Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,206cataloged exploits
35,418CVEs with public exploitation
24,695lab-tested
14,096 exploits
GitHub PoC1
CVE-2017-9805 - Exploit
CVE-2017-9805HIGHunder attack28 Nov 2017
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISK
open
GitHub PoC1
Tomcat 远程代码执行漏洞 Exploit
CVE-2017-12615HIGHunder attackransomware28 Nov 2017
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open
GitHub PoC210
CVE-2017-12149 jboss反序列化 可回显
CVE-2017-12149CRITICALunder attackransomware28 Nov 2017
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISK
open
GitHub PoC2
Shadowshusky/CVE-2017-11882-
CVE-2017-11882HIGHunder attackransomware27 Nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC2
CVE-2015-4852 Oracle WebLogic Scanner
CVE-2015-4852CRITICALunder attack25 Nov 2017
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RISK
open
GitHub PoC
CSC-pentest/cve-2017-11882
CVE-2017-11882HIGHunder attackransomware24 Nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC15
Exploit script for Apache Struts2 REST Plugin XStream RCE (‎CVE-2017-9805)
CVE-2017-9805HIGHunder attack24 Nov 2017
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISK
open
GitHub PoC
# CVE-2017-11882-metasploit This is a Metasploit module which exploits CVE-2017-11882 using the POC below: https://embedi.com/blog/skeleton-closet-ms-office-vulnerability-you-didnt-know-about. ## Installation 1) Copy the cve_2017_11882.rb to /usr/share/metasploit-framework/modules/exploits/windows/local/ 2) Copy the cve-2017-11882.rtf to /usr/share/metasploit-framework/data/exploits/ This module is a quick port to Metasploit and uses mshta.exe to execute the payload. There are better ways to implement this module and exploit but will update it as soon as I have the time.
CVE-2017-11882HIGHunder attackransomware24 Nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC3
Shellshock exploitation script that is able to upload and RCE using any vector due to its versatility.
CVE-2014-6271CRITICALunder attack23 Nov 2017
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC44
CVE-2017-11882 exploitation
CVE-2017-11882HIGHunder attackransomware22 Nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC
CVE-2017-9430 Fix
CVE-2017-943022 Nov 2017
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) o
28RISK
open
GitHub PoC
Grey-Li/CVE-2017-11882
CVE-2017-11882HIGHunder attackransomware22 Nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC34
CVE-2017-11882 File Generator PoC
CVE-2017-11882HIGHunder attackransomware21 Nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC535
CVE-2017-11882 from https://github.com/embedi/CVE-2017-11882
CVE-2017-11882HIGHunder attackransomware21 Nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC22
CVE-2017-12149 JBOSS as 6.X反序列化(反弹shell版)
CVE-2017-12149CRITICALunder attackransomware21 Nov 2017
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISK
open
GitHub PoC330
CVE-2017-11882 Exploit accepts over 17k bytes long command/code in maximum.
CVE-2017-11882HIGHunder attackransomware21 Nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC98
This is a Metasploit module which exploits CVE-2017-11882 using the POC released here : https://embedi.com/blog/skeleton-closet-ms-office-vulnerability-you-didnt-know-about.
CVE-2017-11882HIGHunder attackransomware21 Nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC
CVE-2017-11882
CVE-2017-11882HIGHunder attackransomware21 Nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC494
Proof-of-Concept exploits for CVE-2017-11882
CVE-2017-11882HIGHunder attackransomware20 Nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC3
zhouat/cve-2017-11882
CVE-2017-11882HIGHunder attackransomware19 Nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC2
Exploits CVE-2016-10033 and CVE-2016-10045
CVE-2016-10033CRITICALunder attack19 Nov 2017
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
GitHub PoC67
CVE-2017-8917 - SQL injection Vulnerability Exploit in Joomla 3.7.0
CVE-2017-891719 Nov 2017
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISK
open
GitHub PoC2
herbiezimmerman/2017-11-17-Maldoc-Using-CVE-2017-0199
CVE-2017-0199HIGHunder attackransomware17 Nov 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
GitHub PoC
Python exploit for CVE-2017-16806
CVE-2017-1680613 Nov 2017
The Process function in RemoteTaskServer/WebServer/HttpServer.cs in Ulterius before 1.9.5.0 allows HTTP server directory
60RISK
open
GitHub PoC160
Chrome < 62 uxss exploit (CVE-2017-5124)
CVE-2017-512413 Nov 2017
Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject
23RISK
open
GitHub PoC1
Fork of github.com/spring-projects/spring-data-rest (vulnerable to CVE-2017-8046)
CVE-2017-804608 Nov 2017
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISK
open
GitHub PoC4
Unrestricted file upload vulnerability - Web Viewer 1.0.0.193 on Samsung SRN-1670D
CVE-2017-1652405 Nov 2017
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_u
50RISK
open
GitHub PoC2
RTF de-obfuscator for CVE-2017-0199 documents to find URLs statically.
CVE-2017-0199HIGHunder attackransomware03 Nov 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
GitHub PoC5
Exploit for the linux kernel vulnerability CVE-2017-5123
CVE-2017-512303 Nov 2017
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RISK
open
GitHub PoC2
tomcat-put-cve-2017-12615
CVE-2017-12615HIGHunder attackransomware01 Nov 2017
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open
previouspage 450 / 470next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.