> For the complete documentation index, see [llms.txt](https://calvin-lai.gitbook.io/calvin-lai-security/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://calvin-lai.gitbook.io/calvin-lai-security/oscp-lab-and-exam/tools-for-an-offensive-certification/strategy-for-an-offensive-exam-certification/cves.md).

# CVEs

Some common CVEs "May" be useful in the exam

<table><thead><tr><th width="169.33333333333331">CVE</th><th>Descritpion</th><th>URL</th></tr></thead><tbody><tr><td>CVE-2014-6271</td><td>Shellshock PoC</td><td><a href="https://github.com/zalalov/CVE-2014-6271">https://github.com/zalalov/CVE-2014-6271</a></td></tr><tr><td>CVE-2016-5195</td><td>Dirty COW</td><td><a href="https://github.com/firefart/dirtycow">https://github.com/firefart/dirtycow</a></td></tr><tr><td>CVE-2017-0199</td><td>RTF Dynamite</td><td><a href="https://github.com/bhdresh/CVE-2017-0199">https://github.com/bhdresh/CVE-2017-0199</a></td></tr><tr><td>CVE-2018-10933</td><td>libSSH Authentication Bypass</td><td><a href="https://github.com/blacknbunny/CVE-2018-10933">https://github.com/blacknbunny/CVE-2018-10933</a></td></tr><tr><td>CVE-2018-16509</td><td>Ghostscript</td><td><a href="https://github.com/farisv/PIL-RCE-Ghostscript-CVE-2018-16509">https://github.com/farisv/PIL-RCE-Ghostscript-CVE-2018-16509</a></td></tr><tr><td>CVE-2019-18634</td><td>sudo</td><td><a href="https://github.com/saleemrashid/sudo-cve-2019-18634">https://github.com/saleemrashid/sudo-cve-2019-18634</a></td></tr><tr><td>CVE-2019-5736</td><td>Exploiting RunC</td><td><a href="https://github.com/Frichetten/CVE-2019-5736-PoC">https://github.com/Frichetten/CVE-2019-5736-PoC</a></td></tr><tr><td>CVE-2019-6447</td><td>ES File Explorer Open Port Vulnerability</td><td><a href="https://github.com/fs0c131y/ESFileExplorerOpenPortVuln">https://github.com/fs0c131y/ESFileExplorerOpenPortVuln</a></td></tr><tr><td>CVE-2019-7304</td><td>dirty_sock</td><td><a href="https://github.com/initstring/dirty_sock">https://github.com/initstring/dirty_sock</a></td></tr><tr><td>CVE-2020-1472</td><td>ZeroLogon Testing Script</td><td><a href="https://github.com/SecuraBV/CVE-2020-1472">https://github.com/SecuraBV/CVE-2020-1472</a></td></tr><tr><td>CVE-2020-1472</td><td>ZeroLogon Exploitation Script</td><td><a href="https://github.com/risksense/zerologon">https://github.com/risksense/zerologon</a></td></tr><tr><td>CVE-2021-1675,CVE-2021-34527</td><td>PrintNightmare</td><td><a href="https://github.com/nemo-wq/PrintNightmare-CVE-2021-34527">https://github.com/nemo-wq/PrintNightmare-CVE-2021-34527</a></td></tr><tr><td>CVE-2021-1675</td><td>PrintNightmare LPE (PowerShell)</td><td><a href="https://github.com/calebstewart/CVE-2021-1675">https://github.com/calebstewart/CVE-2021-1675</a></td></tr><tr><td>CVE-2021-21972</td><td>vCenter RCE</td><td><a href="https://github.com/horizon3ai/CVE-2021-21972">https://github.com/horizon3ai/CVE-2021-21972</a></td></tr><tr><td>CVE-2021-22204</td><td>GitLab Exiftool RCE</td><td><a href="https://github.com/CsEnox/Gitlab-Exiftool-RCE">https://github.com/CsEnox/Gitlab-Exiftool-RCE</a></td></tr><tr><td>CVE-2021-22204</td><td>GitLab Exiftool RCE Python Implementation</td><td><a href="https://github.com/convisolabs/CVE-2021-22204-exiftool">https://github.com/convisolabs/CVE-2021-22204-exiftool</a></td></tr><tr><td>CVE-2021-26085</td><td>Confluence Server RCE</td><td><a href="https://github.com/Phuong39/CVE-2021-26085">https://github.com/Phuong39/CVE-2021-26085</a></td></tr><tr><td>CVE-2021-27928</td><td>MariaDB/MySQL-'wsrep provider'</td><td><a href="https://github.com/Al1ex/CVE-2021-27928">https://github.com/Al1ex/CVE-2021-27928</a></td></tr><tr><td>CVE-2021-3129</td><td>Laravel Framework RCE</td><td><a href="https://github.com/nth347/CVE-2021-3129_exploit">https://github.com/nth347/CVE-2021-3129_exploit</a></td></tr><tr><td>CVE-2021-3156</td><td>Sudo 1.8.31 Root Exploit</td><td><a