Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
14,119 exploits
GitHub PoC12
A python script to enumerate CGI scripts vulnerable to CVE-2014-6271 on one specific server
CVE-2014-6271CRITICALunder attack28 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC1
A script, in C, to check if CGI scripts are vulnerable to CVE-2014-6271 (The Bash Bug)
CVE-2014-6271CRITICALunder attack28 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
u20024804/bash-4.2-fixed-CVE-2014-6271
CVE-2014-6271CRITICALunder attack27 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
u20024804/bash-3.2-fixed-CVE-2014-6271
CVE-2014-6271CRITICALunder attack27 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
u20024804/bash-4.3-fixed-CVE-2014-6271
CVE-2014-6271CRITICALunder attack27 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC1
Salt recipe for shellshock (CVE-2014-6271)
CVE-2014-6271CRITICALunder attack26 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
scaner for cve-2014-6271
CVE-2014-6271CRITICALunder attack26 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC4
CVE-2014-6271 (ShellShock) RCE PoC tool
CVE-2014-6271CRITICALunder attack26 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC1
An A/V evasion armoring experiment for CVE-2012-4681
CVE-2012-4681CRITICALunder attackransomware26 Sep 2014
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow
100RISK
open
GitHub PoC
Debian Lenny Bash packages with cve-2014-6271 patches (i386 and amd64)
CVE-2014-6271CRITICALunder attack26 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
Ansible role to check the CVE-2014-6271 vulnerability
CVE-2014-6271CRITICALunder attack26 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
Chef cookbook that will fail if bash vulnerability found per CVE-2014-6271
CVE-2014-6271CRITICALunder attack25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC1
Written fro CVE-2014-6271
CVE-2014-6271CRITICALunder attack25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC46
Python Scanner for "ShellShock" (CVE-2014-6271)
CVE-2014-6271CRITICALunder attack25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
rrreeeyyy/cve-2014-6271-spec
CVE-2014-6271CRITICALunder attack25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
mattclegg/CVE-2014-6271
CVE-2014-6271CRITICALunder attack25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
a auto script to fix CVE-2014-6271 bash vulnerability
CVE-2014-6271CRITICALunder attack25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
woltage/CVE-2014-6271
CVE-2014-6271CRITICALunder attack25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC2
CVE-2014-6271 RCE tool
CVE-2014-6271CRITICALunder attack25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
Quick and dirty nessus .audit file to check is bash is vulnerable to CVE-2014-6271
CVE-2014-6271CRITICALunder attack25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
CVE-2014-6271の検証用Vagrantfileです
CVE-2014-6271CRITICALunder attack25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC1
scripts associate with bourne shell EVN function parsing vulnerability CVE-2014-6271
CVE-2014-6271CRITICALunder attack25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC1
Simple script to check for CVE-2014-6271
CVE-2014-6271CRITICALunder attack25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC6
Patch for CVE-2014-6271
CVE-2014-6271CRITICALunder attack24 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
patched-bash-4.3 for CVE-2014-6271
CVE-2014-6271CRITICALunder attack24 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
Collected fixes for bash CVE-2014-6271
CVE-2014-6271CRITICALunder attack24 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC46
Research of CVE-2014-3153 and its famous exploit towelroot on x86
CVE-2014-3153HIGHunder attack20 Sep 2014
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISK
open
GitHub PoC19
CVE-2014-3153 exploit
CVE-2014-3153HIGHunder attack13 Sep 2014
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISK
open
GitHub PoC15
Scans NTP servers for CVE-2013-5211 NTP DDOS amplification vulnerability.
CVE-2013-521107 Sep 2014
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISK
open
GitHub PoC15
Annotated FBI exploit for the Tor Browser Bundle from mid-2013 (CVE-2013-1690)
CVE-2013-1690HIGHunder attack19 Aug 2014
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before
98RISK
open
previouspage 468 / 471next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.