Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
14,096 exploits
GitHub PoC1
Apache Struts CVE-2017-5638 RCE exploitation
CVE-2017-5638CRITICALunder attackransomware20 Mar 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
Linux Kernel Version 4.14 - 4.4 (Ubuntu && Debian)
CVE-2017-1699519 Mar 2018
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
GitHub PoC
likekabin/CVE-2017-0213
CVE-2017-0213HIGHunder attackransomware19 Mar 2018
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RISK
open
GitHub PoC
CVE-2018-6789
CVE-2018-6789CRITICALunder attackransomware16 Mar 2018
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISK
open
GitHub PoC2
Golang exploit for CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware14 Mar 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC51
PoC of Remote Command Execution via Log injection on SAP NetWeaver AS JAVA CRM
CVE-2018-2380MEDIUMunder attackransomware14 Mar 2018
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information pr
68RISK
open
GitHub PoC37
PoC code for CVE-2017-13253
CVE-2017-1325312 Mar 2018
In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. Thi
23RISK
open
GitHub PoC1
PoC for SpringBreak (CVE-2017-8046)
CVE-2017-804612 Mar 2018
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISK
open
GitHub PoC95
Exploitation Tool for CVE-2017-3066 targeting Adobe Coldfusion 11/12
CVE-2017-3066CRITICALunder attack12 Mar 2018
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier hav
100RISK
open
GitHub PoC
fibonascii/CVE-2004-0558
CVE-2004-055810 Mar 2018
The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of s
28RISK
open
GitHub PoC17
This is a Java program that exploits Spring Break vulnerability (CVE-2017-8046).
CVE-2017-804609 Mar 2018
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISK
open
GitHub PoC14
WARNING: This is a vulnerable application to test the exploit for the Spring Break vulnerability (CVE-2017-8046). Run it at your own risk!
CVE-2017-804608 Mar 2018
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISK
open
GitHub PoC2
Exploit iOS 11.2.x by ZIMPERIUM and semi-completed by me. Sandbox escapes on CVE-2018-4087.
CVE-2018-408708 Mar 2018
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchO
23RISK
open
GitHub PoC130
Improved DOS exploit for wordpress websites (CVE-2018-6389)
CVE-2018-638904 Mar 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISK
open
GitHub PoC2
Tries to exploit a WordPress vulnerability (CVE-2018-6389) which can be used to cause a Denial of Service.
CVE-2018-638904 Mar 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISK
open
GitHub PoC8
Joomla - Component Google Map Landkarten <= 4.2.3 - SQL Injection
CVE-2018-639602 Mar 2018
SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a l
28RISK
open
GitHub PoC1
cve-2017-10271
CVE-2017-10271HIGHunder attackransomware01 Mar 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC
Cisco iOS SNMP Overflow Exploit Toolkit (CVE-2017-6736)
CVE-2017-6736HIGHunder attack01 Mar 2018
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabiliti
93RISK
open
GitHub PoC2
CVE-2018-6389 WordPress Core - 'load-scripts.php' Denial of Service <= 4.9.4
CVE-2018-638901 Mar 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISK
open
GitHub PoC4
Source code and configuration files related to our article in MISC96
CVE-2017-512301 Mar 2018
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RISK
open
GitHub PoC1
This is a sort of Java porting of the Python exploit at: https://www.exploit-db.com/exploits/41570/.
CVE-2017-5638CRITICALunder attackransomware28 Feb 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
alessiogilardi/PoC---CVE-2018-6389
CVE-2018-638928 Feb 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISK
open
GitHub PoC82
A sandbox escape based on the proof-of-concept (CVE-2018-4087) by Rani Idan (Zimperium)
CVE-2018-408728 Feb 2018
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchO
23RISK
open
GitHub PoC
BlackRouter/cve-2018-6389
CVE-2018-638926 Feb 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISK
open
GitHub PoC
MaxSecurity/Office-CVE-2017-8570
CVE-2017-8570HIGHunder attack26 Feb 2018
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RISK
open
GitHub PoC
Proof of Concept of vunerability CVE-2018-6389 on Wordpress 4.9.2
CVE-2018-638925 Feb 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISK
open
GitHub PoC
CVE-2018-4878 样本
CVE-2018-4878HIGHunder attackransomware23 Feb 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISK
open
GitHub PoC59
CVE-2018-4087 PoC
CVE-2018-408721 Feb 2018
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchO
23RISK
open
GitHub PoC1
RavSS/Bluetooth-Crash-CVE-2017-0785
CVE-2017-078521 Feb 2018
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RISK
open
GitHub PoC3
HanseSecure/CVE-2009-1437
CVE-2009-143719 Feb 2018
Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.6 and earlier allows rem
28RISK
open
previouspage 446 / 470next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.