Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'ATMFD.dll' OTF Font Processing Stack Corruption (MS16-026)
CVE-2016-0120doswindows14 Mar 2016
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'ATMFD.dll' OTF Font Processing Pool-Based Buffer Overflow (MS16-026)
CVE-2016-0121doswindows14 Mar 2016
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RISK
open
Exploit-DBVexDay Proof
TeamPass 2.1.24 - Multiple Vulnerabilities
CVE-2015-7563webappsphp14 Mar 2016
Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the aut
23RISK
open
Exploit-DBVexDay Proof
TeamPass 2.1.24 - Multiple Vulnerabilities
CVE-2015-7562webappsphp14 Mar 2016
Multiple cross-site scripting (XSS) vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to inject arbi
23RISK
open
Exploit-DBVexDay Proof
Exim < 4.86.2 - Local Privilege Escalation
CVE-2016-1531locallinux10 Mar 2016
Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.
38RISK
open
Exploit-DBVexDay Proof
Exim 4.84-3 - Local Privilege Escalation
CVE-2016-1531locallinux09 Mar 2016
Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.
38RISK
open
Exploit-DBVexDay Proof
Linux Kernel 3.10/3.18 /4.4 - Netfilter IPT_SO_SET_REPLACE Memory Corruption
CVE-2016-3134doslinux09 Mar 2016
The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local us
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 3.10/3.18 /4.4 - Netfilter IPT_SO_SET_REPLACE Memory Corruption
CVE-2016-3135doslinux09 Mar 2016
Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel through 4.5.2 on 32
23RISK
open
Exploit-DBVexDay Proof
Adobe Digital Editions 4.5.0 - '.pdf' Critical Memory Corruption
CVE-2016-0954doswindows09 Mar 2016
Adobe Digital Editions before 4.5.1 allows attackers to execute arbitrary code or cause a denial of service (memory corr
28RISK
open
Exploit-DBVexDay Proof
ATutor LMS - '/install_modules.php' Cross-Site Request Forgery / Remote Code Execution
CVE-2016-2539webappsphp07 Mar 2016
Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
Avast! - Authenticode Parsing Memory Corruption
CVE-2016-3986doswindows07 Mar 2016
Avast allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a
23RISK
open
Exploit-DBVexDay Proof
Netgear NMS300 ProSafe Network Management System - Arbitrary File Upload (Metasploit)
CVE-2016-1525remotewindows01 Mar 2016
Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allow
60RISK
open
Exploit-DBVexDay Proof
ATutor 2.2.1 - SQL Injection / Remote Code Execution (Metasploit)
CVE-2016-2555remotephp01 Mar 2016
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RISK
open
Exploit-DBVexDay Proof
libxml2 - xmlParserPrintFileContextInternal Heap Buffer Overread
CVE-2016-1838doslinux24 Feb 2016
The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 1
23RISK
open
Exploit-DBVexDay Proof
libxml2 - xmlDictAddString Heap Buffer Overread
CVE-2016-1839doslinux24 Feb 2016
The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS befo
23RISK
open
Exploit-DBVexDay Proof
Dell OpenManage Server Administrator 8.2 - (Authenticated) Directory Traversal
CVE-2016-4004webappswindows23 Feb 2016
Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated adminis
23RISK
open
Exploit-DBVexDay Proof
Adobe Flash - SimpleButton Creation Type Confusion
CVE-2015-8644dosmultiple19 Feb 2016
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on
28RISK
open
Exploit-DBVexDay Proof
Adobe Flash - BitmapData.drawWithQuality Heap Overflow
CVE-2016-0964dosmultiple17 Feb 2016
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on
28RISK
open
Exploit-DBVexDay Proof
Adobe Flash - textfield Constructor Type Confusion
CVE-2016-0985dosmultiple17 Feb 2016
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on
28RISK
open
Exploit-DBVexDay Proof
Adobe Flash - LoadVars.decode Use-After-Free
CVE-2016-0974dosmultiple17 Feb 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and
35RISK
open
Exploit-DBVexDay Proof
Adobe Flash - Out-of-Bounds Image Read
CVE-2016-0965dosmultiple17 Feb 2016
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on
28RISK
open
Exploit-DBVexDay Proof
Adobe Flash - H264 File Stack Corruption
CVE-2016-0967dosmultiple17 Feb 2016
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on
28RISK
open
Exploit-DBVexDay Proof
Adobe Flash - Sound.loadPCMFromByteArray Dangling Pointer
CVE-2016-0984HIGHunder attackdosmultiple17 Feb 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and
83RISK
open
Exploit-DBVexDay Proof
Adobe Flash - ATF Processing Heap Overflow
CVE-2016-0971dosmultiple17 Feb 2016
Heap-based buffer overflow in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS
35RISK
open
Exploit-DBVexDay Proof
glibc - 'getaddrinfo' Stack Buffer Overflow (PoC)
CVE-2015-7547doslinux16 Feb 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Kerberos Security Feature Bypass (MS16-014)
CVE-2016-0049localwindows15 Feb 2016
Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
28RISK
open
Exploit-DBVexDay Proof
Apache Sling Framework (Adobe AEM) 2.3.6 - Information Disclosure
CVE-2016-0956webappsmultiple10 Feb 2016
The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows r
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 7 SP1 (x86) - 'WebDAV' Local Privilege Escalation (MS16-016) (1)
CVE-2016-0051localwindows_x8610 Feb 2016
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RISK
open
Exploit-DBVexDay Proof
Adobe Photoshop CC / Bridge CC - '.png' Parsing Memory Corruption (1)
CVE-2016-0951doswindows09 Feb 2016
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to exec
28RISK
open
Exploit-DBVexDay Proof
Adobe Photoshop CC / Bridge CC - '.png' Parsing Memory Corruption (2)
CVE-2016-0952doswindows09 Feb 2016
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to exec
28RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.