Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DBVexDay Proof
WebKit JSC - 'BytecodeGenerator::emitGetByVal' Incorrect Optimization (1)
CVE-2017-7061dosmultiple12 Sep 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open
Exploit-DBVexDay Proof
Jungo DriverWizard WinDriver < 12.4.0 - Kernel Pool Overflow / Local Privilege Escalation (2)
CVE-2017-14344localwindows12 Sep 2017
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must
23RISK
open
Exploit-DBVexDay Proof
Apache Struts 2.0.1 < 2.3.33 / 2.5 < 2.5.10 - Arbitrary Code Execution
CVE-2017-12611remotemultiple08 Sep 2017
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag in
60RISK
open
Exploit-DBVexDay Proof
Jungo DriverWizard WinDriver < 12.4.0 - Kernel Out-of-Bounds Write Privilege Escalation
CVE-2017-14075localwindows06 Sep 2017
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must
23RISK
open
Exploit-DBVexDay Proof
Jungo DriverWizard WinDriver < 12.4.0 - Kernel Pool Overflow / Local Privilege Escalation (1)
CVE-2017-14153localwindows06 Sep 2017
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must
23RISK
open
Exploit-DBVexDay Proof
RubyGems < 2.6.13 - Arbitrary File Overwrite
CVE-2017-0901locallinux04 Sep 2017
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potenti
28RISK
open
Exploit-DBVexDay Proof
IBM Notes 8.5.x/9.0.x - Denial of Service
CVE-2017-1129dosmultiple02 Sep 2017
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it coul
50RISK
open
Exploit-DBVexDay Proof
IBM Notes 8.5.x/9.0.x - Denial of Service (2)
CVE-2017-1130dosmultiple31 Aug 2017
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it woul
43RISK
open
Exploit-DBVexDay Proof
Git < 2.7.5 - Command Injection (Metasploit)
CVE-2017-1000117remotepython31 Aug 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RISK
open
Exploit-DBVexDay Proof
Metasploit Web UI < 4.14.1-20170828 - Cross-Site Request Forgery
CVE-2017-15084webappsruby30 Aug 2017
The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.
23RISK
open
Exploit-DBVexDay Proof
Apple iOS < 10.3.1 - Kernel
CVE-2017-6995localios26 Aug 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISK
open
Exploit-DBVexDay Proof
Apple iOS < 10.3.1 - Kernel
CVE-2017-6996localios26 Aug 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISK
open
Exploit-DBVexDay Proof
Apple iOS < 10.3.1 - Kernel
CVE-2017-6989localios26 Aug 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISK
open
Exploit-DBVexDay Proof
Apple iOS < 10.3.1 - Kernel
CVE-2017-6997localios26 Aug 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISK
open
Exploit-DBVexDay Proof
Apple iOS < 10.3.1 - Kernel
CVE-2017-6999localios26 Aug 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISK
open
Exploit-DBVexDay Proof
Apple iOS < 10.3.1 - Kernel
CVE-2017-6998localios26 Aug 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISK
open
Exploit-DBVexDay Proof
Apple iOS < 10.3.1 - Kernel
CVE-2017-6994localios26 Aug 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISK
open
Exploit-DBVexDay Proof
Apple iOS < 10.3.1 - Kernel
CVE-2017-6979localios26 Aug 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RISK
open
Exploit-DBVexDay Proof
IBM OpenAdmin Tool - SOAP welcomeServer PHP Code Execution (Metasploit)
CVE-2017-1092remotephp22 Aug 2017
IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system a
60RISK
open
Exploit-DBVexDay Proof
Symantec Messaging Gateway 10.6.3-2 - Root Remote Command Execution
CVE-2017-6327HIGHunder attackwebappsjsp18 Aug 2017
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situ
83RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - Incorrect JIT Optimization with TypedArray Setter #2
CVE-2017-8548doswindows17 Aug 2017
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to obtain
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'JavascriptArray::ConcatArgs' Type Confusion
CVE-2017-8634doswindows17 Aug 2017
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current u
45RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - Uninitialized Arguments (2)
CVE-2017-8670doswindows17 Aug 2017
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - Uninitialized Arguments (1)
CVE-2017-8640doswindows17 Aug 2017
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary cod
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'EmitNew' Integer Overflow
CVE-2017-8636doswindows17 Aug 2017
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
45RISK
open
Exploit-DBVexDay Proof
Adobe Flash - Invoke Accesses Trait Out-of-Bounds
CVE-2017-3106doswindows17 Aug 2017
Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF fil
28RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - Out-of-Bounds Access when Fetching Source
CVE-2017-8657doswindows17 Aug 2017
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'PreVisitCatch' Missing Call
CVE-2017-8656doswindows17 Aug 2017
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'InterpreterStackFrame::ProcessLinkFailedAsmJsModule' Incorrect Usage of 'PushPopFrameHelper' (Denial of Service)
CVE-2017-8646doswindows17 Aug 2017
Microsoft Edge in Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in t
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'TryUndeleteProperty' Incorrect Usage (Denial of Service)
CVE-2017-8635doswindows17 Aug 2017
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
35RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.