindows23 Nov 2015
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RISK
open
Exploit-DBVexDay Proof
Nvidia Stereoscopic 3D Driver Service 7.17.13.5382 - Arbitrary Run Key Creation
CVE-2015-7865localwindows23 Nov 2015
nvSCPAPISvr.exe in the Stereoscopic 3D Driver Service in the NVIDIA GPU graphics driver R340 before 341.92, R352 before
23RISK
open
Exploit-DBVexDay Proof
Joomla! 3.4.4 Component Content History - SQL Injection / Remote Code Execution (Metasploit)
CVE-2015-7858remotephp23 Nov 2015
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RISK
open
Exploit-DB
ZTE ZXHN H108N R1A / ZXV10 W300 Routers - Multiple Vulnerabilities
CVE-2015-7252webappshardware20 Nov 2015
Cross-site scripting (XSS) vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_
23RISK
open
Exploit-DBVexDay Proof
Chkrootkit - Local Privilege Escalation (Metasploit)
CVE-2014-0476locallinux20 Nov 2015
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute a
38RISK
open
Exploit-DB
ZTE ADSL ZXV10 W300 Modems - Multiple Vulnerabilities
CVE-2015-7259webappshardware20 Nov 2015
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid
23RISK
open
Exploit-DB
ZTE ADSL ZXV10 W300 Modems - Multiple Vulnerabilities
CVE-2015-7258webappshardware20 Nov 2015
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain
28RISK
open
Exploit-DB
ZTE ZXHN H108N R1A / ZXV10 W300 Routers - Multiple Vulnerabilities
CVE-2015-7250webappshardware20 Nov 2015
Absolute path traversal vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE
28RISK
open
Exploit-DB
ZTE ZXHN H108N R1A / ZXV10 W300 Routers - Multiple Vulnerabilities
CVE-2015-7251webappshardware20 Nov 2015
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, whic
28RISK
open
Exploit-DB
ZTE ZXHN H108N R1A / ZXV10 W300 Routers - Multiple Vulnerabilities
CVE-2015-7248webappshardware20 Nov 2015
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote attackers to discover usernames and password ha
23RISK
open
Exploit-DB
ZTE ADSL ZXV10 W300 Modems - Multiple Vulnerabilities
CVE-2015-7257webappshardware20 Nov 2015
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrato
23RISK
open
Exploit-DB
ZTE ZXHN H108N R1A / ZXV10 W300 Routers - Multiple Vulnerabilities
CVE-2015-7249webappshardware20 Nov 2015
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote authenticated users to bypass intended access r
23RISK
open
Exploit-DB
ZTE ZXHN H108N R1A / ZXV10 W300 Routers - Multiple Vulnerabilities
CVE-2015-8703webappshardware20 Nov 2015
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE and ZXV10 W300 devices W300V1.0.0f_ER1_PE allow remote authe
23RISK
open
Exploit-DBVexDay Proof
F5 iControl - 'iCall::Script' Root Command Execution (Metasploit)
CVE-2015-3628remotehardware19 Nov 2015
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.
50RISK
open
Exploit-DB
Horde Groupware 5.2.10 - Cross-Site Request Forgery
CVE-2015-7984webappsphp19 Nov 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Hor
23RISK
open
Exploit-DBVexDay Proof
Google Chrome - open-vcdiff Out-of-Bounds Read in Browser Process Integer Overflow
CVE-2015-6763doslinux_x8619 Nov 2015
Multiple unspecified vulnerabilities in Google Chrome before 46.0.2490.71 allow attackers to cause a denial of service o
23RISK
open
Exploit-DB
IBM i Access 7.1 - Local Buffer Overflow / Code Execution
CVE-2015-7422localwindows18 Nov 2015
Buffer overflow in IBM i Access 7.1 on Windows allows local users to cause a denial of service (application crash) via u
23RISK
open
Exploit-DB
IBM i Access 7.1 - Local Buffer Overflow / Code Execution
CVE-2015-2023localwindows18 Nov 2015
Buffer overflow in IBM i Access 7.1 on Windows allows local users to gain privileges via unspecified vectors.
23RISK
open
Exploit-DB
D-Link DIR-816L Wireless Router - Cross-Site Request Forgery
CVE-2015-5999webappshardware16 Nov 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k.sys' Malformed TrueType Program TTF Font Processing Pool-Based Buffer Overflow (MS15-115)
CVE-2015-6104doswindows16 Nov 2015
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k.sys' Malformed OS/2 Table TTF Font Processing Pool-Based Buffer Overflow (MS15-115)
CVE-2015-6103doswindows16 Nov 2015
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RISK
open
previouspage 179 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.