Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
Dnsmasq < 2.78 - Stack Overflow
CVE-2017-14493dosmultiple02 Oct 2017
Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execu
45RISK
open
Exploit-DBVexDay Proof
Dnsmasq < 2.78 - Integer Underflow
CVE-2017-14496dosmultiple02 Oct 2017
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-su
35RISK
open
Exploit-DBVexDay Proof
Dnsmasq < 2.78 - Information Leak
CVE-2017-14494dosmultiple02 Oct 2017
dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vect
35RISK
open
Exploit-DBVexDay Proof
Trend Micro OfficeScan 11.0/XG (12.0) - Private Key Disclosure
CVE-2017-14083webappsphp28 Sep 2017
A vulnerability in Trend Micro OfficeScan 11.0 and XG allows remote unauthenticated users who can access the system to d
23RISK
open
Exploit-DBVexDay Proof
Trend Micro OfficeScan 11.0/XG (12.0) - Information Disclosure
CVE-2017-14085webappsphp28 Sep 2017
Information disclosure vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can acc
23RISK
open
Exploit-DBVexDay Proof
Trend Micro OfficeScan 11.0/XG (12.0) - Code Execution / Memory Corruption
CVE-2017-14086webappswindows28 Sep 2017
Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated u
23RISK
open
Exploit-DBVexDay Proof
Trend Micro OfficeScan 11.0/XG (12.0) - Man In The Middle Remote Code Execution
CVE-2017-14084remotewindows28 Sep 2017
A potential Man-in-the-Middle (MitM) attack vulnerability in Trend Micro OfficeScan 11.0 and XG may allow attackers to e
28RISK
open
Exploit-DBVexDay Proof
Trend Micro OfficeScan 11.0/XG (12.0) - 'Host' Header Injection
CVE-2017-14087webappsphp28 Sep 2017
A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Ho
23RISK
open
Exploit-DBVexDay Proof
Adobe Flash - Out-of-Bounds Write in MP4 Edge Processing
CVE-2017-11281dosmultiple25 Sep 2017
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploita
35RISK
open
Exploit-DBVexDay Proof
Adobe Flash - Out-of-Bounds Memory Read in MP4 Parsing
CVE-2017-11281dosmultiple25 Sep 2017
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploita
35RISK
open
Exploit-DBVexDay Proof
Supervisor 3.0a1 < 3.3.2 - XML-RPC (Authenticated) Remote Code Execution (Metasploit)
CVE-2017-11610remotelinux25 Sep 2017
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RISK
open
Exploit-DBVexDay Proof
Apple iOS 10.2 - Broadcom Out-of-Bounds Write when Handling 802.11k Neighbor Report Response
CVE-2017-11120remoteios25 Sep 2017
On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malformed RRM neighbor repo
23RISK
open
Exploit-DBVexDay Proof
Adobe Flash - Out-of-Bounds Read in applyToRange
CVE-2017-11282dosmultiple25 Sep 2017
Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation co
35RISK
open
Exploit-DBVexDay Proof
CyberLink LabelPrint < 2.5 - Local Buffer Overflow (SEH Unicode)
CVE-2017-14627localwindows23 Sep 2017
Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) au
43RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'Parser::ParseCatch' Does Not Handle 'eval()' (Denial of Service)
CVE-2017-11764doswindows21 Sep 2017
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - Deferred Parsing Makes Wrong Scopes
CVE-2017-8740doswindows21 Sep 2017
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current u
45RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - Chakra Incorrectly Parses Object Patterns
CVE-2017-8729doswindows21 Sep 2017
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current u
45RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'JavascriptFunction::ReparseAsmJsModule' Incorrectly Re-parses
CVE-2017-8755doswindows21 Sep 2017
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary
45RISK
open
Exploit-DBVexDay Proof
Microsoft Edge 38.14393.1066.0 - Memory Corruption with Partial Page Loading
CVE-2017-8731doswindows19 Sep 2017
Microsoft Edge in Microsoft Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge 38.14393.1066.0 - 'COptionsCollectionCacheItem::GetAt' Out-of-Bounds Read
CVE-2017-8734doswindows19 Sep 2017
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arb
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k!NtGdiGetGlyphOutline' Pool Memory Disclosure
CVE-2017-8680doswindows18 Sep 2017
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k!NtGdiEngCreatePalette' Stack Memory Disclosure
CVE-2017-8685doswindows18 Sep 2017
Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows information disclosure by the way
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'nt!NtSetIoCompletion / nt!NtRemoveIoCompletion' Pool Memory Disclosure
CVE-2017-8708doswindows18 Sep 2017
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k!NtGdiGetFontResourceInfoInternalW' Stack Memory Disclosure
CVE-2017-8684doswindows18 Sep 2017
Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k!NtGdiDoBanding' Stack Memory Disclosure
CVE-2017-8687doswindows18 Sep 2017
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k!NtQueryCompositionSurfaceBinding' Stack Memory Disclosure
CVE-2017-8678doswindows18 Sep 2017
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k.sys' '.TTF' Font Processing Out-of-Bounds Read with Malformed 'glyf' Table 'win32k!fsc_CalcGrayRow' (Denial of Service)
CVE-2017-8683doswindows18 Sep 2017
Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold a
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k.sys' '.TTF' Font Processing Out-of-Bounds Reads/Writes with Malformed 'fpgm' table 'win32k!bGeneratePath' (Denial of Service)
CVE-2017-8682doswindows18 Sep 2017
Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold a
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k!NtGdiGetPhysicalMonitorDescription' Stack Memory Disclosure
CVE-2017-8681doswindows18 Sep 2017
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RISK
open
Exploit-DBVexDay Proof
Infinite Automation Mango Automation - Command Injection (Metasploit)
CVE-2015-7901remotejsp13 Sep 2017
Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to execut
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.