Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
8,460 exploits
VulnCheck XDB
client-side
CVE-2017-8570HIGHunder attack27 Mar 2018
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RISK
open
VulnCheck XDB
local
CVE-2017-0213HIGHunder attackransomware21 Mar 2018
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RISK
open
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALunder attackransomware20 Mar 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-7445CRITICALunder attack18 Mar 2018
A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remot
90RISK
open
VulnCheck XDB
local
CVE-2018-6789CRITICALunder attackransomware16 Mar 2018
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-2380MEDIUMunder attackransomware14 Mar 2018
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information pr
68RISK
open
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALunder attackransomware14 Mar 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-804612 Mar 2018
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISK
open
VulnCheck XDB
initial-access
CVE-2017-3066CRITICALunder attack12 Mar 2018
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier hav
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-10271HIGHunder attackransomware01 Mar 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALunder attackransomware28 Feb 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
VulnCheck XDB
client-side
CVE-2017-8570HIGHunder attack26 Feb 2018
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RISK
open
VulnCheck XDB
client-side
CVE-2018-4878HIGHunder attackransomware23 Feb 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISK
open
VulnCheck XDB
local
CVE-2017-1530322 Feb 2018
In CPUID CPU-Z before 1.43, there is an arbitrary memory write that results directly in elevation of privileges, because
23RISK
open
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALunder attackransomware15 Feb 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2015-537414 Feb 2018
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01;
60RISK
open
VulnCheck XDB
client-side
CVE-2018-4878HIGHunder attackransomware10 Feb 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISK
open
VulnCheck XDB
client-side
CVE-2018-4878HIGHunder attackransomware09 Feb 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISK
open
VulnCheck XDB
client-side
CVE-2017-11826HIGHunder attack09 Feb 2018
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Serv
93RISK
open
VulnCheck XDB
client-side
CVE-2017-12617HIGHunder attack09 Feb 2018
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISK
open
VulnCheck XDB
initial-access
CVE-2016-10033CRITICALunder attack09 Feb 2018
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
VulnCheck XDB
local
CVE-2018-100000107 Feb 2018
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISK
open
VulnCheck XDB
denial-of-service
CVE-2018-010107 Feb 2018
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Softw
45RISK
open
VulnCheck XDB
client-side
CVE-2006-477706 Feb 2018
Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) fo
60RISK
open
VulnCheck XDB
initial-access
CVE-2016-10033CRITICALunder attack06 Feb 2018
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2017-1254205 Feb 2018
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RISK
open
VulnCheck XDB
initial-access
CVE-2009-1151CRITICALunder attack03 Feb 2018
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALunder attackransomware28 Jan 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
VulnCheck XDB
local
CVE-2018-100000122 Jan 2018
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISK
open
VulnCheck XDB
client-side
CVE-2017-11882HIGHunder attackransomware16 Jan 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
previouspage 272 / 282next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.