Core Certified Exploits

Expert validated exploits for safe and effective pen tests

Exploit development can be an advanced penetration testing skill that takes time to master. Additionally, when on a job, pen testers often don’t have the resources to create a new exploit. Many resort to searching for and using pre-written exploits that have not been tested and must go through the timely effort of quality assurance testing in order to ensure they are secure and effective. 

Core Impact users can save time by finding all the up-to-date exploits they need in one place. We provide a robust library of exploits designed to enable pen testers to safely and efficiently conduct successful penetration tests. Whether written by our own internal team or by a third party like ExCraft, you can trust they have been thoroughly tested and validated by our experts.

Stay Informed of New Core Certified Exploits

Subscribe to receive regular email updates on new exploits available for Core Impact

 

Browse the Core Certified Exploit Library

We provide pen testers with real-time updates for a wide range of exploits for different platforms, operating systems, and applications. 

 

Search our continuously growing library to discover an exploit that will allow you to gain and retain access on the target host or application.

Title Description Date Added CVE Link Exploit Platform Exploit Type Product Name
Microsoft Windows HTTP Stack DoS This bug could allow an attacker to gain code execution on an affected system by sending specially crafted packets to a system utilizing the HTTP Protocol Stack (http.sys) to process packets. No user interaction, no privileges required, and an elevated service add up to a wormable bug. And while this is definitely more server-centric, remember that Windows clients can also run http.sys, so all affected versions are affected by this bug. Test and deploy this patch quickly.
March 18, 2022 Windows Denial of Service / Remote Impact
Apache James Log4shell Remote Code Execution Vulnerability Exploit Description: JNDI features used in configuration, log messages, and parameters present in Apache Log4j2 do not protect against attacker controlled LDAP and other JNDI related endpoints. This library, used by Apache James, allows unauthenticated attackers to execute system commands. March 17, 2022 Linux, Windows Exploits / Remote Impact
Microsoft Windows Administrator UAC Elevation Bypass Update v2 This update improves the module to bypass UAC by adding support for Windows 11. March 15, 2022 Windows Exploits / Local Impact
Linux Kernel Dirty Pipe Local Privilege Escalation Exploit Improper initialization of the flags member of the pipe buffer structure in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel, could allow an unprivileged local user to write to pages in the page cache backed by read-only files and escalate privileges on the system. March 14, 2022 Linux Exploits / Local Impact
Raspberry Pi Default Credentials Exploit Update Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain administrator privileges.

This update improves Python 3 support.
March 4, 2022 Exploits / Remote Impact
Microsoft Windows Print Spooler Elevation of Privilege Vulnerability Exploit (CVE-2022-21999) An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. February 25, 2022 Windows Exploits / Local Impact
VMware Horizon Log4shell Remote Code Execution Vulnerability Exploit JNDI features used in configuration, log messages, and parameters present in Apache Log4j2 do not protect against attacker controlled LDAP and other JNDI related endpoints. This library, used by VMware Horizon Connection Server, allows unauthenticated attackers to execute system commands. February 21, 2022 Windows Exploits / Remote Code Execution Impact
.NET Assembly Execution This update adds the capability to Windows agents of executing .net assemblies in the target's memory.

Also, a specific module to trigger SharpHound (BloodHound data Collector) is included in it.
February 18, 2022 Post Exploitation Impact
VMware vCenter Server Log4shell Remote Code Execution Vulnerability Exploit Update This update adds SSO domain name detection. February 17, 2022 Windows, Linux Exploits / Remote Code Execution Impact
Vodafone H-500-s 3.5.10 WiFi Password Disclosure Vodafone H-500-s 3.5.10 routers credential disclosure vulnerability February 9, 2022 Exploits / Client Side SCADAPRO
Oracle WebLogic Server 14.1.1.0.0 Local File Inclusion Easily exploitable vulnerability allows unauthenticated attacker with
network access via HTTP to compromise Oracle WebLogic Server.
Successful attacks of this vulnerability can result in unauthorized access
to critical data or complete access to all Oracle WebLogic Server
accessible data.

Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0.
February 9, 2022 Exploits / Remote SCADAPRO
OpenHAB 3.2.0 Authenticated Remote Code Execution Openhab Authenticated Remote Code Execution February 9, 2022 Windows, Linux Exploits / Remote Code Execution SCADAPRO
Fujitsu-Siemens ServerView Remote Command Execution ServerView has a Remote Command Execution in its Webinterface. The DBAsciiAccess CGI script provides a "ping" functionality. In the subparameter "Servername" of the parameter "Parameterlist" of this script, the IP address to be pinged is given. This IP address will be given as a parameter to the ping program without further sanitization. By adding a trailing semicolon after the IP, an attacker can add arbitrary shell commands which will be executed with the permissions of the webserver user. February 9, 2022 Exploits / Remote SCADAPRO
Standa SMCVieW Remote Code Execution Vulnerability This module will receive HTTP requests from vulnerable clients and install agents on them. February 9, 2022 Exploits / Client Side SCADA
ICPDAS NAPOPC_ST DA Server 0-Day Denial Of Service This module causes a Denial of Service in NAPOPC_ST DA Server February 9, 2022 Windows Denial of Service / Remote SCADA
Win32k Window Object Type Confusion Local Privilege Escalation The vulnerability is a win32k window object type confusion leading to an OOB (out-of-bounds) write which can be used to create arbitrary memory read and write capabilities within the Windows kernel to achieve elevated privileges. February 9, 2022 Windows Exploits / Local Impact
PolicyKit pkexec Elevation of Privilege Vulnerability Exploit A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. February 4, 2022 Linux Exploits / Local Impact
NTFS Set Short Name Checker This module allow to set a short name 8.3 of a file when you don't have write privileges to the directory where the file is located.The vulnerability exists due to NtfsSetShortNameInfo does not properly impose security restrictions in NTFS Set Short Name, which leads to security restrictions bypass and privilege escalation.

January 28, 2022 Windows Exploits / Tools Impact
WebHMI_RCE The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal,
that may be automatically processed within the product's environment or lead to arbitrary code execution.
Tested on WebHMI 4.0.7475
January 18, 2022 Exploits / Remote Code Execution SCADAPRO
Grafana 8.3.0 - Directory Traversal Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal,
allowing access to local files. The vulnerable URL path is: (grafana_host_url)/public/plugins//,
where is the plugin ID for any installed plugin.
January 18, 2022 Exploits / Remote File Disclosure SCADAPRO
DBI Technologies Studio Controls for COM Remote Code Execution Vulnerability This module will receive HTTP requests from vulnerable clients and install agents on them. January 18, 2022 Exploits / Client Side SCADAPRO
Siemens SIMATIC S7-300 CPU Remote Denial of Service Specially crafted packets may also be sent to S7-300 CPU Port 80 (default), result in a denial-of-service. January 17, 2022 Denial of Service / Remote SCADA
Keysight Communications Fabric Denial of Service Remote Denial Keysight Communications Fabric January 17, 2022 Windows Denial of Service / Remote SCADA
JatonTec Config Download Vulnerability Exploit This module exploits a download the persistent settings file. January 17, 2022 FreeBSD Exploits / Remote SCADA
IMT Analytics AG FlowAnalyser FlowLab Remote Code Execution Vulnerability This module will receive HTTP requests from vulnerable clients and install RCE exploit on them. January 17, 2022 Exploits / Client Side SCADA