Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
14,096 exploits
GitHub PoC4
CVE-2017-8779 aka RPCBomb
CVE-2017-877909 May 2017
rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider t
60RISK
open
GitHub PoC3
simple python poc for CVE-2017-5689
CVE-2017-5689CRITICALunder attack09 May 2017
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Mana
100RISK
open
GitHub PoC20
cyberheartmi9/CVE-2017-8295
CVE-2017-829506 May 2017
WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for re
28RISK
open
GitHub PoC2
a plugin that protects your wp site from the CVE-2017-8295 vulnerability
CVE-2017-829505 May 2017
WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for re
28RISK
open
GitHub PoC8
Apache Struts 2.0 RCE vulnerability - Allows an attacker to inject OS commands into a web application through the content-type header
CVE-2017-5638CRITICALunder attackransomware05 May 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
homjxi0e/CVE-2017-8295-WordPress-4.7.4---Unauthorized-Password-Reset
CVE-2017-829504 May 2017
WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for re
28RISK
open
GitHub PoC39
CerberusSecurity/CVE-2017-5689
CVE-2017-5689CRITICALunder attack04 May 2017
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Mana
100RISK
open
GitHub PoC2
RedDot CMS versions 7.5 Build 7.5.0.48 and below full database enumeration exploit that takes advantage of a remote SQL injection vulnerability in ioRD.asp.
CVE-2008-161303 May 2017
SQL injection vulnerability in ioRD.asp in RedDot CMS 7.5 Build 7.5.0.48, and possibly other versions including 6.5 and
23RISK
open
GitHub PoC3
Microsoft SQL Server sp_replwritetovarbin Memory Corruption via SQL Injection
CVE-2008-541603 May 2017
Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop
60RISK
open
GitHub PoC
homjxi0e/CVE-2017-3881-Cisco
CVE-2017-3881CRITICALunder attack02 May 2017
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RISK
open
GitHub PoC29
From SQL injection to root shell with CVE-2016-6662 by MaYaSeVeN
CVE-2016-666201 May 2017
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RISK
open
GitHub PoC4
Shellshock POC | CVE-2014-6271 | cgi-bin reverse shell
CVE-2014-6271CRITICALunder attack30 Apr 2017
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
A rebuilt version of the exploit for CVE-2016-1542 and CVE-2016-1543 from insinuator.net
CVE-2016-154227 Apr 2017
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and U
60RISK
open
GitHub PoC83
CVE-2020-8012, CVE-2016-10709, CVE-2017-17099, CVE-2017-18047, CVE-2019-1003000, CVE-2018-1999002
CVE-2020-801226 Apr 2017
CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerabi
60RISK
open
GitHub PoC83
CVE-2020-8012, CVE-2016-10709, CVE-2017-17099, CVE-2017-18047, CVE-2019-1003000, CVE-2018-1999002
CVE-2018-199900226 Apr 2017
A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framewor
45RISK
open
GitHub PoC83
CVE-2020-8012, CVE-2016-10709, CVE-2017-17099, CVE-2017-18047, CVE-2019-1003000, CVE-2018-1999002
CVE-2019-100300026 Apr 2017
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISK
open
GitHub PoC
joke998/Cve-2017-0199
CVE-2017-0199HIGHunder attackransomware25 Apr 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
GitHub PoC
Cve-2017-0199
CVE-2017-0199HIGHunder attackransomware25 Apr 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
GitHub PoC2
An exploit implementation for RCE in RTF & DOCs (CVE-2017-0199)
CVE-2017-0199HIGHunder attackransomware24 Apr 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
GitHub PoC
CVE-2017-7269
CVE-2017-7269CRITICALunder attack24 Apr 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC2
Exploit toolkit CVE-2017-0199 - v2.0 is a handy python script which provides a quick and effective way to exploit Microsoft RTF RCE. It could generate a malicious RTF file and deliver metasploit / meterpreter payload to victim without any complex configuration.
CVE-2017-0199HIGHunder attackransomware23 Apr 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
GitHub PoC2
Exploit toolkit for vulnerability RCE Microsoft RTF
CVE-2017-0199HIGHunder attackransomware22 Apr 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
GitHub PoC7
Exploit toolkit CVE-2017-0199 - v2.0 is a handy python script which provides a quick and effective way to exploit Microsoft RTF RCE. It could generate a malicious RTF file and deliver metasploit / meterpreter / any other payload to victim without any complex configuration.
CVE-2017-0199HIGHunder attackransomware22 Apr 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
GitHub PoC2
homjxi0e/CVE-2017-3881-exploit-cisco-
CVE-2017-3881CRITICALunder attack20 Apr 2017
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RISK
open
GitHub PoC4
phpMyAdmin 3.3.X and 3.4.X - Local File Inclusion
CVE-2011-410719 Apr 2017
The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7
28RISK
open
GitHub PoC16
CVE-2017-0199
CVE-2017-0199HIGHunder attackransomware19 Apr 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
GitHub PoC13
Quick and dirty fix to OLE2 executing code via .hta
CVE-2017-0199HIGHunder attackransomware18 Apr 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
GitHub PoC1
CVE-2011-3368 exploit code
CVE-2011-336818 Apr 2017
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does
60RISK
open
GitHub PoC
Exploit developed by me for CVE-2017-5633.
CVE-2017-563318 Apr 2017
Multiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow
23RISK
open
GitHub PoC23
Proof of concept exploit for CVE-2017-3599
CVE-2017-359918 Apr 2017
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions t
45RISK
open
previouspage 456 / 470next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.