Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
14,080 exploits
GitHub PoC
Cisco iOS SNMP Overflow Exploit Toolkit (CVE-2017-6736)
CVE-2017-6736HIGHunder attack01 Mar 2018
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabiliti
93RISK
open
GitHub PoC2
CVE-2018-6389 WordPress Core - 'load-scripts.php' Denial of Service <= 4.9.4
CVE-2018-638901 Mar 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISK
open
GitHub PoC4
Source code and configuration files related to our article in MISC96
CVE-2017-512301 Mar 2018
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RISK
open
GitHub PoC1
cve-2017-10271
CVE-2017-10271HIGHunder attackransomware01 Mar 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC1
This is a sort of Java porting of the Python exploit at: https://www.exploit-db.com/exploits/41570/.
CVE-2017-5638CRITICALunder attackransomware28 Feb 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
alessiogilardi/PoC---CVE-2018-6389
CVE-2018-638928 Feb 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISK
open
GitHub PoC82
A sandbox escape based on the proof-of-concept (CVE-2018-4087) by Rani Idan (Zimperium)
CVE-2018-408728 Feb 2018
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchO
23RISK
open
GitHub PoC
BlackRouter/cve-2018-6389
CVE-2018-638926 Feb 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISK
open
GitHub PoC
MaxSecurity/Office-CVE-2017-8570
CVE-2017-8570HIGHunder attack26 Feb 2018
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RISK
open
GitHub PoC
Proof of Concept of vunerability CVE-2018-6389 on Wordpress 4.9.2
CVE-2018-638925 Feb 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISK
open
GitHub PoC
CVE-2018-4878 样本
CVE-2018-4878HIGHunder attackransomware23 Feb 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISK
open
GitHub PoC1
RavSS/Bluetooth-Crash-CVE-2017-0785
CVE-2017-078521 Feb 2018
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RISK
open
GitHub PoC59
CVE-2018-4087 PoC
CVE-2018-408721 Feb 2018
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchO
23RISK
open
GitHub PoC3
HanseSecure/CVE-2009-1437
CVE-2009-143719 Feb 2018
Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.6 and earlier allows rem
28RISK
open
GitHub PoC1
Wordpress Username Enumeration /CVE-2017-5487,WordPress < 4.7.1 -
CVE-2017-548717 Feb 2018
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RISK
open
GitHub PoC1
Containerized exploitable PhpCollab
CVE-2017-609017 Feb 2018
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authentica
60RISK
open
GitHub PoC29
CVE-2009-2698 compiled for CentOS 4.8
CVE-2009-269816 Feb 2018
The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel befo
23RISK
open
GitHub PoC6
Struts02 s2-045 exploit program
CVE-2017-5638CRITICALunder attackransomware15 Feb 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
Global Fix for Wordpress CVE-2018-6389
CVE-2018-638915 Feb 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISK
open
GitHub PoC3
CVE-2015-5374 Denial of Service PoC
CVE-2015-537414 Feb 2018
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01;
60RISK
open
GitHub PoC9
ChakraCore exploitation techniques
CVE-2016-719013 Feb 2018
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of se
35RISK
open
GitHub PoC86
Aggressor Script to launch IE driveby for CVE-2018-4878
CVE-2018-4878HIGHunder attackransomware10 Feb 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISK
open
GitHub PoC6
PHPMailer < 5.2.18 Remote Code Execution Exploit
CVE-2016-10033CRITICALunder attack09 Feb 2018
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
GitHub PoC16
Ruby On Rails unrestricted render() exploit
CVE-2016-209809 Feb 2018
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISK
open
GitHub PoC23
mdsecactivebreach/CVE-2018-4878
CVE-2018-4878HIGHunder attackransomware09 Feb 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISK
open
GitHub PoC
Aggressor Script to just launch IE driveby for CVE-2018-4878
CVE-2018-4878HIGHunder attackransomware09 Feb 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISK
open
GitHub PoC2
Metasploit module for WordPress DOS load-scripts.php CVE-2018-638
CVE-2018-638909 Feb 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISK
open
GitHub PoC
Code put together from a few peoples ideas credit given don't use maliciously please
CVE-2017-12617HIGHunder attack09 Feb 2018
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISK
open
GitHub PoC8
Exploit for CVE-2017-11826
CVE-2017-11826HIGHunder attack09 Feb 2018
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Serv
93RISK
open
GitHub PoC2
Modification of Metasploit module for RCE in Ruby-On-Rails Console CVE-2015-3224
CVE-2015-322408 Feb 2018
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RISK
open
previouspage 446 / 470next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.