Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,233GitHub PoC 14,119VulnCheck XDB 8,617Nuclei 4,257Metasploit 3,474✓ verified onlyrecentpopularrisk
14,096 exploits
GitHub PoC★ 22
ERPScan Public POC for CVE-2018-2636
Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Security).
28RISK
open ↗GitHub PoC
Working POC for CVE 2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open ↗GitHub PoC★ 39
The Demo for CVE-2018-1000006
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the pro
60RISK
open ↗GitHub PoC★ 20
BMC Bladelogic RSCD exploits including remote code execution - CVE-2016-1542, CVE-2016-1543, CVE-2016-5063
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and U
60RISK
open ↗GitHub PoC
CVE-2017-7269利用代码(rb文件)
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open ↗GitHub PoC★ 1
dewankpant/CVE-2017-16568
Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality.
23RISK
open ↗GitHub PoC★ 1
备忘:flash挂马工具备份 CVE-2018-4878
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISK
open ↗GitHub PoC
WebLogic wls-wsat RCE CVE-2017-10271
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open ↗GitHub PoC★ 7
cve-2017-10271 POC
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open ↗GitHub PoC★ 1
Struts2 Application Vulnerable to CVE-2017-5638. Explains how the exploit of the vulnerability works in relation to OGNL and the JakartaMultiPart parser.
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open ↗GitHub PoC★ 4
Minishare 1.4.1 Remote Buffer Overflow
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET req
60RISK
open ↗GitHub PoC★ 177
Base64-based encryption oracle exploit for CVE-2017-9248 (Telerik UI for ASP.NET AJAX dialog handler)
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RISK
open ↗GitHub PoC★ 5
CVE-2017-10271 Weblogic 漏洞验证Poc及补丁
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open ↗GitHub PoC★ 11
likekabin/CVE-2018-0802_CVE-2017-11882
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open ↗GitHub PoC
likekabin/CVE-2017-11882
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open ↗GitHub PoC★ 11
likekabin/CVE-2018-0802_CVE-2017-11882
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RISK
open ↗GitHub PoC
Assesses a system for the "speculative execution" vulnerabilities described in CVE-2017-5715, CVE-2017-5753, CVE-2017-5754
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RISK
open ↗GitHub PoC★ 17
a list of BIOS/Firmware fixes adressing CVE-2017-5715, CVE-2017-5753, CVE-2017-5754
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RISK
open ↗GitHub PoC★ 166
PoC for CVE-2018-0802 And CVE-2017-11882
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RISK
open ↗GitHub PoC★ 166
PoC for CVE-2018-0802 And CVE-2017-11882
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open ↗GitHub PoC★ 270
PoC Exploit for CVE-2018-0802 (and optionally CVE-2017-11882)
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open ↗GitHub PoC★ 270
PoC Exploit for CVE-2018-0802 (and optionally CVE-2017-11882)
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RISK
open ↗GitHub PoC★ 68
Exploit the vulnerability to execute the calculator
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RISK
open ↗GitHub PoC★ 11
TwonkyMedia Server 7.0.11-8.5 Directory Traversal CVE-2018-7171
Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of a
28RISK
open ↗GitHub PoC★ 9
8.4.1 Jailbreak using CVE-2016-4655 / CVE-2016-4656
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RISK
open ↗GitHub PoC★ 54
Spectre exploit
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RISK
open ↗GitHub PoC★ 180
Telerik UI for ASP.NET AJAX File upload and .NET deserialisation exploit (CVE-2017-11317, CVE-2017-11357, CVE-2019-18935)
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open ↗GitHub PoC★ 185
Proof of Concept exploit for CVE-2017-8570
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RISK
open ↗GitHub PoC★ 180
Telerik UI for ASP.NET AJAX File upload and .NET deserialisation exploit (CVE-2017-11317, CVE-2017-11357, CVE-2019-18935)
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RISK
open ↗GitHub PoC★ 1
OSX 10.13.2, CVE-2017-5753, Spectre, PoC, C, ASM for OSX, MAC, Intel Arch, Proof of Concept, Hopper.App Output
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.