href="https://github.com/mohinparamasivam/Sudo-1.8.31-Root-Exploit">https://github.com/mohinparamasivam/Sudo-1.8.31-Root-Exploit</a></td></tr><tr><td>CVE-2021-3560</td><td>PwnKit C Implementation</td><td><a href="https://github.com/hakivvi/CVE-2021-3560">https://github.com/hakivvi/CVE-2021-3560</a></td></tr><tr><td>CVE-2021-3560</td><td>polkit Privilege Escalation</td><td><a href="https://github.com/Almorabea/Polkit-exploit">https://github.com/Almorabea/Polkit-exploit</a></td></tr><tr><td>CVE-2021-3560</td><td>polkit Privilege Esclation PoC</td><td><a href="https://github.com/secnigma/CVE-2021-3560-Polkit-Privilege-Esclation">https://github.com/secnigma/CVE-2021-3560-Polkit-Privilege-Esclation</a></td></tr><tr><td>CVE-2021-36934</td><td>HiveNightmare</td><td><a href="https://github.com/GossiTheDog/HiveNightmare">https://github.com/GossiTheDog/HiveNightmare</a></td></tr><tr><td>CVE-2021-4034</td><td>Pkexec Self-contained Exploit</td><td><a href="https://github.com/ly4k/PwnKit">https://github.com/ly4k/PwnKit</a></td></tr><tr><td>CVE-2021-4034</td><td>PoC for PwnKit (1)</td><td><a href="https://github.com/dzonerzy/poc-cve-2021-4034">https://github.com/dzonerzy/poc-cve-2021-4034</a></td></tr><tr><td>CVE-2021-4034</td><td>PoC for PwnKit (2)</td><td><a href="https://github.com/arthepsy/CVE-2021-4034">https://github.com/arthepsy/CVE-2021-4034</a></td></tr><tr><td>CVE-2021-4034</td><td>PoC for PwnKit (3)</td><td><a href="https://github.com/nikaiw/CVE-2021-4034">https://github.com/nikaiw/CVE-2021-4034</a></td></tr><tr><td>CVE-2021-40444</td><td>MSHTML builders</td><td><a href="https://github.com/aslitsecurity/CVE-2021-40444_builders">https://github.com/aslitsecurity/CVE-2021-40444_builders</a></td></tr><tr><td>CVE-2021-40444</td><td>MSHTML Exploit</td><td><a href="https://xret2pwn.github.io/CVE-2021-40444-Analysis-and-Exploit/">https://xret2pwn.github.io/CVE-2021-40444-Analysis-and-Exploit/</a></td></tr><tr><td>CVE-2021-40444</td><td>MSHTML PoC</td><td><a href="https://github.com/lockedbyte/CVE-2021-40444">https://github.com/lockedbyte/CVE-2021-40444</a></td></tr><tr><td>CVE-2021-41379</td><td>InstallerFileTakeOver</td><td><a href="https://github.com/klinix5/InstallerFileTakeOver">https://github.com/klinix5/InstallerFileTakeOver</a></td></tr><tr><td>CVE-2021-41773,CVE-2021-42013, CVE-2020-17519</td><td>SimplesApachePathTraversal</td><td><a href="https://github.com/MrCl0wnLab/SimplesApachePathTraversal">https://github.com/MrCl0wnLab/SimplesApachePathTraversal</a></td></tr><tr><td>CVE-2021-42278,CVE-2021-42287</td><td>sam-the-admin</td><td><a href="https://github.com/WazeHell/sam-the-admin">https://github.com/WazeHell/sam-the-admin</a></td></tr><tr><td>CVE-2021-42278</td><td>sam-the-admin Python Implementation</td><td><a href="https://github.com/ly4k/Pachine">https://github.com/ly4k/Pachine</a></td></tr><tr><td>CVE-2021-42287,CVE-2021-42278</td><td>noPac (1)</td><td><a href="https://github.com/cube0x0/noPac">https://github.com/cube0x0/noPac</a></td></tr><tr><td>CVE-2021-42287,CVE-2021-42278</td><td>noPac (2)</td><td><a href="https://github.com/Ridter/noPac">https://github.com/Ridter/noPac</a></td></tr><tr><td>CVE-2021-42321</td><td>Microsoft Exchange Server RCE</td><td><a href="https://gist.github.com/testanull/0188c1ae847f37a70fe536123d14f398">https://gist.github.com/testanull/0188c1ae847f37a70fe536123d14f398</a></td></tr><tr><td>CVE-2021-44228</td><td>Log4Shell</td><td><a href="https://github.com/kozmer/log4j-shell-poc">https://github.com/kozmer/log4j-shell-poc</a></td></tr><tr><td>CVE-2021-44228</td><td>LogMePwn</td><td><a href="https://github.com/0xInfection/LogMePwn">https://github.com/0xInfection/LogMePwn</a></td></tr><tr><td>CVE-2022-0847</td><td>DirtyPipe-Exploits</td><td><a href="https://github.com/AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits">https://github.com/AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits</a></td></tr><tr><td>CVE-2022-21999</td><td>SpoolFool</td><td><a