Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
Microsoft Windows - Font Driver Buffer Overflow (MS15-078) (Metasploit)
CVE-2015-2426HIGHunder attacklocalwindows_x86-6417 Sep 2015
Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2
100RISK
open
Exploit-DBVexDay Proof
Google Android - libstagefright Integer Overflow Remote Code Execution
CVE-2015-3864remoteandroid17 Sep 2015
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RISK
open
Exploit-DBVexDay Proof
Microsoft Office 2007 - OLESSDirectyEntry.CreateTime Type Confusion
CVE-2015-2521doswindows16 Sep 2015
Microsoft Excel 2007 SP3, Excel 2010 SP2, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to exec
28RISK
open
Exploit-DBVexDay Proof
Microsoft Office 2007 - 'OGL.dll' ValidateBitmapInfo Bounds Check Failure (MS15-097)
CVE-2015-2510doswindows16 Sep 2015
Buffer overflow in the Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2, Office 2007 S
35RISK
open
Exploit-DBVexDay Proof
Microsoft Excel 2007/2010/2013 - BIFFRecord Use-After-Free
CVE-2015-2523doswindows16 Sep 2015
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel for Mac 2011 and 2016, Office Compati
35RISK
open
Exploit-DBVexDay Proof
Microsoft Office 2007 - BIFFRecord Length Use-After-Free
CVE-2015-2520doswindows16 Sep 2015
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel for Mac 2011 and 2016, Office Compatibility Pack SP3, and Excel Viewer a
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - NtUserGetClipboardAccessToken Token Leak (MS15-023)
CVE-2015-2527localwindows15 Sep 2015
The process-initialization implementation in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1,
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - CreateObjectTask SettingsSyncDiagnostics Privilege Escalation
CVE-2015-2524localwindows15 Sep 2015
Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not proper
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - CreateObjectTask TileUserBroker Privilege Escalation
CVE-2015-2528localwindows15 Sep 2015
Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not proper
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Media Center - MCL (MS15-100) (Metasploit)
CVE-2015-2509remotewindows15 Sep 2015
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remo
60RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Task Scheduler - 'DeleteExpiredTaskAfter' File Deletion Privilege Escalation
CVE-2015-2525localwindows15 Sep 2015
Task Scheduler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 10 (Build 10130) - User Mode Font Driver Thread Permissions Privilege Escalation
CVE-2015-2508localwindows15 Sep 2015
The Adobe Type Manager Library in Microsoft Windows 10 allows local users to gain privileges via a crafted application,
23RISK
open
Exploit-DBVexDay Proof
CMS Bolt - Arbitrary File Upload (Metasploit)
CVE-2015-7309remotephp15 Sep 2015
The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authent
50RISK
open
Exploit-DBVexDay Proof
ManageEngine EventLog Analyzer < 10.6 build 10060 - SQL Execution
CVE-2015-7387webappsmultiple14 Sep 2015
ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions
60RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX Install.Framework - SUID Root Runner Binary Privilege Escalation
CVE-2015-5754localosx10 Sep 2015
Race condition in runner in Install.framework in the Install Framework Legacy component in Apple OS X before 10.10.5 all
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX Install.Framework - Arbitrary mkdir / unlink and chown to Admin Group
CVE-2015-5784localosx10 Sep 2015
runner in Install.framework in the Install Framework Legacy component in Apple OS X before 10.10.5 does not properly dro
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX - Install.framework suid Helper Privilege Escalation
CVE-2015-3704localosx10 Sep 2015
runner in Install.framework in the Install Framework Legacy subsystem in Apple OS X before 10.10.4 does not properly dro
23RISK
open
Exploit-DBVexDay Proof
PHP 5.4/5.5/5.6 - SplObjectStorage 'Unserialize()' Use-After-Free
CVE-2015-6834dosphp09 Sep 2015
Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote
35RISK
open
Exploit-DBVexDay Proof
PHP Session Deserializer - Use-After-Free
CVE-2015-6835dosphp09 Sep 2015
The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_
35RISK
open
Exploit-DBVexDay Proof
PHP 5.4/5.5/5.6 - SplDoublyLinkedList 'Unserialize()' Use-After-Free
CVE-2015-6834dosphp09 Sep 2015
Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote
35RISK
open
Exploit-DBVexDay Proof
Google Android - 'Stagefright' Remote Code Execution
CVE-2015-1538remoteandroid09 Sep 2015
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RISK
open
Exploit-DBVexDay Proof
Endian Firewall - Password Change Command Injection (Metasploit)
CVE-2015-5082remotelinux07 Sep 2015
Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW
50RISK
open
Exploit-DBVexDay Proof
Tenda N3 Wireless N150 Router - Authentication Bypass
CVE-2015-5995webappshardware03 Sep 2015
Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 and Tenda N3 Wireless N150 devices allow remote attacke
28RISK
open
Exploit-DBVexDay Proof
Bedita 3.5.1 - Cross-Site Scripting
CVE-2015-6809webappsphp01 Sep 2015
Multiple cross-site scripting (XSS) vulnerabilities in BEdita before 3.6.0 allow remote attackers to inject arbitrary we
23RISK
open
Exploit-DBVexDay Proof
Boxoft WAV to MP3 Converter - 'convert' Local Buffer Overflow
CVE-2015-7243localwindows31 Aug 2015
Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly
50RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX Entitlements - 'Rootpipe' Local Privilege Escalation (Metasploit)
CVE-2015-3673localosx31 Aug 2015
Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allow
38RISK
open
Exploit-DBVexDay Proof
PCMan FTP Server 2.0.7 - 'RENAME' Remote Buffer Overflow
CVE-2013-4730remotewindows29 Aug 2015
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RISK
open
Exploit-DBVexDay Proof
QEMU - Programmable Interrupt Timer Controller Heap Overflow
CVE-2015-3214dosmultiple27 Aug 2015
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read
23RISK
open
Exploit-DBVexDay Proof
Oracle GlassFish Server 4.1 - Directory Traversal
CVE-2017-1000028webappsmultiple27 Aug 2015
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Trave
60RISK
open
Exploit-DBVexDay Proof
Microsoft Office 2007 - Malformed Document Stack Buffer Overflow
CVE-2015-0064doswindows25 Aug 2015
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Automation Services in SharePoint Server 2010, Web Applica
28RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.