Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DBVexDay Proof
SAP SAPCAR - Multiple Vulnerabilities
CVE-2016-5845doslinux10 Aug 2016
SAP SAPCAR does not check the return value of file operations when extracting files, which allows remote attackers to ca
23RISK
open
Exploit-DBVexDay Proof
SAP SAPCAR - Multiple Vulnerabilities
CVE-2016-5847doslinux10 Aug 2016
SAP SAPCAR allows local users to change the permissions of arbitrary files and consequently gain privileges via a hard l
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 7 (x86/x64) - Group Policy Privilege Escalation (MS16-072)
CVE-2016-3223localwindows08 Aug 2016
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold an
28RISK
open
Exploit-DBVexDay Proof
VMware Host Guest Client Redirector - DLL Side Loading (Metasploit)
CVE-2016-5330localwindows06 Aug 2016
Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 t
43RISK
open
Exploit-DBVexDay Proof
Wireshark 1.12.0 < 1.12.12 / 2.0.0 < 2.0.4 - PacketBB Dissector Denial of Service
CVE-2016-6505dosmultiple03 Aug 2016
epan/dissectors/packet-packetbb.c in the PacketBB dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allo
23RISK
open
Exploit-DBVexDay Proof
Wireshark 2.0.0 < 2.0.4 - MMSE / WAP / WBXML / WSP Dissectors Denial of Service
CVE-2016-6512dosmultiple03 Aug 2016
epan/dissectors/packet-wap.c in Wireshark 2.x before 2.0.5 omits an overflow check in the tvb_get_guintvar function, whi
23RISK
open
Exploit-DBVexDay Proof
Wireshark 2.0.0 < 2.0.4 - CORBA IDL Dissectors Denial of Service
CVE-2016-6503doswindows_x86-6403 Aug 2016
The CORBA IDL dissectors in Wireshark 2.x before 2.0.5 on 64-bit Windows platforms do not properly interact with Visual
23RISK
open
Exploit-DBVexDay Proof
Wireshark 1.12.0 < 1.12.12 - NDS Dissector Denial of Service
CVE-2016-6504dosmultiple03 Aug 2016
epan/dissectors/packet-ncp2222.inc in the NDS dissector in Wireshark 1.12.x before 1.12.13 does not properly maintain a
23RISK
open
Exploit-DBVexDay Proof
PHP 5.5.37/5.6.23/7.0.8 - 'bzread()' Out-of-Bounds Write
CVE-2016-5399dosphp25 Jul 2016
The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attac
23RISK
open
Exploit-DBVexDay Proof
Micro Focus Filr 2 2.0.0.421/1.2 1.2.0.846 - Multiple Vulnerabilities
CVE-2016-1609webappsjava25 Jul 2016
Multiple cross-site scripting (XSS) vulnerabilities in Novell Filr before 1.2 Security Update 3 and 2.0 before Security
23RISK
open
Exploit-DBVexDay Proof
Micro Focus Filr 2 2.0.0.421/1.2 1.2.0.846 - Multiple Vulnerabilities
CVE-2016-1611webappsjava25 Jul 2016
Novell Filr 1.2 before Hot Patch 6 and 2.0 before Hot Patch 2 uses world-writable permissions for /etc/profile.d/vainit.
23RISK
open
Exploit-DBVexDay Proof
PHP gettext 1.0.12 - 'gettext.php' Code Execution
CVE-2016-6175webappsphp25 Jul 2016
Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via
28RISK
open
Exploit-DBVexDay Proof
Micro Focus Filr 2 2.0.0.421/1.2 1.2.0.846 - Multiple Vulnerabilities
CVE-2016-1610webappsjava25 Jul 2016
Directory traversal vulnerability in the email-template feature in Novell Filr before 1.2 Security Update 3 and 2.0 befo
28RISK
open
Exploit-DBVexDay Proof
Micro Focus Filr 2 2.0.0.421/1.2 1.2.0.846 - Multiple Vulnerabilities
CVE-2016-1607webappsjava25 Jul 2016
Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Novell Filr before 2.0 Sec
23RISK
open
Exploit-DBVexDay Proof
Micro Focus Filr 2 2.0.0.421/1.2 1.2.0.846 - Multiple Vulnerabilities
CVE-2016-1608webappsjava25 Jul 2016
vaconfig/time in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote authenticated u
28RISK
open
Exploit-DBVexDay Proof
NetBSD - 'mail.local(8)' Local Privilege Escalation
CVE-2016-6253localbsd21 Jul 2016
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or
38RISK
open
Exploit-DBVexDay Proof
Django CMS 3.3.0 - Editor Snippet Persistent Cross-Site Scripting
CVE-2016-6186webappspython20 Jul 2016
Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/j
23RISK
open
Exploit-DBVexDay Proof
Adobe Flash Player 22.0.0.192 - DefineSprite Memory Corruption
CVE-2016-4175dosmultiple13 Jul 2016
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 7 < 10 / 2008 < 2012 (x86/x64) - Secondary Logon Handle Privilege Escalation (MS16-032) (Metasploit)
CVE-2016-0099HIGHunder attackransomwarelocalwindows13 Jul 2016
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC 15.016.20045 - Invalid Font '.ttf' Memory Corruption (5)
CVE-2016-4207dosmultiple13 Jul 2016
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC 15.016.20045 - Invalid Font '.ttf' Memory Corruption (7)
CVE-2016-4201dosmultiple13 Jul 2016
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RISK
open
Exploit-DBVexDay Proof
Adobe Flash Player 22.0.0.192 - SceneAndFrameData Memory Corruption
CVE-2016-4177dosmultiple13 Jul 2016
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC 15.016.20045 - Invalid Font '.ttf' Memory Corruption (3)
CVE-2016-4203dosmultiple13 Jul 2016
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC 15.016.20045 - Invalid Font '.ttf' Memory Corruption (1)
CVE-2016-4205dosmultiple13 Jul 2016
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC 15.016.20045 - Invalid Font '.ttf' Memory Corruption (6)
CVE-2016-4206dosmultiple13 Jul 2016
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RISK
open
Exploit-DBVexDay Proof
Adobe Flash Player 22.0.0.192 - TAG Memory Corruption
CVE-2016-4176dosmultiple13 Jul 2016
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632
28RISK
open
Exploit-DBVexDay Proof
Adobe Flash Player 22.0.0.192 - DefineBitsJPEG2 Memory Corruption
CVE-2016-4179dosmultiple13 Jul 2016
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC 15.016.20045 - Invalid Font '.ttf' Memory Corruption (2)
CVE-2016-4204dosmultiple13 Jul 2016
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC 15.016.20045 - Invalid Font '.ttf' Memory Corruption (4)
CVE-2016-4208dosmultiple13 Jul 2016
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RISK
open
Exploit-DBVexDay Proof
Adobe Flash - ATF Processing Overflow
CVE-2016-4135dosmultiple11 Jul 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.