Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
14,096 exploits
GitHub PoC11
Al1ex/CVE-2017-7269
CVE-2017-7269CRITICALunder attack28 Apr 2018
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC6
POC to test/exploit drupal vulnerability SA-CORE-2018-004 / CVE-2018-7602
CVE-2018-7602CRITICALunder attackransomware27 Apr 2018
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RISK
open
GitHub PoC13
CVE-2017-16995(Ubuntu本地提权漏洞)
CVE-2017-1699526 Apr 2018
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
GitHub PoC
CVE-2018-9160
CVE-2018-916026 Apr 2018
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
60RISK
open
GitHub PoC2
Tool to dive Apache logs for evidence of exploitation of CVE-2018-7600
CVE-2018-7600CRITICALunder attackransomware24 Apr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC
herbiezimmerman/CVE-2017-11882-Possible-Remcos-Malspam
CVE-2017-11882HIGHunder attackransomware23 Apr 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC
mudhappy/Wordpress-Hack-CVE-2018-6389
CVE-2018-638920 Apr 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISK
open
GitHub PoC
CalderaForms 1.5.9.1 XSS (WordPress plugin) - tutorial
CVE-2018-774720 Apr 2018
Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow re
23RISK
open
GitHub PoC2
Shadowshusky/CVE-2018-2628all
CVE-2018-2628CRITICALunder attack20 Apr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
GitHub PoC
shaoshore/CVE-2018-2628
CVE-2018-2628CRITICALunder attack20 Apr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
GitHub PoC1
xssfile/CVE-2017-8464-EXP
CVE-2017-8464HIGHunder attack20 Apr 2018
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RISK
open
GitHub PoC119
macOS 10.13.3 (17D47) Safari Wasm Exploit
CVE-2018-412119 Apr 2018
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud b
28RISK
open
GitHub PoC11
Exploit for CVE-2018-7600.. called drupalgeddon2,
CVE-2018-7600CRITICALunder attackransomware19 Apr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC1
CVE-2018-2628
CVE-2018-2628CRITICALunder attack19 Apr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
GitHub PoC1
9uest/CVE-2018-2628
CVE-2018-2628CRITICALunder attack19 Apr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
GitHub PoC20
CVE-2018-2628
CVE-2018-2628CRITICALunder attack18 Apr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
GitHub PoC15
WebLogic WLS核心组件反序列化漏洞多线程批量检测脚本 CVE-2018-2628-MultiThreading
CVE-2018-2628CRITICALunder attack18 Apr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
GitHub PoC14
jiansiting/weblogic-cve-2018-2628
CVE-2018-2628CRITICALunder attack18 Apr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
GitHub PoC1
CVE-2018-2628
CVE-2018-2628CRITICALunder attack18 Apr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
GitHub PoC78
CVE-2018-2628 & CVE-2018-2893
CVE-2018-2628CRITICALunder attack18 Apr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
GitHub PoC2
zjxzjx/CVE-2018-2628-detect
CVE-2018-2628CRITICALunder attack18 Apr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
GitHub PoC24
POC for CVE-2018-1273
CVE-2018-1273CRITICALunder attackransomware17 Apr 2018
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RISK
open
GitHub PoC141
Exploit for Drupal 7 <= 7.57 CVE-2018-7600
CVE-2018-7600CRITICALunder attackransomware17 Apr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC1
This is a Java program that exploits Spring Break vulnerability (CVE-2017-8046).
CVE-2017-804616 Apr 2018
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISK
open
GitHub PoC71
CVE-2018-7600 - Drupal 7.x RCE
CVE-2018-7600CRITICALunder attackransomware16 Apr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC41
CVE-2018-6546-Exploit
CVE-2018-654615 Apr 2018
plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming
28RISK
open
GitHub PoC7
Proof-of-Concept for Drupal CVE-2018-7600 / SA-CORE-2018-002
CVE-2018-7600CRITICALunder attackransomware15 Apr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC3
Tool to check for CVE-2018-7600 vulnerability on several URLS
CVE-2018-7600CRITICALunder attackransomware15 Apr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC4
Testing and exploitation tool for Drupalgeddon 2 (CVE-2018-7600)
CVE-2018-7600CRITICALunder attackransomware15 Apr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC5
MSF exploit module for Drupalgeddon 2 (CVE-2018-7600 / SA-CORE-2018-002)
CVE-2018-7600CRITICALunder attackransomware14 Apr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
previouspage 444 / 470next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.