Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,910GitHub PoC 14,997VulnCheck XDB 8,843Nuclei 4,358Metasploit 3,489✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
Samba 3.5.0 < 4.4.14/4.5.10/4.6.4 - 'is_known_pipename()' Arbitrary Module Load (Metasploit)
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft MsMpEng - Multiple Crashes While Scanning Malformed Files
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft MsMpEng - Multiple Crashes While Scanning Malformed Files
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft MsMpEng - Multiple Crashes While Scanning Malformed Files
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
28RISK
open ↗Exploit-DB✓ VexDay Proof
Apple WebKit / Safari 10.0.3(12602.4.8) - 'Editor::Command::execute' Universal Cross-Site Scripting
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebKit - 'ContainerNode::parserInsertBefore' Universal Cross-Site Scripting
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox < 53 - 'ConvolvePixel' Memory Disclosure
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for other
28RISK
open ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox < 53 - 'gfxTextRun' Out-of-Bounds Read
An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitabl
28RISK
open ↗Exploit-DB✓ VexDay Proof
WebKit - 'enqueuePageshowEvent' / 'enqueuePopstateEvent' Universal Cross-Site Scripting
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RISK
open ↗Exploit-DB✓ VexDay Proof
WebKit - 'FrameLoader::clear' Stealing Variables via Page Navigation
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple WebKit / Safari 10.0.3(12602.4.8) - 'WebCore::FrameView::scheduleRelayout' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RISK
open ↗Exploit-DB✓ VexDay Proof
Samba 3.5.0 - Remote Code Execution
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS Kernel - Use-After-Free Due to Bad Locking in Unix Domain Socket File Descriptor Externalization
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS - 'TIKeyboardLayout initWithCoder:' NSKeyedArchiver Heap Corruption Due to Rounding Error
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS - Lack of Bounds Checking in HIServices Custom CFObject Serialization Local Privilege Escalation
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Accessibili
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS - 'CAMediaTimingFunctionBuiltin' NSKeyedArchiver Memory Corruption Due to Lack of Bounds Checking
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "CoreAnimati
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS - Memory Corruption Due to Bad Bounds Checking in NSCharacterSet Coding for NSKeyedUnarchiver
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS - NSUnarchiver Heap Corruption Due to Lack of Bounds Checking in [NSBuiltinCharacterSet initWithCoder:]
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
28RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS - 'stackshot' Raw Frame Pointers
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" com
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS - '32-bit syscall exit' Kernel Register Leak
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" com
23RISK
open ↗Exploit-DB✓ VexDay Proof
VMware Workstation for Linux 12.5.2 build-4638234 - ALSA Configuration Host Local Privilege Escalation
VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration fil
38RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 4.11 - eBPF Verifier Log Leaks Lower Half of map Pointer
The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allow_ptr_leaks value
23RISK
open ↗Exploit-DB✓ VexDay Proof
PlaySMS 1.4 - 'import.php' Remote Code Execution
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Margin Handling Heap Corruption
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser
28RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin PHPMailer 4.6 - Host Header Command Injection (Metasploit)
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash - AVC Deblocking Out-of-Bounds Read
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Advanced V
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - COM Aggregate Marshaler/IRemUnknown2 Type Confusion Privilege Escalation
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RISK
open ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Out-of-Bounds Read in Getting TextField Width
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability when parsing a sh
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Running Object Table Register ROTFLAGS_ALLOWANYCLIENT Privilege Escalation
Windows COM in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple iOS < 10.3.2 - Notifications API Denial of Service
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. The issue involves the "Notifications"
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.