Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
14,119 exploits
GitHub PoC442
An exploit for Apache Struts CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware12 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
CVE: 2017-5638 in different formats
CVE-2017-5638CRITICALunder attackransomware11 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC8
detection for Apache Struts recon and compromise
CVE-2017-5638CRITICALunder attackransomware11 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
jrrombaldo/CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware11 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC1
This is Valve for Tomcat7 to block Struts 2 Remote Code Execution vulnerability (CVE-2017-5638)
CVE-2017-5638CRITICALunder attackransomware11 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC2
Tweaking original PoC (https://github.com/rapid7/metasploit-framework/issues/8064) to work on self-signed certificates
CVE-2017-5638CRITICALunder attackransomware11 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
test struts2 vulnerability CVE-2017-5638 in Mac OS X
CVE-2017-5638CRITICALunder attackransomware11 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC21
Example PoC Code for CVE-2017-5638 | Apache Struts Exploit
CVE-2017-5638CRITICALunder attackransomware10 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC35
Demo Application and Exploit
CVE-2017-5638CRITICALunder attackransomware10 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
Telegram Bot to manage botnets created with struts vulnerability(CVE-2017-5638)
CVE-2017-5638CRITICALunder attackransomware10 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC25
S2-045 漏洞 POC-TOOLS CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware09 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
bongbongco/cve-2017-5638
CVE-2017-5638CRITICALunder attackransomware08 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC61
Struts2 S2-045(CVE-2017-5638)Exp with GUI
CVE-2017-5638CRITICALunder attackransomware07 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC23
Struts2 S2-045(CVE-2017-5638)Vulnerability environment - http://www.mottoin.com/97954.html
CVE-2017-5638CRITICALunder attackransomware07 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC81
An exploit for CVE-2016-7255 on Windows 7/8/8.1/10(pre-anniversary) 64 bit
CVE-2016-7255HIGHunder attack02 Mar 2017
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RISK
open
GitHub PoC1
A brief report on CVE-2016-4117 (A vulnerability in Adobe Flash)
CVE-2016-4117HIGHunder attack23 Feb 2017
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as
100RISK
open
GitHub PoC
不完美的利用代码,只能用于学习:)
CVE-2016-466921 Feb 2017
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS b
38RISK
open
GitHub PoC
Proof of concept exploit for CVE-2012-1723
CVE-2012-1723CRITICALunder attackransomware20 Feb 2017
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 up
100RISK
open
GitHub PoC1
CVE-2017-2370
CVE-2017-237013 Feb 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RISK
open
GitHub PoC
CVE-2013-1775 Exploit written in Perl
CVE-2013-177511 Feb 2017
sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypas
38RISK
open
GitHub PoC30
This is a tool for exploiting Ticketbleed (CVE-2016-9244) vulnerability.
CVE-2016-924410 Feb 2017
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may
45RISK
open
GitHub PoC
Minion plugin for checking Ticketbleed (CVE-2016-9244)
CVE-2016-924410 Feb 2017
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may
45RISK
open
GitHub PoC1
CVE-2016-9079 exploit code as it appeared on https://lists.torproject.org/pipermail/tor-talk/2016-November/042639.html
CVE-2016-9079HIGHunder attack08 Feb 2017
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RISK
open
GitHub PoC4
paralelo14/CVE-2015-1579
CVE-2015-157903 Feb 2017
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitra
43RISK
open
GitHub PoC
Ian Beer's exploit for CVE-2017-2370 (kernel memory r/w on iOS 10.2)
CVE-2017-237002 Feb 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RISK
open
GitHub PoC4
Go Exploit for CVE-2011-4862
CVE-2011-486202 Feb 2017
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RISK
open
GitHub PoC
OpenSSL CVE-2017-3730 proof-of-concept
CVE-2017-373030 Jan 2017
Bad (EC)DHE parameters cause a client crash
35RISK
open
GitHub PoC
CVE-2015-1635
CVE-2015-1635CRITICALunder attack28 Jan 2017
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open
GitHub PoC
vagrant box exploiting cve-2016-0728
CVE-2016-072827 Jan 2017
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISK
open
GitHub PoC
Ian Beer's exploit for CVE-2017-2370 (kernel memory r/w on iOS 10.2) https://bugs.chromium.org/p/project-zero/issues/detail?id=1004
CVE-2017-237026 Jan 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RISK
open
previouspage 459 / 471next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.