Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,233GitHub PoC 14,119VulnCheck XDB 8,617Nuclei 4,257Metasploit 3,474✓ verified onlyrecentpopularrisk
14,096 exploits
GitHub PoC★ 13
Mitigate CVE-2018-6389 WordPress load-scripts / load-styles attacks
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISK
open ↗GitHub PoC★ 56
This tool takes advantage of CVE-2018-11776 and Shodan to perform mass exploitation of verified and vulnerable Apache Struts servers.
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open ↗GitHub PoC★ 3
tuxotron/cve-2018-11776-docker
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open ↗GitHub PoC★ 16
A simple exploit for Apache Struts RCE S2-057 (CVE-2018-11776)
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open ↗GitHub PoC★ 2
Tiny script to enumerate users using CVE-2017-9554 (forget_passwd.cgi)
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allo
60RISK
open ↗GitHub PoC★ 21
Proof of Concept for CVE-2018-11776
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open ↗GitHub PoC★ 3
moayadalmalat/CVE-2017-12636
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RISK
open ↗GitHub PoC★ 12
Vulnerable docker container for CVE-2018-11776
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open ↗GitHub PoC★ 303
An exploit for Apache Struts CVE-2018-11776
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open ↗GitHub PoC★ 4
Environment for CVE-2018-11776 / S2-057 (Apache Struts 2)
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open ↗GitHub PoC★ 123
Working Python test and PoC for CVE-2018-11776, includes Docker lab
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open ↗GitHub PoC★ 10
CVE-2018-11776(S2-057) EXPLOIT CODE
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open ↗GitHub PoC★ 21
Simple poc of CVE-2018-8414 Windows Package Setting RCE Vulnerability
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows
93RISK
open ↗GitHub PoC★ 15
Creating a vulnerable environment and the PoC
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open ↗GitHub PoC★ 534
Exploit written in Python for CVE-2018-15473 with threading and export formats
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open ↗GitHub PoC★ 111
PoC for Privilege Escalation in Windows 10 Diagnostics Hub Standard Collector Service
An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary
23RISK
open ↗GitHub PoC
a exp for cve-2018-9948/9958 , current shellcode called win-calc
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RISK
open ↗GitHub PoC★ 3
dangokyo/CVE-2015-5119
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RISK
open ↗GitHub PoC★ 3
CVE-2018-15473 - Opensshenum is an user enumerator exploiting an OpenSsh bug
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open ↗GitHub PoC★ 159
OpenSSH 2.3 up to 7.4 Mass Username Enumeration (CVE-2018-15473).
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open ↗GitHub PoC★ 1
CVE-2018-8120 Windows LPE exploit
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open ↗GitHub PoC★ 258
PoC for CVE-2018-15133 (Laravel unserialize vulnerability)
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open ↗GitHub PoC
kaisaryousuf/CVE-2018-8208
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
23RISK
open ↗GitHub PoC★ 118
Implements the POP/MOV SS (CVE-2018-8897) vulnerability by leveraging SYSCALL to perform a local privilege escalation (LPE).
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RISK
open ↗GitHub PoC★ 178
Exploit for CVE-2018-4233, a WebKit JIT optimization bug used during Pwn2Own 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
68RISK
open ↗GitHub PoC★ 6
Foxit Reader version 9.0.1.1049 Use After Free with ASLR and DEP bypass on heap
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RISK
open ↗GitHub PoC★ 96
A Burp extension to detect and exploit versions of Telerik Web UI vulnerable to CVE-2017-9248.
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RISK
open ↗GitHub PoC★ 61
CVE-2007-2447 - Samba usermap script
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open ↗GitHub PoC★ 2
Crestron AirMedia AM-100 Traversal and Hashdump Metasploit Modules
Directory traversal vulnerability in cgi-bin/login.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13
28RISK
open ↗GitHub PoC★ 20
on Mac 10.12.2
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.