Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
14,096 exploits
GitHub PoC7
Repository for CVE-2014-4936 POC code.
CVE-2014-493605 Oct 2014
The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE)
43RISK
open
GitHub PoC3
Libsafe - Safety Check Bypass Vulnerability (Proof of Concept Exploit & Time Randomization to Thwart It)
CVE-2005-112504 Oct 2014
Race condition in libsafe 2.0.16 and earlier, when running in multi-threaded applications, allows attackers to bypass li
23RISK
open
GitHub PoC11
Android app to scan for bash Vulnerability - CVE-2014-6271 also known as Shellshock
CVE-2014-6271CRITICALunder attack03 Oct 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
This module determine the vulnerability of a bash binary to the shellshock exploits (CVE-2014-6271 or CVE-2014-7169) and then patch that where possible
CVE-2014-6271CRITICALunder attack29 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC13
shellshock CVE-2014-6271 CGI Exploit, Use like Openssh via CGI
CVE-2014-6271CRITICALunder attack29 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC1
ryeyao/CVE-2014-6271_Test
CVE-2014-6271CRITICALunder attack29 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC2
CVE-2014-6271 Remote Interactive Shell - PoC Exploit
CVE-2014-6271CRITICALunder attack29 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC12
A python script to enumerate CGI scripts vulnerable to CVE-2014-6271 on one specific server
CVE-2014-6271CRITICALunder attack28 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC1
A script, in C, to check if CGI scripts are vulnerable to CVE-2014-6271 (The Bash Bug)
CVE-2014-6271CRITICALunder attack28 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
u20024804/bash-4.3-fixed-CVE-2014-6271
CVE-2014-6271CRITICALunder attack27 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
u20024804/bash-3.2-fixed-CVE-2014-6271
CVE-2014-6271CRITICALunder attack27 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
u20024804/bash-4.2-fixed-CVE-2014-6271
CVE-2014-6271CRITICALunder attack27 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
Ansible role to check the CVE-2014-6271 vulnerability
CVE-2014-6271CRITICALunder attack26 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC4
CVE-2014-6271 (ShellShock) RCE PoC tool
CVE-2014-6271CRITICALunder attack26 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
Debian Lenny Bash packages with cve-2014-6271 patches (i386 and amd64)
CVE-2014-6271CRITICALunder attack26 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC1
Salt recipe for shellshock (CVE-2014-6271)
CVE-2014-6271CRITICALunder attack26 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
scaner for cve-2014-6271
CVE-2014-6271CRITICALunder attack26 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC1
An A/V evasion armoring experiment for CVE-2012-4681
CVE-2012-4681CRITICALunder attackransomware26 Sep 2014
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow
100RISK
open
GitHub PoC
mattclegg/CVE-2014-6271
CVE-2014-6271CRITICALunder attack25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
a auto script to fix CVE-2014-6271 bash vulnerability
CVE-2014-6271CRITICALunder attack25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
Chef cookbook that will fail if bash vulnerability found per CVE-2014-6271
CVE-2014-6271CRITICALunder attack25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
Quick and dirty nessus .audit file to check is bash is vulnerable to CVE-2014-6271
CVE-2014-6271CRITICALunder attack25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC2
CVE-2014-6271 RCE tool
CVE-2014-6271CRITICALunder attack25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC1
scripts associate with bourne shell EVN function parsing vulnerability CVE-2014-6271
CVE-2014-6271CRITICALunder attack25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
CVE-2014-6271の検証用Vagrantfileです
CVE-2014-6271CRITICALunder attack25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC1
Written fro CVE-2014-6271
CVE-2014-6271CRITICALunder attack25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC46
Python Scanner for "ShellShock" (CVE-2014-6271)
CVE-2014-6271CRITICALunder attack25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
rrreeeyyy/cve-2014-6271-spec
CVE-2014-6271CRITICALunder attack25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
woltage/CVE-2014-6271
CVE-2014-6271CRITICALunder attack25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC1
Simple script to check for CVE-2014-6271
CVE-2014-6271CRITICALunder attack25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
previouspage 467 / 470next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.