Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,559cataloged exploits
34,978CVEs with public exploitation
24,695lab-tested
13,960 exploits
GitHub PoC2
weblogic CVE-2019-2725利用exp。
CVE-2019-2725HIGHunder attackransomware08 Jan 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC2
Simple Overflow demo, like CVE-2017-11882 exp
CVE-2017-11882HIGHunder attackransomware08 Jan 2020
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC
geropl/CVE-2019-5736
CVE-2019-573608 Jan 2020
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
GitHub PoC149
bluefrostsecurity/CVE-2019-1215
CVE-2019-1215HIGHunder attackransomware06 Jan 2020
An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Win
76RISK
open
GitHub PoC
CVE-2017-9841 detector script
CVE-2017-9841CRITICALunder attack06 Jan 2020
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
GitHub PoC1
Any3ite/CVE-2014-6271
CVE-2014-6271CRITICALunder attack06 Jan 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC5
CVE-2019-10758
CVE-2019-10758CRITICALunder attack05 Jan 2020
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse
100RISK
open
GitHub PoC
CVE-2017-8759 use file
CVE-2017-8759HIGHunder attack02 Jan 2020
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RISK
open
GitHub PoC
CVE-2019-16278:Nostromo Web服务器的RCE漏洞
CVE-2019-16278CRITICALunder attack01 Jan 2020
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
GitHub PoC1
(Nhttpd) Nostromo 1.9.6 RCE due to Directory Traversal
CVE-2019-16278CRITICALunder attack31 Dec 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
GitHub PoC
samba 4.5.9
CVE-2017-7494CRITICALunder attackransomware30 Dec 2019
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open
GitHub PoC
webmin_CVE-2019-15107
CVE-2019-15107CRITICALunder attackransomware29 Dec 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC4
Identify vulnerable (RCE) vBulletin 5.0.0 - 5.5.4 instances using Shodan (CVE-2019-16759)
CVE-2019-16759CRITICALunder attack29 Dec 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISK
open
GitHub PoC
HttpFileServer httpd 2.3
CVE-2014-6287CRITICALunder attack27 Dec 2019
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
GitHub PoC5
CVE-2018-8639-EXP
CVE-2018-8639HIGHunder attackransomware27 Dec 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
76RISK
open
GitHub PoC111
masahiro331/CVE-2019-10758
CVE-2019-10758CRITICALunder attack26 Dec 2019
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse
100RISK
open
GitHub PoC8
poc exploit for webmin backdoor (CVE-2019-15107 and CVE-2019-15231)
CVE-2019-15107CRITICALunder attackransomware25 Dec 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC78
Apache Log4j 1.2.X存在反序列化远程代码执行漏洞
CVE-2019-17571CRITICAL25 Dec 2019
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be explo
60RISK
open
GitHub PoC8
PoC for CVE-2019-19844 ( https://www.djangoproject.com/weblog/2019/dec/18/security-releases/ )
CVE-2019-1984425 Dec 2019
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address
35RISK
open
GitHub PoC3
CVE-2018-6389: WordPress <= 4.9.x 拒绝服务(DOS)漏洞
CVE-2018-638922 Dec 2019
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISK
open
GitHub PoC645
一款功能强大的漏洞扫描器,子域名爆破使用aioDNS,asyncio异步快速扫描,覆盖目标全方位资产进行批量漏洞扫描,中间件信息收集,自动收集ip代理,探测Waf信息时自动使用来保护本机真实Ip,在本机Ip被Waf杀死后,自动切换代理Ip进行扫描,Waf信息收集(国内外100+款waf信息)包括安全狗,云锁,阿里云,云盾,腾讯云等,提供部分已知waf bypass 方案,中间件漏洞检测(Thinkphp,weblogic等 CVE-2018-5955,CVE-2018-12613,CVE-2018-11759等),支持SQL注入, XSS, 命令执行,文件包含, ssrf 漏洞扫描, 支持自定义漏洞邮箱推送功能
CVE-2018-595521 Dec 2019
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau
60RISK
open
GitHub PoC1
my extended take on Mark Brand's CVE 2016-3861 libutils bug
CVE-2016-386121 Dec 2019
LibUtils in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016
23RISK
open
GitHub PoC100
PoC for CVE-2019-19844(https://www.djangoproject.com/weblog/2019/dec/18/security-releases/)
CVE-2019-1984421 Dec 2019
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address
35RISK
open
GitHub PoC
Mass exploit for CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware20 Dec 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC5
CVE-2019-10092 Docker - Apache HTTP Server
CVE-2019-1009218 Dec 2019
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page
60RISK
open
GitHub PoC1
CVE-2018-9995 POC
CVE-2018-999516 Dec 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
GitHub PoC
ianxtianxt/CVE-2019-15107
CVE-2019-15107CRITICALunder attackransomware15 Dec 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC6
SmoZy92/CVE-2019-11932
CVE-2019-1193215 Dec 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open
GitHub PoC373
RCE exploit for a .NET JSON deserialization vulnerability in Telerik UI for ASP.NET AJAX.
CVE-2019-18935CRITICALunder attackransomware12 Dec 2019
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
GitHub PoC
CVE-2019-2725-POC
CVE-2019-2725HIGHunder attackransomware12 Dec 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
previouspage 410 / 466next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.