Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
14,080 exploits
GitHub PoC5
CVE-2017-12617 and CVE-2017-12615 for tomcat server
CVE-2017-12615HIGHunder attackransomware06 Oct 2017
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open
GitHub PoC53
Exploits for the win32kfull!bFill vulnerability on Win10 x64 RS2 using Bitmap or Palette techniques
CVE-2016-3309HIGHunder attackransomware06 Oct 2017
The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1;
76RISK
open
GitHub PoC399
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution
CVE-2017-12617HIGHunder attack05 Oct 2017
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISK
open
GitHub PoC31
Scan/Exploit Blueborne CVE-2017-0785
CVE-2017-078504 Oct 2017
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RISK
open
GitHub PoC63
Webkit uxss exploit (CVE-2017-7089)
CVE-2017-708903 Oct 2017
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud befor
23RISK
open
GitHub PoC
Usbhijacking | CVE-2017-8464
CVE-2017-8464HIGHunder attack03 Oct 2017
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RISK
open
GitHub PoC3
this script is used for hack bluetooth devices CVE 2017 0785 which was done by ARMIS This File is password protected for password contact atusha@gmail.comr
CVE-2017-078502 Oct 2017
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RISK
open
GitHub PoC2
SPRING DATA REST CVE-2017-8046 DEMO
CVE-2017-804601 Oct 2017
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISK
open
GitHub PoC3
First script, pgp-cgi-cve-2012-1823 BASH script
CVE-2012-1823CRITICALunder attack01 Oct 2017
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISK
open
GitHub PoC5
own2pwn/blueborne-CVE-2017-1000251-POC
CVE-2017-100025101 Oct 2017
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and includ
28RISK
open
GitHub PoC
billa3283/CVE-2017-0213
CVE-2017-0213HIGHunder attackransomware01 Oct 2017
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RISK
open
GitHub PoC
CVE-2017-12943
CVE-2017-1294329 Sep 2017
D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?RE
35RISK
open
GitHub PoC
clone
CVE-2017-100025128 Sep 2017
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and includ
28RISK
open
GitHub PoC19
OptionsBleed (CVE-2017-9798) PoC / Scanner
CVE-2017-979827 Sep 2017
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user
60RISK
open
GitHub PoC11
just a python script for cve-2017-12615
CVE-2017-12615HIGHunder attackransomware25 Sep 2017
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open
GitHub PoC
Check for Struts Vulnerability CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware25 Sep 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
l0n3rs/CVE-2017-9798
CVE-2017-979824 Sep 2017
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user
60RISK
open
GitHub PoC
l0n3rs/CVE-2017-8759
CVE-2017-8759HIGHunder attack24 Sep 2017
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RISK
open
GitHub PoC112
POC Exploit for Apache Tomcat 7.0.x CVE-2017-12615 PUT JSP vulnerability.
CVE-2017-12615HIGHunder attackransomware23 Sep 2017
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open
GitHub PoC18
Blueborne CVE-2017-1000251 PoC for linux machines
CVE-2017-100025123 Sep 2017
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and includ
28RISK
open
GitHub PoC
Metasploit module for Apache Struts CVE-2017-9791 Remote Code Execution Vulnerability
CVE-2017-9791CRITICALunder attack23 Sep 2017
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RISK
open
GitHub PoC40
CVE-2017-0785 BlueBorne PoC
CVE-2017-078522 Sep 2017
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RISK
open
GitHub PoC
CVE-2017-0785: BlueBorne PoC
CVE-2017-078522 Sep 2017
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RISK
open
GitHub PoC2
CVE-2017-9798
CVE-2017-979820 Sep 2017
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user
60RISK
open
GitHub PoC463
Blueborne CVE-2017-0785 Android information leak vulnerability
CVE-2017-078520 Sep 2017
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RISK
open
GitHub PoC
viethdgit/CVE-2017-0199
CVE-2017-0199HIGHunder attackransomware19 Sep 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
GitHub PoC
CVE-2017-8759
CVE-2017-8759HIGHunder attack19 Sep 2017
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RISK
open
GitHub PoC2
Two versions of CVE-2017-8759 exploits
CVE-2017-8759HIGHunder attack19 Sep 2017
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RISK
open
GitHub PoC3
Checks a shared hosting environment for CVE-2017-9798
CVE-2017-979818 Sep 2017
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user
60RISK
open
GitHub PoC11
A proof of concept for Joomla's CVE-2015-8562 vulnerability (Object Injection RCE)
CVE-2015-856217 Sep 2017
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISK
open
previouspage 451 / 470next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.