Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
14,096 exploits
GitHub PoC724
Exploit toolkit CVE-2017-0199 - v4.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test Microsoft Office RCE. It could generate a malicious RTF/PPSX file and deliver metasploit / meterpreter / other payload to victim without any complex configuration.
CVE-2017-0199HIGHunder attackransomware17 Apr 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
GitHub PoC2
homjxi0e/CVE-2017-0108
CVE-2017-010815 Apr 2017
The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 20
35RISK
open
GitHub PoC
homjxi0e/CVE-2016-7255
CVE-2016-7255HIGHunder attack15 Apr 2017
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RISK
open
GitHub PoC7
Addressbar spoofing through blob URL (Firefox browser). An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by blob: as the protocol, leading to user confusion and further spoofing attacks.
CVE-2017-541514 Apr 2017
An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leadin
28RISK
open
GitHub PoC
homjxi0e/cve-2017-7269
CVE-2017-7269CRITICALunder attack13 Apr 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC12
SyFi/cve-2017-0199
CVE-2017-0199HIGHunder attackransomware13 Apr 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
GitHub PoC
ryhanson/CVE-2017-0199
CVE-2017-0199HIGHunder attackransomware13 Apr 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
GitHub PoC213
CVE-2017-3881 Cisco Catalyst Remote Code Execution PoC
CVE-2017-3881CRITICALunder attack10 Apr 2017
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RISK
open
GitHub PoC4
Exploit for CVE-2017-6971 remote command execution in nfsen 1.3.7.
CVE-2017-697110 Apr 2017
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary comma
28RISK
open
GitHub PoC10
Strutsy - Mass exploitation of Apache Struts (CVE-2017-5638) vulnerability
CVE-2017-5638CRITICALunder attackransomware09 Apr 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC5
Ruby Exploit for IIS 6.0 Buffer Overflow (CVE-2017-7269)
CVE-2017-7269CRITICALunder attack06 Apr 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC92
iis6 exploit 2017 CVE-2017-7269
CVE-2017-7269CRITICALunder attack05 Apr 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC134
fixed msf module for cve-2017-7269
CVE-2017-7269CRITICALunder attack30 Mar 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC
Poc for iis6.0
CVE-2017-7269CRITICALunder attack30 Mar 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC
whiteHat001/cve-2017-7269picture
CVE-2017-7269CRITICALunder attack30 Mar 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC89
CVE-2017-7269 回显PoC ,用于远程漏洞检测..
CVE-2017-7269CRITICALunder attack29 Mar 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC22
An exploit for Microsoft IIS 6.0 CVE-2017-7269
CVE-2017-7269CRITICALunder attack29 Mar 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC1
exec 8 bytes command
CVE-2017-7269CRITICALunder attack29 Mar 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC2
Struts2 RCE CVE-2017-5638 CLI shell
CVE-2017-5638CRITICALunder attackransomware28 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
mcassano/cve-2017-5638
CVE-2017-5638CRITICALunder attackransomware26 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware23 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC6
k0keoyo/CVE-2017-0038-EXP-C-JS
CVE-2017-003822 Mar 2017
gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
45RISK
open
GitHub PoC
ottimo/burp-alfresco-referer-proxy-cve-2014-9301
CVE-2014-930121 Mar 2017
Server-side request forgery (SSRF) vulnerability in the proxy servlet in Alfresco Community Edition before 5.0.a allows
23RISK
open
GitHub PoC1
S2-046|S2-045: Struts 2 Remote Code Execution vulnerability(CVE-2017-5638)
CVE-2017-5638CRITICALunder attackransomware21 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC21
st2-046-poc CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware21 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC2
The DGS-1510 Websmart switch series firmware has been found to have security vulneratiblies. The vulnerabilities include unauthenticated command bypass and unauthenticated information disclosure.
CVE-2017-620620 Mar 2017
D-Link DGS-1510-28XMP, DGS-1510-28X, DGS-1510-52X, DGS-1510-52, DGS-1510-28P, DGS-1510-28, and DGS-1510-20 Websmart devi
28RISK
open
GitHub PoC1
boompig/cve-2016-6662
CVE-2016-666219 Mar 2017
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RISK
open
GitHub PoC4
CVE-2016-5195 dirtycow by timwr automated multi file patch tool
CVE-2016-5195HIGHunder attack18 Mar 2017
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC3
Apache Struts (CVE-2017-5638) Shell
CVE-2017-5638CRITICALunder attackransomware17 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC2
Struts2 RCE CVE-2017-5638 non-intrusive check shell script
CVE-2017-5638CRITICALunder attackransomware16 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
previouspage 457 / 470next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.