Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,266GitHub PoC 14,131VulnCheck XDB 8,635Nuclei 4,274Metasploit 3,474✓ verified onlyrecentpopularrisk
14,119 exploits
GitHub PoC★ 213
CVE-2017-3881 Cisco Catalyst Remote Code Execution PoC
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RISK
open ↗GitHub PoC★ 4
Exploit for CVE-2017-6971 remote command execution in nfsen 1.3.7.
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary comma
28RISK
open ↗GitHub PoC★ 10
Strutsy - Mass exploitation of Apache Struts (CVE-2017-5638) vulnerability
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open ↗GitHub PoC★ 5
Ruby Exploit for IIS 6.0 Buffer Overflow (CVE-2017-7269)
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open ↗GitHub PoC★ 92
iis6 exploit 2017 CVE-2017-7269
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open ↗GitHub PoC★ 134
fixed msf module for cve-2017-7269
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open ↗GitHub PoC
Poc for iis6.0
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open ↗GitHub PoC
whiteHat001/cve-2017-7269picture
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open ↗GitHub PoC★ 22
An exploit for Microsoft IIS 6.0 CVE-2017-7269
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open ↗GitHub PoC★ 1
exec 8 bytes command
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open ↗GitHub PoC★ 89
CVE-2017-7269 回显PoC ,用于远程漏洞检测..
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open ↗GitHub PoC★ 2
Struts2 RCE CVE-2017-5638 CLI shell
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open ↗GitHub PoC
mcassano/cve-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open ↗GitHub PoC
CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open ↗GitHub PoC★ 6
k0keoyo/CVE-2017-0038-EXP-C-JS
gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
45RISK
open ↗GitHub PoC★ 1
S2-046|S2-045: Struts 2 Remote Code Execution vulnerability(CVE-2017-5638)
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open ↗GitHub PoC★ 21
st2-046-poc CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open ↗GitHub PoC
ottimo/burp-alfresco-referer-proxy-cve-2014-9301
Server-side request forgery (SSRF) vulnerability in the proxy servlet in Alfresco Community Edition before 5.0.a allows
23RISK
open ↗GitHub PoC★ 2
The DGS-1510 Websmart switch series firmware has been found to have security vulneratiblies. The vulnerabilities include unauthenticated command bypass and unauthenticated information disclosure.
D-Link DGS-1510-28XMP, DGS-1510-28X, DGS-1510-52X, DGS-1510-52, DGS-1510-28P, DGS-1510-28, and DGS-1510-20 Websmart devi
28RISK
open ↗GitHub PoC★ 1
boompig/cve-2016-6662
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RISK
open ↗GitHub PoC★ 4
CVE-2016-5195 dirtycow by timwr automated multi file patch tool
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open ↗GitHub PoC★ 3
Apache Struts (CVE-2017-5638) Shell
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open ↗GitHub PoC★ 2
Struts2 RCE CVE-2017-5638 non-intrusive check shell script
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open ↗GitHub PoC★ 83
MS16-032(CVE-2016-0099) for SERVICE ONLY
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RISK
open ↗GitHub PoC★ 1
CVE-2014-0050 Vulnerable site sample
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products,
60RISK
open ↗GitHub PoC★ 14
cve-2017-5638 Vulnerable site sample
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open ↗GitHub PoC★ 1
Example PHP Exploiter for CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open ↗GitHub PoC★ 3
CVE-2016-4657 for NintendoSwitch rwx
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RISK
open ↗GitHub PoC★ 442
An exploit for Apache Struts CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open ↗GitHub PoC★ 2
A php based exploiter for CVE-2017-5638.
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.