Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,175GitHub PoC 14,096VulnCheck XDB 8,607Nuclei 4,255Metasploit 3,474✓ verified onlyrecentpopularrisk
14,096 exploits
GitHub PoC★ 4
paralelo14/CVE-2015-1579
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitra
43RISK
open ↗GitHub PoC★ 4
Go Exploit for CVE-2011-4862
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RISK
open ↗GitHub PoC
Ian Beer's exploit for CVE-2017-2370 (kernel memory r/w on iOS 10.2)
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RISK
open ↗GitHub PoC
OpenSSL CVE-2017-3730 proof-of-concept
Bad (EC)DHE parameters cause a client crash
35RISK
open ↗GitHub PoC
CVE-2015-1635
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open ↗GitHub PoC
vagrant box exploiting cve-2016-0728
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISK
open ↗GitHub PoC
Ian Beer's exploit for CVE-2017-2370 (kernel memory r/w on iOS 10.2) https://bugs.chromium.org/p/project-zero/issues/detail?id=1004
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RISK
open ↗GitHub PoC
Pilou-Pilou/docker_CVE-2014-6271.
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗GitHub PoC★ 1
Proof of concept CVE-2016-2098
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISK
open ↗GitHub PoC★ 271
CVE-2016-5195 (Dirty COW) PoC for Android 6.0.1 Marshmallow
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open ↗GitHub PoC★ 1
cve-2009-3103
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISK
open ↗GitHub PoC★ 3
Android APK Based On Public Information Using DirtyCOW CVE-2016-5195 Exploit
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open ↗GitHub PoC
sribaba/android-CVE-2016-5195
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open ↗GitHub PoC★ 3
heh3/CVE-2016-7255
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RISK
open ↗GitHub PoC★ 4
Proof-of-concept exploit for CVE-2016-1827 on OS X Yosemite.
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RISK
open ↗GitHub PoC★ 32
Elasticsearch 1.4.0 < 1.4.2 Remote Code Execution exploit and vulnerable container
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RISK
open ↗GitHub PoC★ 4
Joomla 1.5 - 3.4.5 Object Injection RCE X-Forwarded-For header
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISK
open ↗GitHub PoC★ 151
ProFTPd 1.3.5 - (mod_copy) Remote Command Execution exploit and vulnerable container
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISK
open ↗GitHub PoC★ 140
Proof-of-Concept exploit for Edge bugs (CVE-2016-7200 & CVE-2016-7201)
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RISK
open ↗GitHub PoC
Script to take advantage of CVE-2010-3847
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not pro
38RISK
open ↗GitHub PoC★ 8
Prevent PHP vulnerabilities similar to CVE-2016-10033 and CVE-2016-10045.
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open ↗GitHub PoC★ 408
PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open ↗GitHub PoC★ 2
k0keoyo/CVE-2012-0003_eXP
Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows
68RISK
open ↗GitHub PoC★ 66
Local privilege escalation through macOS 10.12.1 via CVE-2016-1825 or CVE-2016-7617.
IOHIDFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a d
23RISK
open ↗GitHub PoC★ 20
CVE-2013-6282 proof of concept for Android
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not
98RISK
open ↗GitHub PoC★ 12
Android attempt at PoC CVE-2016-8655
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cau
43RISK
open ↗GitHub PoC★ 5
McAfee Virus Scan for Linux multiple remote flaws (CVE 2016-8016, CVE 2016-8017, CVE 2016-8018, CVE 2016-8019, CVE 2016-8020, CVE 2016-8021, CVE 2016-8022, CVE 2016-8023, CVE 2016-8024, CVE 2016-8025)
Information exposure in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote
23RISK
open ↗GitHub PoC★ 53
OpenSSH remote DOS exploit and vulnerable container
The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password a
35RISK
open ↗GitHub PoC
Linux af_packet.c race condition (local root)
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cau
43RISK
open ↗GitHub PoC
Chocobo Root (CVE-2016-8655) Analysis
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cau
43RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.