Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
14,119 exploits
GitHub PoC
whiteHat001/cve-2010-3333
CVE-2010-3333HIGHunder attack26 Sep 2016
Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2
100RISK
open
GitHub PoC3
这里保存着我学习CVE-2012-1889这个漏洞的利用所用到的文件
CVE-2012-1889HIGHunder attack25 Sep 2016
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attacker
100RISK
open
GitHub PoC9
0ldSQL_MySQL_RCE_exploit.py (ver. 1.0) (CVE-2016-6662) MySQL Remote Root Code Execution / Privesc PoC Exploit For testing purposes only. Do no harm.
CVE-2016-666220 Sep 2016
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RISK
open
GitHub PoC163
Public repository for improvements to the EXTRABACON exploit
CVE-2016-6366HIGHunder attack20 Sep 2016
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Service
100RISK
open
GitHub PoC
research CVE-2016-6662
CVE-2016-666216 Sep 2016
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RISK
open
GitHub PoC1
Simple ansible playbook to patch mysql servers against CVE-2016-6662
CVE-2016-666215 Sep 2016
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RISK
open
GitHub PoC
MySQL server CVE-2016-6662 patch playbook
CVE-2016-666214 Sep 2016
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RISK
open
GitHub PoC33
Verification tools for CVE-2016-1287
CVE-2016-128708 Sep 2016
Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0
45RISK
open
GitHub PoC2
CVE-2014-6332 ZeroDay POC - Starts PowerShell
CVE-2014-6332HIGHunder attack29 Aug 2016
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RISK
open
GitHub PoC1
linux 提权
CVE-2012-005622 Jul 2016
The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when
28RISK
open
GitHub PoC11
This is a python-based standalone exploit for CVE-2006-6184. This exploit triggers a stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote attackers to cause a denial of service or execute arbitrary code.
CVE-2006-618421 Jul 2016
Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote at
50RISK
open
GitHub PoC1
CVE-2016-3962-Exploit
CVE-2016-396217 Jul 2016
Stack-based buffer overflow in the NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTI
23RISK
open
GitHub PoC
KosukeShimofuji/CVE-2016-5734
CVE-2016-573408 Jul 2016
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to
60RISK
open
GitHub PoC1
JBoss Autopwn CVE-2010-0738 JBoss authentication bypass
CVE-2010-0738MEDIUMunder attackransomware02 Jul 2016
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RISK
open
GitHub PoC
CVE-2016-4971 written in nodejs
CVE-2016-497102 Jul 2016
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted F
35RISK
open
GitHub PoC364
Exploit that extracts Qualcomm's KeyMaster keys using CVE-2015-6639 and CVE-2016-2431
CVE-2015-663930 Jun 2016
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to
23RISK
open
GitHub PoC3
对CVE-2016-0189漏洞补丁的分析
CVE-2016-0189HIGHunder attack25 Jun 2016
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other
100RISK
open
GitHub PoC114
Proof-of-Concept exploit for CVE-2016-0189 (VBScript Memory Corruption in IE11)
CVE-2016-0189HIGHunder attack22 Jun 2016
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other
100RISK
open
GitHub PoC
CVE-2016-0051 样本库
CVE-2016-005116 Jun 2016
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RISK
open
GitHub PoC2
Docker container implementing tests for CVE-2016-2107 - LuckyNegative20
CVE-2016-210709 Jun 2016
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a
45RISK
open
GitHub PoC1
A PoC of CVE-2016-2098 (rails4.2.5.1 / view render)
CVE-2016-209807 Jun 2016
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISK
open
GitHub PoC
thejackerz/scanner-exploit-joomla-CVE-2015-8562
CVE-2015-856207 Jun 2016
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISK
open
GitHub PoC4
MySQL DoS in the Procedure Analyse Function – CVE-2015-4870
CVE-2015-487030 May 2016
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated
35RISK
open
GitHub PoC
towelroot
CVE-2014-3153HIGHunder attack29 May 2016
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISK
open
GitHub PoC6
Magento Unauthorized Remote Code Execution (CVE-2016-4010)
CVE-2016-401025 May 2016
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary
60RISK
open
GitHub PoC86
Local privilege escalation for OS X 10.10.5 via CVE-2016-1828.
CVE-2016-182818 May 2016
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RISK
open
GitHub PoC
Test modified buggy poc
CVE-2016-080115 May 2016
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01
35RISK
open
GitHub PoC15
Microsoft Office / COM Object DLL Planting
CVE-2015-613214 May 2016
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
60RISK
open
GitHub PoC78
abdsec/CVE-2016-0801
CVE-2016-080111 May 2016
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01
35RISK
open
GitHub PoC41
hexx0r/CVE-2016-0051
CVE-2016-005108 May 2016
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RISK
open
previouspage 462 / 471next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.