Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
14,096 exploits
GitHub PoC
patched-bash-4.3 for CVE-2014-6271
CVE-2014-6271CRITICALunder attack24 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC6
Patch for CVE-2014-6271
CVE-2014-6271CRITICALunder attack24 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
Collected fixes for bash CVE-2014-6271
CVE-2014-6271CRITICALunder attack24 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC46
Research of CVE-2014-3153 and its famous exploit towelroot on x86
CVE-2014-3153HIGHunder attack20 Sep 2014
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISK
open
GitHub PoC19
CVE-2014-3153 exploit
CVE-2014-3153HIGHunder attack13 Sep 2014
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISK
open
GitHub PoC15
Scans NTP servers for CVE-2013-5211 NTP DDOS amplification vulnerability.
CVE-2013-521107 Sep 2014
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISK
open
GitHub PoC15
Annotated FBI exploit for the Tor Browser Bundle from mid-2013 (CVE-2013-1690)
CVE-2013-1690HIGHunder attack19 Aug 2014
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before
98RISK
open
GitHub PoC2
Technicolor TC7200 - Credentials Disclosure CVE : CVE-2014-1677
CVE-2014-167731 Jul 2014
Technicolor TC7200 with firmware STD6.01.12 could allow remote attackers to obtain sensitive information.
28RISK
open
GitHub PoC124
CVE-2014-3153 aka towelroot
CVE-2014-3153HIGHunder attack24 Jul 2014
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISK
open
GitHub PoC6
POC Code to exploite CVE-2014-3120
CVE-2014-3120HIGHunder attack07 Jul 2014
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execut
100RISK
open
GitHub PoC4
Exploit for cve-2012-3137 Oracle challenge
CVE-2012-313718 Jun 2014
The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 all
35RISK
open
GitHub PoC1
struts1 CVE-2014-0114 classLoader manipulation vulnerability patch
CVE-2014-011410 Jun 2014
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in o
60RISK
open
GitHub PoC12
A request parameter filter solution for Struts 1 CVE-2014-0114 based on the work of Alvaro Munoz and the HP Fortify team
CVE-2014-011422 May 2014
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in o
60RISK
open
GitHub PoC
SunRain/CVE-2014-0196
CVE-2014-0196MEDIUMunder attack13 May 2014
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver a
68RISK
open
GitHub PoC
Demonstration of CVE-2014-3120
CVE-2014-3120HIGHunder attack13 May 2014
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execut
100RISK
open
GitHub PoC18
cve-2014-0130 rails directory traversal vuln
CVE-2014-0130HIGHunder attack08 May 2014
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in
83RISK
open
GitHub PoC15
CVE-2014-0160 (Heartbeat Buffer over-read bug)
CVE-2014-0160HIGHunder attack03 May 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC18
Maltego transform to detect the OpenSSL Heartbleed vulnerability (CVE-2014-0160)
CVE-2014-0160HIGHunder attack01 May 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC1
CVE-2014-0094 test program for struts1
CVE-2014-009427 Apr 2014
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via t
60RISK
open
GitHub PoC4
openssl Heartbleed bug(CVE-2014-0160) check for Node.js
CVE-2014-0160HIGHunder attack19 Apr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC98
OpenSSL Heartbleed (CVE-2014-0160) vulnerability scanner, data miner and RSA key-restore tools.
CVE-2014-0160HIGHunder attack15 Apr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC3
A checker (site and tool) for CVE-2014-0160
CVE-2014-0160HIGHunder attack15 Apr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC
A checker (site and tool) for CVE-2014-0160:
CVE-2014-0160HIGHunder attack15 Apr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC
Test script for test 1Password database for SSL Hea(r)t Bleeding (CVE-2014-0160)
CVE-2014-0160HIGHunder attack13 Apr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC1
A research tool designed to check for OpenSSL CVE-2014-0160 vulnerability
CVE-2014-0160HIGHunder attack13 Apr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC
Nmap NSE script that discovers/exploits Heartbleed/CVE-2014-0160.
CVE-2014-0160HIGHunder attack13 Apr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC6
Script to find Exit and Guard nodes in the Tor Network, that are still suffering from CVE-2014-0160
CVE-2014-0160HIGHunder attack12 Apr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC5
POC for CVE-2014-0160 (Heartbleed) for DTLS
CVE-2014-0160HIGHunder attack12 Apr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC2
OpenSSL Heartbleed (CVE-2014-0160) vulnerability scanner.
CVE-2014-0160HIGHunder attack11 Apr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC
CVE-2014-0160 scanner
CVE-2014-0160HIGHunder attack11 Apr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
previouspage 468 / 470next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.