href="https://github.com/ly4k/SpoolFool">https://github.com/ly4k/SpoolFool</a></td></tr><tr><td>CVE-2022-22963</td><td>Spring4Shell</td><td><a href="https://github.com/tweedge/springcore-0day-en">https://github.com/tweedge/springcore-0day-en</a></td></tr><tr><td>CVE-2022-23119,CVE-2022-23120</td><td>Trend Micro Deep Security Agent for Linux Arbitrary File Read</td><td><a href="https://github.com/modzero/MZ-21-02-Trendmicro">https://github.com/modzero/MZ-21-02-Trendmicro</a></td></tr><tr><td>CVE-2022-26134</td><td>ConfluentPwn</td><td><a href="https://github.com/redhuntlabs/ConfluentPwn">https://github.com/redhuntlabs/ConfluentPwn</a></td></tr><tr><td>CVE-2022-30190</td><td>MS-MSDT Follina Attach Vector</td><td><a href="https://github.com/JohnHammond/msdt-follina">https://github.com/JohnHammond/msdt-follina</a></td></tr><tr><td>CVE-2022-30190</td><td>MS-MSDT Follina Exploit PoC</td><td><a href="https://github.com/onecloudemoji/CVE-2022-30190">https://github.com/onecloudemoji/CVE-2022-30190</a></td></tr><tr><td>CVE-2022-30190</td><td>MS-MSDT Follina Exploit Python Implementation</td><td><a href="https://github.com/chvancooten/follina.py">https://github.com/chvancooten/follina.py</a></td></tr><tr><td>CVE-2022-34918</td><td>LPE Netfilter Kernel Exploit</td><td><a href="https://github.com/randorisec/CVE-2022-34918-LPE-PoC">https://github.com/randorisec/CVE-2022-34918-LPE-PoC</a></td></tr><tr><td>n/a</td><td>SeBackupPrivilege</td><td><a href="https://github.com/giuliano108/SeBackupPrivilege/tree/master/SeBackupPrivilegeCmdLets/bin/Debug">https://github.com/giuliano108/SeBackupPrivilege/tree/master/SeBackupPrivilegeCmdLets/bin/Debug</a></td></tr><tr><td>n/a</td><td>RoguePotato</td><td><a href="https://github.com/antonioCoco/RoguePotato">https://github.com/antonioCoco/RoguePotato</a></td></tr><tr><td>n/a</td><td>RottenPotatoNG</td><td><a href="https://github.com/breenmachine/RottenPotatoNG">https://github.com/breenmachine/RottenPotatoNG</a></td></tr><tr><td>n/a</td><td>GenericPotato</td><td><a href="https://github.com/micahvandeusen/GenericPotato">https://github.com/micahvandeusen/GenericPotato</a></td></tr><tr><td>n/a</td><td>JuicyPotato</td><td><a href="https://github.com/ohpe/juicy-potato">https://github.com/ohpe/juicy-potato</a></td></tr><tr><td>n/a</td><td>JuicyPotatoNG</td><td><a href="https://github.com/antonioCoco/JuicyPotatoNG">https://github.com/antonioCoco/JuicyPotatoNG</a></td></tr><tr><td>n/a</td><td>MultiPotato</td><td><a href="https://github.com/S3cur3Th1sSh1t/MultiPotato">https://github.com/S3cur3Th1sSh1t/MultiPotato</a></td></tr><tr><td>n/a</td><td>PrintSpoofer (1)</td><td><a href="https://github.com/dievus/printspoofer">https://github.com/dievus/printspoofer</a></td></tr><tr><td>n/a</td><td>PrintSpoofer (2)</td><td><a href="https://github.com/itm4n/PrintSpoofer">https://github.com/itm4n/PrintSpoofer</a></td></tr><tr><td>n/a</td><td>Shocker (1)</td><td><a href="https://github.com/gabrtv/shocker">https://github.com/gabrtv/shocker</a></td></tr><tr><td>n/a</td><td>Shocker (2)</td><td><a href="https://github.com/nccgroup/shocker">https://github.com/nccgroup/shocker</a></td></tr><tr><td>n/a</td><td>SystemNightmare</td><td><a href="https://github.com/GossiTheDog/SystemNightmare">https://github.com/GossiTheDog/SystemNightmare</a></td></tr><tr><td>n/a</td><td>PetitPotam</td><td><a href="https://github.com/topotam/PetitPotam">https://github.com/topotam/PetitPotam</a></td></tr><tr><td>n/a</td><td>DFSCoerce MS-DFSNM Exploit</td><td><a href="https://github.com/Wh04m1001/DFSCoerce">https://github.com/Wh04m1001/DFSCoerce</a></td></tr><tr><td>n/a</td><td>Windows Exploits</td><td><a href="https://github.com/SecWiki/windows-kernel-exploits">https://github.com/SecWiki/windows-kernel-exploits</a></td></tr><tr><td>n/a</td><td>Pre-compiled Windows Exploits</td><td><a href="https://github.com/abatchy17/WindowsExploits">https://github.com/abatchy17/WindowsExploits</a></td></tr></tbody></table>
