Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,910GitHub PoC 14,997VulnCheck XDB 8,843Nuclei 4,358Metasploit 3,489✓ verified onlyrecentpopularrisk
24,695 exploits
Exploit-DB✓ VexDay Proof
Kaseya Virtual System Administrator (VSA) - Multiple Vulnerabilities (2)
Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before
28RISK
open ↗Exploit-DB✓ VexDay Proof
ManageEngine EventLog Analyzer - Remote Code Execution (Metasploit)
ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions
60RISK
open ↗Exploit-DB✓ VexDay Proof
Kaseya Virtual System Administrator (VSA) - Multiple Vulnerabilities (2)
Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before
60RISK
open ↗Exploit-DB✓ VexDay Proof
Watchguard XCS - Remote Command Execution (Metasploit)
Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell
50RISK
open ↗Exploit-DB✓ VexDay Proof
Watchguard XCS - Remote Command Execution (Metasploit)
SQL injection vulnerability in Watchguard XCS 9.2 and 10.0 before build 150522 allows remote attackers to execute arbitr
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'NtGdiBitBlt' Buffer Overflow (MS15-097)
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'DeferWindowPos' Use-After-Free (MS15-073)
win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Wi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Regex Engine (TRE) - Integer Signedness / Overflow
The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent attackers to execute
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - Bitmap Handling Use-After-Free (MS15-061) (1)
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco AnyConnect Secure Mobility Client 3.1.08009 - Local Privilege Escalation
Untrusted search path vulnerability in the CMainThread::launchDownloader function in vpndownloader.exe in Cisco AnyConne
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - Bitmap Handling Use-After-Free (MS15-061) (2)
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'UserCommitDesktopMemory' Use-After-Free (MS15-073)
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - WindowStation Use-After-Free (MS15-061)
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - Brush Object Use-After-Free (MS15-061)
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'HmgAllocateObjectAttr' Use-After-Free (MS15-061)
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'SURFOBJ' Null Pointer Dereference (MS15-061)
Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows S
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - Pool Buffer Overflow Drawing Caption Bar (MS15-061)
Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows S
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - Null Pointer Dereference with Window Station and Clipboard (MS15-061)
The kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple qlmanage - SceneKit::daeElement::setElementName Heap Overflow
SceneKit in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (me
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'win32k!vSolidFillRect' Buffer Overflow (MS15-061)
Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows S
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - Use-After-Free with Printer Device Contexts (MS15-097)
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Regex Engine (TRE) - Stack Buffer Overflow (PoC)
The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent attackers to execute
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'bGetRealizedBrush' Use-After-Free (MS15-097)
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - Use-After-Free with Cursor Object (MS15-097)
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'NtGdiStretchBlt' Pool Buffer Overflow (MS15-097)
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'FlashWindowEx' Memory Corruption (MS15-097)
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
23RISK
open ↗Exploit-DB✓ VexDay Proof
Konica Minolta FTP Utility 1.00 - (Authenticated) CWD Command Overflow (SEH) (Metasploit)
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD comma
50RISK
open ↗Exploit-DB✓ VexDay Proof
ManageEngine OpManager - Remote Code Execution (Metasploit)
ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser a
50RISK
open ↗Exploit-DB✓ VexDay Proof
Google Android - libstagefright Integer Overflow Remote Code Execution
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Font Driver Buffer Overflow (MS15-078) (Metasploit)
Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.