Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
14,096 exploits
GitHub PoC
OpenSSH < 7.7 User Enumeration CVE-2018-15473 Exploit
CVE-2018-15473MEDIUM08 Oct 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC8
proof-of-concept (PoC) for linux dists based on Debian, CentOS and RedHat - exploit 1
CVE-2018-14634HIGHunder attack08 Oct 2018
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with a
76RISK
open
GitHub PoC2
Metasploit module for CVE-2016-1555
CVE-2016-1555CRITICALunder attack06 Oct 2018
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear
100RISK
open
GitHub PoC2
webr0ck/poc-cve-2018-1273
CVE-2018-1273CRITICALunder attackransomware05 Oct 2018
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RISK
open
GitHub PoC10
An exploitation tool to extract passwords using CVE-2015-5995.
CVE-2015-599504 Oct 2018
Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 and Tenda N3 Wireless N150 devices allow remote attacke
28RISK
open
GitHub PoC116
Multi-threaded, IPv6 aware, wordlists/single-user username enumeration via CVE-2018-15473
CVE-2018-15473MEDIUM03 Oct 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC26
lexfo/cve-2017-11176
CVE-2017-1117602 Oct 2018
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RISK
open
GitHub PoC4
MASS Exploiter
CVE-2018-7600CRITICALunder attackransomware02 Oct 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC
likekabin/CVE-2018-17182
CVE-2018-1718201 Oct 2018
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RISK
open
GitHub PoC1
likekabin/vmacache_CVE-2018-17182
CVE-2018-1718201 Oct 2018
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RISK
open
GitHub PoC130
Linux 内核VMA-UAF 提权漏洞(CVE-2018-17182),0day
CVE-2018-1718229 Sep 2018
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RISK
open
GitHub PoC
Make CVE-2007-4607 exploitable again!
CVE-2007-460727 Sep 2018
Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used
50RISK
open
GitHub PoC20
Gain root privilege by exploiting CVE-2014-3153 vulnerability
CVE-2014-3153HIGHunder attack27 Sep 2018
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISK
open
GitHub PoC
bkhablenko/CVE-2017-8046
CVE-2017-804626 Sep 2018
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISK
open
GitHub PoC1
cscli/CVE-2017-5223
CVE-2017-522326 Sep 2018
An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML docume
23RISK
open
GitHub PoC112
DVR-Exploiter a Bash Script Program Exploit The DVR's Based on CVE-2018-9995
CVE-2018-999523 Sep 2018
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
GitHub PoC
Exploit SLmail Buffer Overflow CVE-2003-0264
CVE-2003-026416 Sep 2018
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RISK
open
GitHub PoC513
Java反序列化漏洞利用工具V1.0 Java反序列化相关漏洞的检查工具,采用JDK 1.8+NetBeans8.2开发,软件运行必须安装JDK 1.8或者以上版本。 支持:weblogic xml反序列化漏洞 CVE-2017-10271/CNVD-C-2019-48814/CVE-2019-2725检查。
CVE-2019-2725HIGHunder attackransomware13 Sep 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC513
Java反序列化漏洞利用工具V1.0 Java反序列化相关漏洞的检查工具,采用JDK 1.8+NetBeans8.2开发,软件运行必须安装JDK 1.8或者以上版本。 支持:weblogic xml反序列化漏洞 CVE-2017-10271/CNVD-C-2019-48814/CVE-2019-2725检查。
CVE-2017-10271HIGHunder attackransomware13 Sep 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC1
porting CVE-2016-7255 to x86 for educational purposes.
CVE-2016-7255HIGHunder attack13 Sep 2018
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RISK
open
GitHub PoC1
veloCloud VMWare - Vulnerability
CVE-2018-6961HIGHunder attack12 Sep 2018
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web U
100RISK
open
GitHub PoC7
C# implementation of BasuCert/WinboxPoC [Winbox Critical Vulnerability (CVE-2018-14847)]
CVE-2018-14847CRITICALunder attack11 Sep 2018
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open
GitHub PoC2
Simple poc of CVE-2018-8353 Microsoft Scripting Engine Use After Free
CVE-2018-835310 Sep 2018
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
35RISK
open
GitHub PoC
likekabin/CVE-2018-8174-msf
CVE-2018-8174HIGHunder attackransomware06 Sep 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISK
open
GitHub PoC
jezzus/CVE-2018-11776-Python-PoC
CVE-2018-11776HIGHunder attack06 Sep 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
GitHub PoC
jezzus/CVE-2018-4121
CVE-2018-412106 Sep 2018
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud b
28RISK
open
GitHub PoC2
Apache Struts version analyzer (Ansible) based on CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware04 Sep 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC5
A remote code execution exploit for WebLogic based on CVE-2018-2628
CVE-2018-2628CRITICALunder attack04 Sep 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
GitHub PoC95
Primefaces <= 5.2.21, 5.3.8 or 6.0 - Remote Code Execution Exploit
CVE-2017-1000486CRITICALunder attack03 Sep 2018
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISK
open
GitHub PoC25
CVE-2017-10366: Oracle PeopleSoft 8.54, 8.55, 8.56 Java deserialization exploit
CVE-2017-1036603 Sep 2018
Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Perform
35RISK
open
previouspage 439 / 470next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.