Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
14,014 exploits
GitHub PoC15
RTSPServer Code Execution Vulnerability CVE-2018-4013
CVE-2018-4013CRITICAL24 Nov 2018
An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server l
48RISK
open
GitHub PoC2
zeroto01/CVE-2018-14667
CVE-2018-14667CRITICALunder attack23 Nov 2018
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RISK
open
GitHub PoC1
un4ckn0wl3z/CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware22 Nov 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
libSSH bypass
CVE-2018-10933CRITICAL21 Nov 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC
tafamace/CVE-2017-17485
CVE-2017-17485CRITICAL19 Nov 2018
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because o
60RISK
open
GitHub PoC
tafamace/CVE-2016-0793
CVE-2016-079319 Nov 2018
Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Se
28RISK
open
GitHub PoC83
Tool for CVE-2018-16323
CVE-2018-1632318 Nov 2018
ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that ha
35RISK
open
GitHub PoC
cve-2018-14667 demo
CVE-2018-14667CRITICALunder attack18 Nov 2018
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RISK
open
GitHub PoC3
CVE-2018-16509 (Ghostscript contains multiple -dSAFER sandbox bypass vulnerabilities)
CVE-2018-1650917 Nov 2018
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RISK
open
GitHub PoC
Implementation of CVE-2018-10933 with CIDR block scanner
CVE-2018-10933CRITICAL16 Nov 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC
My first try to code my own LPE exploit.
CVE-2017-1117613 Nov 2018
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RISK
open
GitHub PoC9
CVE-2016-4657 web-kit vulnerability for ios 9.3, nintendo switch browser vulnerability
CVE-2016-4657HIGHunder attack11 Nov 2018
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RISK
open
GitHub PoC
Setup, exploit and patch for CVE-2009-4092 Simplog CSRF
CVE-2009-409210 Nov 2018
Cross-site request forgery (CSRF) vulnerability in user.php in Simplog 0.9.3.2, and possibly earlier, allows remote atta
23RISK
open
GitHub PoC5
CMS Made Simple 2.2.7 RCE exploit
CVE-2018-1051709 Nov 2018
In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code ex
28RISK
open
GitHub PoC1
Wordpress plugin Site-Editor v1.1.1 LFI exploit
CVE-2018-742209 Nov 2018
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RISK
open
GitHub PoC10
PHPMyAdmin v4.8.0 and v.4.8.1 LFI exploit
CVE-2018-1261309 Nov 2018
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open
GitHub PoC3
beraphin/CVE-2018-6789
CVE-2018-6789CRITICALunder attackransomware08 Nov 2018
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISK
open
GitHub PoC
matlink/CVE-2018-17456
CVE-2018-1745608 Nov 2018
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RISK
open
GitHub PoC
来自:https://www.freebuf.com/articles/web/31700.html
CVE-2014-0160HIGHunder attack08 Nov 2018
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC21
an RCE (remote command execution) approach of CVE-2018-7750
CVE-2018-775006 Nov 2018
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x
28RISK
open
GitHub PoC14
Exploit for PlaySMS 1.4 authenticated RCE
CVE-2017-910106 Nov 2018
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RISK
open
GitHub PoC
bolonobolo/CVE-2018-14665
CVE-2018-1466502 Nov 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RISK
open
GitHub PoC2
matlink/CVE-2018-17961
CVE-2018-1796101 Nov 2018
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving err
23RISK
open
GitHub PoC2
Fully functional script for brute forcing SSH and trying credentials - CVE-2018-15473
CVE-2018-15473MEDIUM31 Oct 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC80
CVE-2018-8440 standalone exploit
CVE-2018-8440HIGHunder attackransomware31 Oct 2018
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
91RISK
open
GitHub PoC
matlink/evince-cve-2017-1000083
CVE-2017-100008330 Oct 2018
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to e
50RISK
open
GitHub PoC
matlink/cve-2017-1000083-atril-nautilus
CVE-2017-100008330 Oct 2018
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to e
50RISK
open
GitHub PoC10
CVE-2018-2628漏洞工具包
CVE-2018-2628CRITICALunder attack30 Oct 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
GitHub PoC1
kastellanos/CVE-2018-7602
CVE-2018-7602CRITICALunder attackransomware29 Oct 2018
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RISK
open
GitHub PoC4
Exploit for vulnerability CVE-2018-6389 on wordpress sites
CVE-2018-638928 Oct 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISK
open
previouspage 434 / 468next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.