Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
14,014 exploits
GitHub PoC17
OpenBsd_CVE-2018-14665
CVE-2018-1466527 Oct 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RISK
open
GitHub PoC
ensimag-security/CVE-2018-10933
CVE-2018-10933CRITICAL25 Oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC14
CVE-2018-3245
CVE-2018-324525 Oct 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
45RISK
open
GitHub PoC172
CVE-2018-3245-PoC
CVE-2018-324524 Oct 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
45RISK
open
GitHub PoC
Multi-threaded, reliable scanner for CVE-2018-10933.
CVE-2018-10933CRITICAL24 Oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC
throwawayaccount12312312/precompiled-CVE-2018-10933
CVE-2018-10933CRITICAL24 Oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC1
A libssh CVE-2018-10933 scanner written in rust
CVE-2018-10933CRITICAL24 Oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC62
A weaponized version of CVE-2018-9206
CVE-2018-920624 Oct 2018
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISK
open
GitHub PoC17
OpenSSH 7.7 - Username Enumeration
CVE-2018-15473MEDIUM24 Oct 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC7
TALOS-2018-0684/cve-2018-4013 poc
CVE-2018-4013CRITICAL24 Oct 2018
An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server l
48RISK
open
GitHub PoC9
CVE-2018-7600 POC (Drupal RCE)
CVE-2018-7600CRITICALunder attackransomware23 Oct 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC
j0lama/CVE-2017-11882
CVE-2017-11882HIGHunder attackransomware23 Oct 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC
CVE-2018-10933
CVE-2018-10933CRITICAL23 Oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC1
CVE-2018-10933 POC (LIBSSH)
CVE-2018-10933CRITICAL23 Oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC13
A Python PoC for CVE-2018-9206
CVE-2018-920622 Oct 2018
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISK
open
GitHub PoC2
CVE-2018-10933
CVE-2018-10933CRITICAL21 Oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC3
a python script to exploit libssh authentication vulnerability
CVE-2018-10933CRITICAL21 Oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC
1-day
CVE-2018-1745621 Oct 2018
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RISK
open
GitHub PoC
pghook/CVE-2018-10933_Scanner
CVE-2018-10933CRITICAL20 Oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC11
LibSSH Authentication Bypass Exploit using RCE
CVE-2018-10933CRITICAL20 Oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC22
libssh CVE-2018-10933
CVE-2018-10933CRITICAL20 Oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC
Variant of hackerhouse-opensource/cve-2018-10933
CVE-2018-10933CRITICAL20 Oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC
cve-2018/cve-2018-10933
CVE-2018-10933CRITICAL18 Oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC110
cve-2018-10933 libssh authentication bypass
CVE-2018-10933CRITICAL18 Oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC1
likekabin/CVE-2018-10933-libSSH-Authentication-Bypass
CVE-2018-10933CRITICAL18 Oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC10
Hunt for and Exploit the libSSH Authentication Bypass (CVE-2018-10933)
CVE-2018-10933CRITICAL18 Oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC1
Exploit adapted for a specific PoC on Ubuntu 16.04.01
CVE-2017-1699518 Oct 2018
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
GitHub PoC1
Scripts to analyze conflicker worm which exploits famous netapi vulnerability (CVE-2008-4250) i.e MS08-067
CVE-2008-4250CRITICALunder attack18 Oct 2018
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISK
open
GitHub PoC
likekabin/CVE-2018-10933_ssh
CVE-2018-10933CRITICAL18 Oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC9
Proof of Concept Exploit for PrimeFaces 5.x EL Injection (CVE-2017-1000486)
CVE-2017-1000486CRITICALunder attack17 Oct 2018
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISK
open
previouspage 435 / 468next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.