Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
14,096 exploits
GitHub PoC4
paralelo14/CVE-2015-1579
CVE-2015-157903 Feb 2017
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitra
43RISK
open
GitHub PoC4
Go Exploit for CVE-2011-4862
CVE-2011-486202 Feb 2017
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RISK
open
GitHub PoC
Ian Beer's exploit for CVE-2017-2370 (kernel memory r/w on iOS 10.2)
CVE-2017-237002 Feb 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RISK
open
GitHub PoC
OpenSSL CVE-2017-3730 proof-of-concept
CVE-2017-373030 Jan 2017
Bad (EC)DHE parameters cause a client crash
35RISK
open
GitHub PoC
CVE-2015-1635
CVE-2015-1635CRITICALunder attack28 Jan 2017
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open
GitHub PoC
vagrant box exploiting cve-2016-0728
CVE-2016-072827 Jan 2017
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISK
open
GitHub PoC
Ian Beer's exploit for CVE-2017-2370 (kernel memory r/w on iOS 10.2) https://bugs.chromium.org/p/project-zero/issues/detail?id=1004
CVE-2017-237026 Jan 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RISK
open
GitHub PoC
Pilou-Pilou/docker_CVE-2014-6271.
CVE-2014-6271CRITICALunder attack25 Jan 2017
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC1
Proof of concept CVE-2016-2098
CVE-2016-209825 Jan 2017
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISK
open
GitHub PoC271
CVE-2016-5195 (Dirty COW) PoC for Android 6.0.1 Marshmallow
CVE-2016-5195HIGHunder attack20 Jan 2017
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC1
cve-2009-3103
CVE-2009-310317 Jan 2017
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISK
open
GitHub PoC3
Android APK Based On Public Information Using DirtyCOW CVE-2016-5195 Exploit
CVE-2016-5195HIGHunder attack16 Jan 2017
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC
sribaba/android-CVE-2016-5195
CVE-2016-5195HIGHunder attack15 Jan 2017
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC3
heh3/CVE-2016-7255
CVE-2016-7255HIGHunder attack13 Jan 2017
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RISK
open
GitHub PoC4
Proof-of-concept exploit for CVE-2016-1827 on OS X Yosemite.
CVE-2016-182710 Jan 2017
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RISK
open
GitHub PoC32
Elasticsearch 1.4.0 < 1.4.2 Remote Code Execution exploit and vulnerable container
CVE-2015-1427CRITICALunder attack09 Jan 2017
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RISK
open
GitHub PoC4
Joomla 1.5 - 3.4.5 Object Injection RCE X-Forwarded-For header
CVE-2015-856208 Jan 2017
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISK
open
GitHub PoC151
ProFTPd 1.3.5 - (mod_copy) Remote Command Execution exploit and vulnerable container
CVE-2015-330608 Jan 2017
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISK
open
GitHub PoC140
Proof-of-Concept exploit for Edge bugs (CVE-2016-7200 & CVE-2016-7201)
CVE-2016-7200HIGHunder attack04 Jan 2017
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RISK
open
GitHub PoC
Script to take advantage of CVE-2010-3847
CVE-2010-384702 Jan 2017
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not pro
38RISK
open
GitHub PoC8
Prevent PHP vulnerabilities similar to CVE-2016-10033 and CVE-2016-10045.
CVE-2016-10033CRITICALunder attack29 Dec 2016
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
GitHub PoC408
PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container
CVE-2016-10033CRITICALunder attack26 Dec 2016
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
GitHub PoC2
k0keoyo/CVE-2012-0003_eXP
CVE-2012-0003HIGH26 Dec 2016
Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows
68RISK
open
GitHub PoC66
Local privilege escalation through macOS 10.12.1 via CVE-2016-1825 or CVE-2016-7617.
CVE-2016-182525 Dec 2016
IOHIDFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a d
23RISK
open
GitHub PoC20
CVE-2013-6282 proof of concept for Android
CVE-2013-6282HIGHunder attack19 Dec 2016
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not
98RISK
open
GitHub PoC12
Android attempt at PoC CVE-2016-8655
CVE-2016-865517 Dec 2016
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cau
43RISK
open
GitHub PoC5
McAfee Virus Scan for Linux multiple remote flaws (CVE 2016-8016, CVE 2016-8017, CVE 2016-8018, CVE 2016-8019, CVE 2016-8020, CVE 2016-8021, CVE 2016-8022, CVE 2016-8023, CVE 2016-8024, CVE 2016-8025)
CVE-2016-801613 Dec 2016
Information exposure in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote
23RISK
open
GitHub PoC53
OpenSSH remote DOS exploit and vulnerable container
CVE-2016-651509 Dec 2016
The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password a
35RISK
open
GitHub PoC
Linux af_packet.c race condition (local root)
CVE-2016-865509 Dec 2016
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cau
43RISK
open
GitHub PoC
Chocobo Root (CVE-2016-8655) Analysis
CVE-2016-865509 Dec 2016
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cau
43RISK
open
previouspage 459 / 470next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.