Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
Jungo DriverWizard WinDriver < 12.4.0 - Kernel Pool Overflow / Local Privilege Escalation (2)
CVE-2017-14344localwindows12 Sep 2017
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must
23RISK
open
Exploit-DBVexDay Proof
WebKit JSC - 'BytecodeGenerator::emitGetByVal' Incorrect Optimization (1)
CVE-2017-7061dosmultiple12 Sep 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open
Exploit-DBVexDay Proof
Apache Struts 2.0.1 < 2.3.33 / 2.5 < 2.5.10 - Arbitrary Code Execution
CVE-2017-12611remotemultiple08 Sep 2017
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag in
60RISK
open
Exploit-DBVexDay Proof
Jungo DriverWizard WinDriver < 12.4.0 - Kernel Out-of-Bounds Write Privilege Escalation
CVE-2017-14075localwindows06 Sep 2017
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must
23RISK
open
Exploit-DBVexDay Proof
Jungo DriverWizard WinDriver < 12.4.0 - Kernel Pool Overflow / Local Privilege Escalation (1)
CVE-2017-14153localwindows06 Sep 2017
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must
23RISK
open
Exploit-DBVexDay Proof
RubyGems < 2.6.13 - Arbitrary File Overwrite
CVE-2017-0901locallinux04 Sep 2017
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potenti
28RISK
open
Exploit-DBVexDay Proof
IBM Notes 8.5.x/9.0.x - Denial of Service
CVE-2017-1129dosmultiple02 Sep 2017
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it coul
50RISK
open
Exploit-DBVexDay Proof
IBM Notes 8.5.x/9.0.x - Denial of Service (2)
CVE-2017-1130dosmultiple31 Aug 2017
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it woul
43RISK
open
Exploit-DBVexDay Proof
Git < 2.7.5 - Command Injection (Metasploit)
CVE-2017-1000117remotepython31 Aug 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RISK
open
Exploit-DBVexDay Proof
Metasploit Web UI < 4.14.1-20170828 - Cross-Site Request Forgery
CVE-2017-15084webappsruby30 Aug 2017
The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.
23RISK
open
Exploit-DBVexDay Proof
Apple iOS < 10.3.1 - Kernel
CVE-2017-6996localios26 Aug 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISK
open
Exploit-DBVexDay Proof
Apple iOS < 10.3.1 - Kernel
CVE-2017-6995localios26 Aug 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISK
open
Exploit-DBVexDay Proof
Apple iOS < 10.3.1 - Kernel
CVE-2017-6997localios26 Aug 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISK
open
Exploit-DBVexDay Proof
Apple iOS < 10.3.1 - Kernel
CVE-2017-6979localios26 Aug 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RISK
open
Exploit-DBVexDay Proof
Apple iOS < 10.3.1 - Kernel
CVE-2017-6989localios26 Aug 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISK
open
Exploit-DBVexDay Proof
Apple iOS < 10.3.1 - Kernel
CVE-2017-6994localios26 Aug 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISK
open
Exploit-DBVexDay Proof
Apple iOS < 10.3.1 - Kernel
CVE-2017-6998localios26 Aug 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISK
open
Exploit-DBVexDay Proof
Apple iOS < 10.3.1 - Kernel
CVE-2017-6999localios26 Aug 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISK
open
Exploit-DBVexDay Proof
IBM OpenAdmin Tool - SOAP welcomeServer PHP Code Execution (Metasploit)
CVE-2017-1092remotephp22 Aug 2017
IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system a
60RISK
open
Exploit-DBVexDay Proof
Symantec Messaging Gateway 10.6.3-2 - Root Remote Command Execution
CVE-2017-6327HIGHunder attackwebappsjsp18 Aug 2017
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situ
83RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'TryUndeleteProperty' Incorrect Usage (Denial of Service)
CVE-2017-8635doswindows17 Aug 2017
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge 40.15063.0.0 Chakra - Incorrect JIT Optimization with TypedArray Setter #3
CVE-2017-8601doswindows17 Aug 2017
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'EmitNew' Integer Overflow
CVE-2017-8636doswindows17 Aug 2017
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
45RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - Out-of-Bounds Access when Fetching Source
CVE-2017-8657doswindows17 Aug 2017
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - Incorrect JIT Optimization with TypedArray Setter #2
CVE-2017-8548doswindows17 Aug 2017
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to obtain
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - Uninitialized Arguments (2)
CVE-2017-8670doswindows17 Aug 2017
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - Uninitialized Arguments (1)
CVE-2017-8640doswindows17 Aug 2017
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary cod
35RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'JavascriptArray::ConcatArgs' Type Confusion
CVE-2017-8634doswindows17 Aug 2017
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current u
45RISK
open
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'JavascriptFunction::EntryCall' Fails to Handle 'CallInfo' Properly
CVE-2017-8671doswindows17 Aug 2017
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary
35RISK
open
Exploit-DBVexDay Proof
Adobe Flash - Invoke Accesses Trait Out-of-Bounds
CVE-2017-3106doswindows17 Aug 2017
Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF fil
28RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.