Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,043cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
Aruba AirWave 8.2.3 - XML External Entity Injection / Cross-Site Scripting
CVE-2016-8526webappsxml01 Mar 2017
Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a
23RISK
open
Exploit-DBVexDay Proof
Aruba AirWave 8.2.3 - XML External Entity Injection / Cross-Site Scripting
CVE-2016-8527webappsxml01 Mar 2017
Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). Th
43RISK
open
Exploit-DBVexDay Proof
Sophos Web Appliance 4.3.1.1 - Session Fixation
CVE-2017-6412webappsphp28 Feb 2017
In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310.
23RISK
open
Exploit-DBVexDay Proof
Netgear DGN2200v1/v2/v3/v4 - 'dnslookup.cgi' Remote Command Execution
CVE-2017-6334HIGHunder attackwebappshardware25 Feb 2017
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute ar
100RISK
open
Exploit-DBVexDay Proof
Apple WebKit 10.0.2 - 'Frame::setDocument' Universal Cross-Site Scripting
CVE-2017-2365webappsmultiple24 Feb 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISK
open
Exploit-DBVexDay Proof
Apple WebKit 10.0.2 - Cross-Origin or Sandboxed IFRAME Pop-up Blocker Bypass
CVE-2017-2371webappsmultiple24 Feb 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "WebKit" compon
23RISK
open
Exploit-DBVexDay Proof
Apple WebKit 10.0.2 - 'FrameLoader::clear' Universal Cross-Site Scripting
CVE-2017-2363webappsmacos24 Feb 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISK
open
Exploit-DBVexDay Proof
Microsoft Edge / Internet Explorer - 'HandleColumnBreakOnColumnSpanningElement' Type Confusion
CVE-2017-0037HIGHunder attackdoswindows24 Feb 2017
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilde
93RISK
open
Exploit-DBVexDay Proof
Apple macOS HelpViewer 10.12.1 - XSS Leads to Arbitrary File Execution / Arbitrary File Read
CVE-2017-2361remotemacos23 Feb 2017
An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Help Viewer
28RISK
open
Exploit-DBVexDay Proof
Adobe Flash - Use-After-Free in Applying Bitmap Filter
CVE-2017-2985dosmultiple21 Feb 2017
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability in the ActionScript
28RISK
open
Exploit-DBVexDay Proof
Adobe Flash - MP4 AMF Parsing Overflow
CVE-2017-2992dosmultiple21 Feb 2017
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability when parsing an MP4 h
35RISK
open
Exploit-DBVexDay Proof
Adobe Flash - SWF Stack Corruption
CVE-2017-2988dosmultiple21 Feb 2017
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable memory corruption vulnerability when performing g
28RISK
open
Exploit-DBVexDay Proof
Adobe Flash - YUVPlane Decoding Heap Overflow
CVE-2017-2986dosmultiple21 Feb 2017
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability in the Flash Video (F
35RISK
open
Exploit-DBVexDay Proof
Artifex MuPDF mujstest 1.10a - Null Pointer Dereference
CVE-2017-6060doslinux17 Feb 2017
Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, Inc. MuPDF 1.10a allows remote attackers t
23RISK
open
Exploit-DBVexDay Proof
dotCMS 3.6.1 - Blind Boolean SQL Injection
CVE-2017-5344webappsphp16 Feb 2017
An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessib
23RISK
open
Exploit-DBVexDay Proof
Geutebruck 5.02024 G-Cam/EFD-2250 - 'testaction.cgi' Remote Command Execution (Metasploit)
CVE-2017-5174webappshardware15 Feb 2017
An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authenticatio
35RISK
open
Exploit-DBVexDay Proof
Cisco ASA - WebVPN CIFS Handling Buffer Overflow
CVE-2017-3807doshardware15 Feb 2017
A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software,
28RISK
open
Exploit-DBVexDay Proof
Geutebruck 5.02024 G-Cam/EFD-2250 - 'testaction.cgi' Remote Command Execution (Metasploit)
CVE-2017-5173webappshardware15 Feb 2017
An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD
28RISK
open
Exploit-DBVexDay Proof
NVIDIA Driver 375.70 - Buffer Overflow in Command Buffer Submission
CVE-2017-0313doswindows15 Feb 2017
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) implem
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'gdi32.dll' EMR_SETDIBITSTODEVICE Heap Out-of-Bounds Reads / Memory Disclosure
CVE-2017-0038doswindows15 Feb 2017
gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
45RISK
open
Exploit-DBVexDay Proof
GOM Player 2.3.10.5266 - '.fpx' Denial of Service
CVE-2017-5881doswindows15 Feb 2017
GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspeci
23RISK
open
Exploit-DBVexDay Proof
NVIDIA Driver 375.70 - DxgkDdiEscape 0x100008b Out-of-Bounds Read/Write
CVE-2017-0312doswindows15 Feb 2017
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handle
23RISK
open
Exploit-DBVexDay Proof
Microsoft Edge - TypedArray.sort Use-After-Free (MS16-145)
CVE-2016-7288doswindows14 Feb 2017
The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (m
45RISK
open
Exploit-DBVexDay Proof
ntfs-3g - Unsanitized modprobe Environment Privilege Escalation
CVE-2017-0358HIGHlocallinux14 Feb 2017
ntfs-3g: Modprobe influence vulnerability via environment variables
56RISK
open
Exploit-DBVexDay Proof
Google Android - android.util.MemoryIntArray Ashmem Race Conditions
CVE-2017-0412dosandroid14 Feb 2017
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
23RISK
open
Exploit-DBVexDay Proof
Google Android - Inter-process munmap in android.util.MemoryIntArray
CVE-2017-0411dosandroid14 Feb 2017
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
23RISK
open
Exploit-DBVexDay Proof
HP Smart Storage Administrator 2.30.6.0 - Remote Command Injection (Metasploit)
CVE-2016-8523remotemultiple10 Feb 2017
A Remote Arbitrary Code Execution vulnerability in HPE Smart Storage Administrator version before v2.60.18.0 was found.
28RISK
open
Exploit-DBVexDay Proof
Apple WebKit - 'HTMLKeygenElement' Type Confusion
CVE-2017-2369dosmultiple01 Feb 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISK
open
Exploit-DBVexDay Proof
Apple WebKit - Type Confusion in RenderBox with Accessibility Enabled
CVE-2017-2373dosmultiple01 Feb 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISK
open
Exploit-DBVexDay Proof
Apple WebKit - 'HTMLFormElement::reset()' Use-After Free
CVE-2017-2362dososx01 Feb 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.