Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
14,096 exploits
GitHub PoC4
PoC for CVE-2018-7600 Drupal SA-CORE-2018-002 (Drupalgeddon 2).
CVE-2018-7600CRITICALunder attackransomware14 Apr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC7
Drupal 0day Remote PHP Code Execution (Perl)
CVE-2018-7600CRITICALunder attackransomware14 Apr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC3
CVE-2018-7600 (Drupal)
CVE-2018-7600CRITICALunder attackransomware13 Apr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC10
Environment for CVE-2018-1273 (Spring Data Commons)
CVE-2018-1273CRITICALunder attackransomware13 Apr 2018
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RISK
open
GitHub PoC600
Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)
CVE-2018-7600CRITICALunder attackransomware12 Apr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC
Example exploit for CVE-2016-5195
CVE-2016-5195HIGHunder attack11 Apr 2018
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC14
Fixed No Virus Manual Automatic Loader exe no zip because zip picks up the anti virus detector.
CVE-2017-0213HIGHunder attackransomware10 Apr 2018
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RISK
open
GitHub PoC5
CVE-2017-8570生成脚本(CVE-2017-0199另一种利用方式)
CVE-2017-8570HIGHunder attack08 Apr 2018
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RISK
open
GitHub PoC2
Android Blueborne RCE CVE-2017-0781
CVE-2017-078106 Apr 2018
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RISK
open
GitHub PoC2
Android Blueborne RCE CVE-2017-0781
CVE-2017-078106 Apr 2018
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RISK
open
GitHub PoC7
Flash Exploit Poc
CVE-2018-4878HIGHunder attackransomware04 Apr 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISK
open
GitHub PoC
Phusion WebServer 1.0 - 'URL' Remote Buffer Overflow
CVE-2002-028903 Apr 2018
Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary cod
28RISK
open
GitHub PoC
Phusion WebServer 1.0 - Directory Traversal
CVE-2002-028803 Apr 2018
Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (t
23RISK
open
GitHub PoC
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request, possibly triggering a buffer overflow.
CVE-2002-020103 Apr 2018
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute a
28RISK
open
GitHub PoC
March Networks DVR 3204 - Logfile Information Disclosure
CVE-2007-663803 Apr 2018
March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows r
28RISK
open
GitHub PoC
Cooolsoft PowerFTP Server 2.0 3/2.10 - Multiple Denial of Service Vulnerabilities
CVE-2001-093203 Apr 2018
Buffer overflow in Cooolsoft PowerFTP Server 2.03 allows remote attackers to cause a denial of service and possibly exec
28RISK
open
GitHub PoC
Nortel Wireless LAN Access Point 2200 Series - Denial of Service
CVE-2004-254903 Apr 2018
Nortel Wireless LAN (WLAN) Access Point (AP) 2220, 2221, and 2225 allow remote attackers to cause a denial of service (s
28RISK
open
GitHub PoC
Xerver 2.10 - Multiple Request Denial of Service Vulnerabilities
CVE-2002-044803 Apr 2018
Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request
28RISK
open
GitHub PoC
Airsensor M520 - HTTPd Unauthenticated Remote Denial of Service / Buffer Overflow (PoC)
CVE-2007-503603 Apr 2018
Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated
23RISK
open
GitHub PoC
Cisco VPN Client - Integer Overflow Denial of Service
CVE-2009-411802 Apr 2018
The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0
23RISK
open
GitHub PoC267
A code demonstrating CVE-2018-0886
CVE-2018-088602 Apr 2018
The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 S
45RISK
open
GitHub PoC
tomcat7.x远程命令执行
CVE-2017-12615HIGHunder attackransomware01 Apr 2018
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open
GitHub PoC49
An implementation of CVE-2016-0974 for the Nintendo Wii.
CVE-2016-097401 Apr 2018
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and
35RISK
open
GitHub PoC114
CVE-2018-7600 Drupal RCE
CVE-2018-7600CRITICALunder attackransomware30 Mar 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC354
💀Proof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002
CVE-2018-7600CRITICALunder attackransomware30 Mar 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC
lucad93/CVE-2018-3810
CVE-2018-381029 Mar 2018
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RISK
open
GitHub PoC5
CVE-2017-14322 Interspire Email Marketer (emailmarketer) Exploit
CVE-2017-1432227 Mar 2018
The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior
35RISK
open
GitHub PoC
likekabin/CVE-2017-0199
CVE-2017-0199HIGHunder attackransomware22 Mar 2018
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
GitHub PoC1
A version of CVE-2017-0213 that I plan to use with an Empire stager
CVE-2017-0213HIGHunder attackransomware21 Mar 2018
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RISK
open
GitHub PoC1
Apache Struts CVE-2017-5638 RCE exploitation
CVE-2017-5638CRITICALunder attackransomware20 Mar 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
previouspage 445 / 470next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.