Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
14,080 exploits
GitHub PoC146
CVE-2018-13382
CVE-2018-13382CRITICALunder attackransomware11 Aug 2019
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RISK
open
GitHub PoC
ThanHuuTuan/CVE-2017-7269
CVE-2017-7269CRITICALunder attack09 Aug 2019
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC90
Apache Solr DataImport Handler RCE
CVE-2019-0193HIGHunder attack09 Aug 2019
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RISK
open
GitHub PoC4
linux 提权
CVE-2019-13272HIGHunder attack07 Aug 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
GitHub PoC
Lee-SungYoung/cve-2019-5736-study
CVE-2019-573605 Aug 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
GitHub PoC
Aquí está mi nuevo y primer exploit web, este exploit ataca a la vulnerabilidad de HeartBleed (CVE-2014-0160) espero que os guste.
CVE-2014-0160HIGHunder attack05 Aug 2019
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC1
CVE-2018-16509 Docker Playground - Ghostscript command execution
CVE-2018-1650904 Aug 2019
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RISK
open
GitHub PoC1
提权漏洞
CVE-2019-13272HIGHunder attack04 Aug 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
GitHub PoC3
this is not stable
CVE-2013-202803 Aug 2019
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cau
60RISK
open
GitHub PoC1
SSH account enumeration verification script(CVE-2018-15473)
CVE-2018-15473MEDIUM02 Aug 2019
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC5
The exploit for CVE-2019-13272
CVE-2019-13272HIGHunder attack31 Jul 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
GitHub PoC332
Linux 4.10 < 5.1.17 PTRACE_TRACEME local root
CVE-2019-13272HIGHunder attack31 Jul 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
GitHub PoC3
CVE-2019-1132
CVE-2019-1132HIGHunder attack31 Jul 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RISK
open
GitHub PoC1
quandqn/cve-2018-14667
CVE-2018-14667CRITICALunder attack29 Jul 2019
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RISK
open
GitHub PoC4
infiniteLoopers/CVE-2019-2107
CVE-2019-210727 Jul 2019
In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. Th
23RISK
open
GitHub PoC60
EoP POC for CVE-2019-1132
CVE-2019-1132HIGHunder attack26 Jul 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RISK
open
GitHub PoC39
Some debug notes and exploit(not blind)
CVE-2019-7238CRITICALunder attack26 Jul 2019
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RISK
open
GitHub PoC1
收集网上CVE-2018-0708的poc和exp(目前没有找到exp)
CVE-2019-0708CRITICALunder attackransomware25 Jul 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC14
POC for CVE-2019-14339 Canon PRINT 2.5.5
CVE-2019-1433925 Jul 2019
The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly res
23RISK
open
GitHub PoC10
CVE-2019–11581 PoC
CVE-2019-11581CRITICALunder attack25 Jul 2019
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators an
100RISK
open
GitHub PoC1
收集网上CVE-2018-0708的poc和exp(目前没有找到exp)
CVE-2018-070825 Jul 2019
Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allo
28RISK
open
GitHub PoC3
Exim Honey Pot for CVE-2019-10149 exploit attempts.
CVE-2019-10149CRITICALunder attack25 Jul 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
GitHub PoC1
perf_swevent_init
CVE-2013-2094HIGHunder attack23 Jul 2019
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RISK
open
GitHub PoC1
CVE-2017-16995 eBPF PoC for Ubuntu 16.04
CVE-2017-1699523 Jul 2019
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
GitHub PoC6
cve-2016-6187
CVE-2016-618723 Jul 2019
The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buff
23RISK
open
GitHub PoC1
My old sysret / ptrace PoC
CVE-2014-469923 Jul 2019
The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved
23RISK
open
GitHub PoC2
cve-2014-4014
CVE-2014-401423 Jul 2019
The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inappli
23RISK
open
GitHub PoC293
Public work for CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware23 Jul 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC
Y0n0Y/cve-2018-8120-exp
CVE-2018-8120HIGHunder attackransomware20 Jul 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
GitHub PoC3
Scanner PoC for CVE-2019-0708 RDP RCE vuln
CVE-2019-0708CRITICALunder attackransomware18 Jul 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
previouspage 422 / 470next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.