Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
14,096 exploits
GitHub PoC7
A demo exploit of CVE-2016-9079 on Ubuntu x64
CVE-2016-9079HIGHunder attack29 Jul 2018
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RISK
open
GitHub PoC
PercussiveElbow/CVE-2004-2271-MiniShare-1.4.1-Buffer-Overflow
CVE-2004-227125 Jul 2018
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET req
60RISK
open
GitHub PoC8
CVE-2013-6117
CVE-2013-611723 Jul 2018
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
50RISK
open
GitHub PoC2
This Python 3 script is for uploading shell (and other files) to Windows Server / Linux via Oracle 11g R2 (CVE-2010-3600).
CVE-2010-360020 Jul 2018
Unspecified vulnerability in the Client System Analyzer component in Oracle Database Server 11.1.0.7 and 11.2.0.1 and En
60RISK
open
GitHub PoC
likekabin/ShareDoc_cve-2015-5477
CVE-2015-547717 Jul 2018
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RISK
open
GitHub PoC
likekabin/CVE-2018-4121
CVE-2018-412117 Jul 2018
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud b
28RISK
open
GitHub PoC49
Collection of exploits/POC for PrestaShop cookie vulnerabilities (CVE-2018-13784)
CVE-2018-1378416 Jul 2018
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfi
28RISK
open
GitHub PoC
happynote3966/CVE-2018-7600
CVE-2018-7600CRITICALunder attackransomware12 Jul 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC
happynote3966/CVE-2018-7602
CVE-2018-7602CRITICALunder attackransomware12 Jul 2018
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RISK
open
GitHub PoC
Linux Null pointer dereference
CVE-2009-269212 Jul 2018
The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socke
43RISK
open
GitHub PoC1
dd
CVE-2018-8120HIGHunder attackransomware11 Jul 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
GitHub PoC1
happynote3966/CVE-2014-3704
CVE-2014-370411 Jul 2018
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISK
open
GitHub PoC5
XML external entity (XXE) vulnerability in /ssc/fm-ws/services in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10 (0day CVE-2018-12463)
CVE-2018-12463HIGH10 Jul 2018
MFSBGN03811 rev.1 - Fortify Software Security Center (SSC), Multiple vulnerabilities
46RISK
open
GitHub PoC30
Analysis of VBS exploit CVE-2018-8174
CVE-2018-8174HIGHunder attackransomware10 Jul 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISK
open
GitHub PoC1
lonehand/Oracle-WebLogic-CVE-2017-10271-master
CVE-2017-10271HIGHunder attackransomware06 Jul 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC3
likekabin/CVE-2018-2628
CVE-2018-2628CRITICALunder attack02 Jul 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
GitHub PoC
Aruthw/CVE-2014-6271
CVE-2014-6271CRITICALunder attack30 Jun 2018
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
qy1202/https-github.com-Ridter-CVE-2017-11882-
CVE-2017-11882HIGHunder attackransomware28 Jun 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC11
Exploitable target to CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware26 Jun 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
stevenlinfeng/CVE-2018-2628
CVE-2018-2628CRITICALunder attack26 Jun 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
GitHub PoC
Rig Exploit for CVE-2018-8174 As with its previous campaigns, Rig’s Seamless campaign uses malvertising. In this case, the malvertisements have a hidden iframe that redirects victims to Rig’s landing page, which includes an exploit for CVE-2018-8174 and shellcode. This enables remote code execution of the shellcode obfuscated in the landing page. After successful exploitation, a second-stage downloader is retrieved, which appears to be a variant of SmokeLoader due to the URL. It would then download the final payload, a Monero miner.
CVE-2018-8174HIGHunder attackransomware26 Jun 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISK
open
GitHub PoC1
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Text Annotations. When setting the point attribute, the process does not properly validate the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process.
CVE-2018-995825 Jun 2018
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1
50RISK
open
GitHub PoC
guwudoor/CVE-2018-8214
CVE-2018-821425 Jun 2018
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
23RISK
open
GitHub PoC
leandrocamposcardoso/CVE-2017-5638-Mass-Exploit
CVE-2017-5638CRITICALunder attackransomware24 Jun 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC520
Proof of Concept of Winbox Critical Vulnerability (CVE-2018-14847)
CVE-2018-14847CRITICALunder attack24 Jun 2018
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open
GitHub PoC1
Cisco ASA - CVE-2018-0296 | Exploit
CVE-2018-0296HIGHunder attack22 Jun 2018
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RISK
open
GitHub PoC
Ektron Content Management System (CMS) 9.20 SP2, remote re-enabling users (CVE-2018–12596)
CVE-2018-1259621 Jun 2018
Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote at
28RISK
open
GitHub PoC205
Script to test for Cisco ASA path traversal vulnerability (CVE-2018-0296) and extract system information.
CVE-2018-0296HIGHunder attack21 Jun 2018
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RISK
open
GitHub PoC107
Test CVE-2018-0296 and extract usernames
CVE-2018-0296HIGHunder attack21 Jun 2018
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RISK
open
GitHub PoC9
MS15-034 HTTP.sys 远程执行代码检测脚本(MS15-034 HTTP.sys remote execution code poc script)
CVE-2015-1635CRITICALunder attack20 Jun 2018
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open
previouspage 441 / 470next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.