Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
14,119 exploits
GitHub PoC213
CVE-2017-3881 Cisco Catalyst Remote Code Execution PoC
CVE-2017-3881CRITICALunder attack10 Apr 2017
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RISK
open
GitHub PoC4
Exploit for CVE-2017-6971 remote command execution in nfsen 1.3.7.
CVE-2017-697110 Apr 2017
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary comma
28RISK
open
GitHub PoC10
Strutsy - Mass exploitation of Apache Struts (CVE-2017-5638) vulnerability
CVE-2017-5638CRITICALunder attackransomware09 Apr 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC5
Ruby Exploit for IIS 6.0 Buffer Overflow (CVE-2017-7269)
CVE-2017-7269CRITICALunder attack06 Apr 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC92
iis6 exploit 2017 CVE-2017-7269
CVE-2017-7269CRITICALunder attack05 Apr 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC134
fixed msf module for cve-2017-7269
CVE-2017-7269CRITICALunder attack30 Mar 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC
Poc for iis6.0
CVE-2017-7269CRITICALunder attack30 Mar 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC
whiteHat001/cve-2017-7269picture
CVE-2017-7269CRITICALunder attack30 Mar 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC22
An exploit for Microsoft IIS 6.0 CVE-2017-7269
CVE-2017-7269CRITICALunder attack29 Mar 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC1
exec 8 bytes command
CVE-2017-7269CRITICALunder attack29 Mar 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC89
CVE-2017-7269 回显PoC ,用于远程漏洞检测..
CVE-2017-7269CRITICALunder attack29 Mar 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC2
Struts2 RCE CVE-2017-5638 CLI shell
CVE-2017-5638CRITICALunder attackransomware28 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
mcassano/cve-2017-5638
CVE-2017-5638CRITICALunder attackransomware26 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware23 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC6
k0keoyo/CVE-2017-0038-EXP-C-JS
CVE-2017-003822 Mar 2017
gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
45RISK
open
GitHub PoC1
S2-046|S2-045: Struts 2 Remote Code Execution vulnerability(CVE-2017-5638)
CVE-2017-5638CRITICALunder attackransomware21 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC21
st2-046-poc CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware21 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
ottimo/burp-alfresco-referer-proxy-cve-2014-9301
CVE-2014-930121 Mar 2017
Server-side request forgery (SSRF) vulnerability in the proxy servlet in Alfresco Community Edition before 5.0.a allows
23RISK
open
GitHub PoC2
The DGS-1510 Websmart switch series firmware has been found to have security vulneratiblies. The vulnerabilities include unauthenticated command bypass and unauthenticated information disclosure.
CVE-2017-620620 Mar 2017
D-Link DGS-1510-28XMP, DGS-1510-28X, DGS-1510-52X, DGS-1510-52, DGS-1510-28P, DGS-1510-28, and DGS-1510-20 Websmart devi
28RISK
open
GitHub PoC1
boompig/cve-2016-6662
CVE-2016-666219 Mar 2017
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RISK
open
GitHub PoC4
CVE-2016-5195 dirtycow by timwr automated multi file patch tool
CVE-2016-5195HIGHunder attack18 Mar 2017
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC3
Apache Struts (CVE-2017-5638) Shell
CVE-2017-5638CRITICALunder attackransomware17 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC2
Struts2 RCE CVE-2017-5638 non-intrusive check shell script
CVE-2017-5638CRITICALunder attackransomware16 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC83
MS16-032(CVE-2016-0099) for SERVICE ONLY
CVE-2016-0099HIGHunder attackransomware15 Mar 2017
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RISK
open
GitHub PoC1
CVE-2014-0050 Vulnerable site sample
CVE-2014-005015 Mar 2017
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products,
60RISK
open
GitHub PoC14
cve-2017-5638 Vulnerable site sample
CVE-2017-5638CRITICALunder attackransomware15 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC1
Example PHP Exploiter for CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware13 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC3
CVE-2016-4657 for NintendoSwitch rwx
CVE-2016-4657HIGHunder attack13 Mar 2017
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RISK
open
GitHub PoC442
An exploit for Apache Struts CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware12 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC2
A php based exploiter for CVE-2017-5638.
CVE-2017-5638CRITICALunder attackransomware12 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
previouspage 458 / 471next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.