Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
IPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code Injection
CVE-2014-7169CRITICALunder attackwebappscgi01 Oct 2014
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISK
open
Exploit-DBVexDay Proof
IPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code Injection
CVE-2014-7196webappscgi01 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
IPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code Injection
CVE-2014-3659webappscgi01 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
IPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code Injection
CVE-2014-7227webappscgi01 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
IPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code Injection
CVE-2014-6271CRITICALunder attackwebappscgi01 Oct 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Exploit-DBVexDay Proof
IPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code Injection
CVE-2014-7910webappscgi01 Oct 2014
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RISK
open
Exploit-DBVexDay Proof
IPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code Injection
CVE-2014-62771webappscgi01 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
dhclient 4.1 - Bash Environment Variable Command Injection (Shellshock)
CVE-2014-7169CRITICALunder attackremotelinux29 Sep 2014
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISK
open
Exploit-DBVexDay Proof
dhclient 4.1 - Bash Environment Variable Command Injection (Shellshock)
CVE-2014-6277remotelinux29 Sep 2014
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
35RISK
open
Exploit-DBVexDay Proof
dhclient 4.1 - Bash Environment Variable Command Injection (Shellshock)
CVE-2014-7187remotelinux29 Sep 2014
Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers t
35RISK
open
Exploit-DBVexDay Proof
dhclient 4.1 - Bash Environment Variable Command Injection (Shellshock)
CVE-2014-6278HIGHunder attackremotelinux29 Sep 2014
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 8 - Fixed Col Span ID (Full ASLR + DEP + EMET 5.0 Bypass) (MS12-037)
CVE-2012-1876remotewindows29 Sep 2014
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allo
50RISK
open
Exploit-DBVexDay Proof
dhclient 4.1 - Bash Environment Variable Command Injection (Shellshock)
CVE-2014-7186remotelinux29 Sep 2014
The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial o
35RISK
open
Exploit-DBVexDay Proof
GNU Bash - 'Shellshock' Environment Variable Command Injection
CVE-2014-62771remotelinux25 Sep 2014
20RISK
open
Exploit-DBVexDay Proof
GNU Bash - 'Shellshock' Environment Variable Command Injection
CVE-2014-7169CRITICALunder attackremotelinux25 Sep 2014
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISK
open
Exploit-DBVexDay Proof
GNU Bash - 'Shellshock' Environment Variable Command Injection
CVE-2014-7196remotelinux25 Sep 2014
20RISK
open
Exploit-DBVexDay Proof
Bash - 'Shellshock' Environment Variables Command Injection
CVE-2014-7196remotelinux25 Sep 2014
20RISK
open
Exploit-DBVexDay Proof
GNU Bash - Environment Variable Command Injection (Metasploit)
CVE-2014-62771remotecgi25 Sep 2014
20RISK
open
Exploit-DBVexDay Proof
Bash - 'Shellshock' Environment Variables Command Injection
CVE-2014-7169CRITICALunder attackremotelinux25 Sep 2014
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISK
open
Exploit-DBVexDay Proof
GNU Bash - Environment Variable Command Injection (Metasploit)
CVE-2014-7169CRITICALunder attackremotecgi25 Sep 2014
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISK
open
Exploit-DBVexDay Proof
GNU Bash - Environment Variable Command Injection (Metasploit)
CVE-2014-6271CRITICALunder attackremotecgi25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Exploit-DBVexDay Proof
GNU Bash - Environment Variable Command Injection (Metasploit)
CVE-2014-7196remotecgi25 Sep 2014
20RISK
open
Exploit-DBVexDay Proof
Bash - 'Shellshock' Environment Variables Command Injection
CVE-2014-3671remotelinux25 Sep 2014
20RISK
open
Exploit-DBVexDay Proof
OSClass 3.4.1 - 'index.php' Local File Inclusion
CVE-2014-6308webappsphp25 Sep 2014
Directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a .. (dot
43RISK
open
Exploit-DBVexDay Proof
GNU Bash - Environment Variable Command Injection (Metasploit)
CVE-2014-3671remotecgi25 Sep 2014
20RISK
open
Exploit-DBVexDay Proof
GNU Bash - 'Shellshock' Environment Variable Command Injection
CVE-2014-3659remotelinux25 Sep 2014
20RISK
open
Exploit-DBVexDay Proof
Bash - 'Shellshock' Environment Variables Command Injection
CVE-2014-3659remotelinux25 Sep 2014
20RISK
open
Exploit-DBVexDay Proof
GNU Bash - Environment Variable Command Injection (Metasploit)
CVE-2014-3659remotecgi25 Sep 2014
20RISK
open
Exploit-DBVexDay Proof
Bash - 'Shellshock' Environment Variables Command Injection
CVE-2014-6271CRITICALunder attackremotelinux25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Exploit-DBVexDay Proof
GNU Bash - 'Shellshock' Environment Variable Command Injection
CVE-2014-6271CRITICALunder attackremotelinux25 Sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.