Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - 'Inline::InlineCallApplyTarget_Shared' does not Return the return Instruction
CVE-2017-11841doswindows27 Nov 2017
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, versio
35RISK
open
Exploit-DBVexDay Proof
ZTE ZXDSL 831CII - Improper Access Restrictions
CVE-2017-16953webappshardware27 Nov 2017
connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to mo
28RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - 'GlobOpt::OptTagChecks' Must Consider IsLoopPrePass Properly
CVE-2017-11840doswindows27 Nov 2017
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, versio
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Incorrect Function Declaration Scope
CVE-2017-11870doswindows27 Nov 2017
ChakraCore and Microsoft Edge in Windows 10 1703, 1709, and Windows Server, version 1709 allows an attacker to gain the
35RISK
open
Exploit-DBVexDay Proof
Exim 4.89 - 'BDAT' Denial of Service
CVE-2017-16944dosmultiple27 Nov 2017
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - 'BailOutOnTaggedValue' Bailouts Type Confusion
CVE-2017-11839doswindows27 Nov 2017
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows a
35RISK
open
Exploit-DBVexDay Proof
Linux Kernel - 'mincore()' Uninitialized Kernel Heap Page Disclosure
CVE-2017-16994doslinux24 Nov 2017
The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, w
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::SVGPatternElement::collectPatternAttributes' Out-of-Bounds Read
CVE-2017-13783dosmultiple22 Nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::RenderObject::previousSibling' Use-After-Free
CVE-2017-13798dosmultiple22 Nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::AXObjectCache::performDeferredCacheUpdate' Use-After-Free
CVE-2017-13795dosmultiple22 Nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::DocumentLoader::frameLoader' Use-After-Free
CVE-2017-13794dosmultiple22 Nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::TreeScope::documentScope' Use-After-Free
CVE-2017-13796dosmultiple22 Nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::SimpleLineLayout::RunResolver::runForPoint' Out-of-Bounds Read
CVE-2017-13784dosmultiple22 Nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::FormSubmission::create' Use-After-Free
CVE-2017-13791dosmultiple22 Nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::InputType::element' Use-After-Free (2)
CVE-2017-13792dosmultiple22 Nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::PositionIterator::decrement' Use-After-Free
CVE-2017-13797dosmultiple22 Nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::RenderText::localCaretRect' Out-of-Bounds Read
CVE-2017-13785dosmultiple22 Nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'WebCore::Style::TreeResolver::styleForElement' Use-After-Free
CVE-2017-13802dosmultiple22 Nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 10 - 'nt!NtQueryDirectoryFile (luafv!LuafvCopyDirectoryEntry)' Pool Memory Disclosure
CVE-2017-11831doswindows21 Nov 2017
Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2,
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 10 - CiSetFileCache TOCTOU Security Feature Bypass
CVE-2017-11830localwindows20 Nov 2017
Device Guard in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allow
23RISK
open
Exploit-DBVexDay Proof
iOS < 11.1 / tvOS < 11.1 / watchOS < 4.1 - Denial of Service
CVE-2017-13849dosios20 Nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. tvOS before 11.1 is affected. watchOS be
23RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra: JIT - 'Lowerer::LowerBoundCheck' Incorrect Integer Overflow Check
CVE-2017-11861doswindows16 Nov 2017
Microsoft Edge in Windows 10 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker t
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Type Confusion with switch Statements
CVE-2017-11811doswindows16 Nov 2017
ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - 'Object.setPrototypeOf' Memory Corruption
CVE-2017-8751doswindows16 Nov 2017
Microsoft Edge in Microsoft Windows 1703 allows an attacker to execute arbitrary code in the context of the current user
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra: JIT - 'OP_Memset' Type Confusion
CVE-2017-11873doswindows16 Nov 2017
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709
35RISK
open
Exploit-DBVexDay Proof
Zeta Components Mail 1.8.1 - Remote Code Execution
CVE-2017-15806webappsphp16 Nov 2017
The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the s
28RISK
open
Exploit-DBVexDay Proof
D-Link DIR-605L < 2.08 - Denial of Service
CVE-2017-9675doshardware14 Nov 2017
On D-Link DIR-605L devices, firmware before 2.08UIBetaB01.bin allows an unauthenticated GET request to trigger a reboot.
28RISK
open
Exploit-DBVexDay Proof
Kirby CMS < 2.5.7 - Cross-Site Scripting
CVE-2017-16807webappsphp13 Nov 2017
A cross-site Scripting (XSS) vulnerability in Kirby Panel before 2.3.3, 2.4.x before 2.4.2, and 2.5.x before 2.5.7 exist
23RISK
open
Exploit-DBVexDay Proof
MyBB 1.8.13 - Cross-Site Scripting
CVE-2017-16781webappsphp11 Nov 2017
The installer in MyBB before 1.8.13 has XSS.
23RISK
open
Exploit-DBVexDay Proof
MyBB 1.8.13 - Remote Code Execution
CVE-2017-16780webappsphp11 Nov 2017
The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration fi
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.