Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,832GitHub PoC 14,991VulnCheck XDB 8,829Nuclei 4,357Metasploit 3,489✓ verified onlyrecentpopularrisk
24,695 exploits
Exploit-DB✓ VexDay Proof
Broadcom Wi-Fi SoC - Heap Overflow 'wlc_tdls_cal_mic_chk' Due to Large RSN IE in TDLS Setup Confirm Frame
A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary
28RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Webkit - Universal Cross-Site Scripting by Accessing a Named Property from an Unloaded Window
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Webkit - 'JSCallbackData' Universal Cross-Site Scripting
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issu
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS Kernel 10.12.2 (16C67) - 'AppleIntelCapriController::GetLinkConfig' Code Execution Due to Lack of Bounds Checking
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graph
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple WebKit 10.0.2 (12602.3.12.0.1) - 'disconnectSubframes' Universal Cross-Site Scripting
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple WebKit - 'RenderLayer' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS Kernel 10.12.3 (16D32) - SIOCSIFORDER Socket ioctl Memory Corruption Due to Bad Bounds Checking
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple WebKit - 'FormSubmission::create' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS Kernel 10.12.3 (16D32) - SIOCGIFORDER Socket ioctl Off-by-One Memory Corruption
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple WebKit - 'WebCore::toJS' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS Kernel 10.12.3 (16D32) - Bad Locking in necp_open Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS Kernel 10.12.3 (16D32) - 'bpf' Heap Overflow
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS Kernel 10.12.2 (16C67) - Memory Disclosure Due to Lack of Bounds Checking in AppleIntelCapriController::getDisplayPipeCapability
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graph
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS Kernel 10.12.3 (16D32) - Double-Free Due to Bad Locking in fsevents Device
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS Kernel 10.12.3 (16D32) - 'audit_pipe_open' Off-by-One Memory Corruption
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RISK
open ↗Exploit-DB✓ VexDay Proof
Broadcom Wi-Fi SoC - TDLS Teardown Request Remote Heap Overflow
A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary
28RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS Kernel 10.12.3 (16D32) - Use-After-Free Due to Double-Release in posix_spawn
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RISK
open ↗Exploit-DB✓ VexDay Proof
Broadcom Wi-Fi SoC - 'dhd_handle_swc_evt' Heap Overflow
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execu
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple WebKit 10.0.2 - HTMLInputElement Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple WebKit - 'ComposedTreeIterator::traverseNextInShadowTree' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple WebKit - 'table' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. watchOS
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple WebKit - Negative-Size memmove in HTMLFormElement
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple WebKit 10.0.2(12602.3.12.0.1) - 'Frame::setDocument (1)' Universal Cross-Site Scripting
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. The
23RISK
open ↗Exploit-DB✓ VexDay Proof
Bluecoat ASG 6.6/CAS 1.3 - Local Privilege Escalation (Metasploit)
Blue Coat Advanced Secure Gateway (ASG) 6.6 before 6.6.5.4 and Content Analysis System (CAS) 1.3 before 1.3.7.4 are susc
28RISK
open ↗Exploit-DB✓ VexDay Proof
Bluecoat ASG 6.6/CAS 1.3 - OS Command Injection (Metasploit)
Blue Coat Advanced Secure Gateway (ASG) 6.6 before 6.6.5.4 and Content Analysis System (CAS) 1.3 before 1.3.7.4 are susc
28RISK
open ↗Exploit-DB✓ VexDay Proof
Splunk Enterprise - Information Disclosure
Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS/IOS 10.12.2 (16C67) - 'mach_msg' Heap Overflow
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sync Breeze Enterprise 9.5.16 - 'Import Command' Local Buffer Overflow
A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9
50RISK
open ↗Exploit-DB✓ VexDay Proof
QNAP QTS < 4.2.4 - Domain Privilege Escalation
QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Safari - Builtin JavaScript Allows Function.caller to be Used in Strict Mode
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.