Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
14,096 exploits
GitHub PoC
Proof-of-Concept CVE-2016-0199
CVE-2016-019916 Oct 2016
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
35RISK
open
GitHub PoC1
Reproducible exploits for: CVE-2016-1240 CVE-2008-2938 CVE-2014-2064 CVE-2014-1904
CVE-2016-124013 Oct 2016
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debia
38RISK
open
GitHub PoC1
Reproducible exploits for: CVE-2016-1240 CVE-2008-2938 CVE-2014-2064 CVE-2014-1904
CVE-2008-293813 Oct 2016
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16,
60RISK
open
GitHub PoC103
OS X 10.11.6 LPE PoC for CVE-2016-4655 / CVE-2016-4656
CVE-2016-4655MEDIUMunder attack02 Oct 2016
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RISK
open
GitHub PoC27
CVE-2016-2776
CVE-2016-277630 Sep 2016
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly
60RISK
open
GitHub PoC
just some research notes
CVE-2015-386430 Sep 2016
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RISK
open
GitHub PoC
KosukeShimofuji/CVE-2016-2776
CVE-2016-277628 Sep 2016
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly
60RISK
open
GitHub PoC
whiteHat001/cve-2010-3333
CVE-2010-3333HIGHunder attack26 Sep 2016
Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2
100RISK
open
GitHub PoC3
这里保存着我学习CVE-2012-1889这个漏洞的利用所用到的文件
CVE-2012-1889HIGHunder attack25 Sep 2016
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attacker
100RISK
open
GitHub PoC163
Public repository for improvements to the EXTRABACON exploit
CVE-2016-6366HIGHunder attack20 Sep 2016
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Service
100RISK
open
GitHub PoC9
0ldSQL_MySQL_RCE_exploit.py (ver. 1.0) (CVE-2016-6662) MySQL Remote Root Code Execution / Privesc PoC Exploit For testing purposes only. Do no harm.
CVE-2016-666220 Sep 2016
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RISK
open
GitHub PoC
research CVE-2016-6662
CVE-2016-666216 Sep 2016
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RISK
open
GitHub PoC1
Simple ansible playbook to patch mysql servers against CVE-2016-6662
CVE-2016-666215 Sep 2016
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RISK
open
GitHub PoC
MySQL server CVE-2016-6662 patch playbook
CVE-2016-666214 Sep 2016
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RISK
open
GitHub PoC33
Verification tools for CVE-2016-1287
CVE-2016-128708 Sep 2016
Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0
45RISK
open
GitHub PoC2
CVE-2014-6332 ZeroDay POC - Starts PowerShell
CVE-2014-6332HIGHunder attack29 Aug 2016
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RISK
open
GitHub PoC1
linux 提权
CVE-2012-005622 Jul 2016
The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when
28RISK
open
GitHub PoC11
This is a python-based standalone exploit for CVE-2006-6184. This exploit triggers a stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote attackers to cause a denial of service or execute arbitrary code.
CVE-2006-618421 Jul 2016
Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote at
50RISK
open
GitHub PoC1
CVE-2016-3962-Exploit
CVE-2016-396217 Jul 2016
Stack-based buffer overflow in the NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTI
23RISK
open
GitHub PoC
KosukeShimofuji/CVE-2016-5734
CVE-2016-573408 Jul 2016
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to
60RISK
open
GitHub PoC1
JBoss Autopwn CVE-2010-0738 JBoss authentication bypass
CVE-2010-0738MEDIUMunder attackransomware02 Jul 2016
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RISK
open
GitHub PoC
CVE-2016-4971 written in nodejs
CVE-2016-497102 Jul 2016
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted F
35RISK
open
GitHub PoC364
Exploit that extracts Qualcomm's KeyMaster keys using CVE-2015-6639 and CVE-2016-2431
CVE-2015-663930 Jun 2016
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to
23RISK
open
GitHub PoC3
对CVE-2016-0189漏洞补丁的分析
CVE-2016-0189HIGHunder attack25 Jun 2016
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other
100RISK
open
GitHub PoC114
Proof-of-Concept exploit for CVE-2016-0189 (VBScript Memory Corruption in IE11)
CVE-2016-0189HIGHunder attack22 Jun 2016
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other
100RISK
open
GitHub PoC
CVE-2016-0051 样本库
CVE-2016-005116 Jun 2016
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RISK
open
GitHub PoC2
Docker container implementing tests for CVE-2016-2107 - LuckyNegative20
CVE-2016-210709 Jun 2016
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a
45RISK
open
GitHub PoC1
A PoC of CVE-2016-2098 (rails4.2.5.1 / view render)
CVE-2016-209807 Jun 2016
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISK
open
GitHub PoC
thejackerz/scanner-exploit-joomla-CVE-2015-8562
CVE-2015-856207 Jun 2016
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISK
open
GitHub PoC4
MySQL DoS in the Procedure Analyse Function – CVE-2015-4870
CVE-2015-487030 May 2016
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated
35RISK
open
previouspage 461 / 470next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.