Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
14,096 exploits
GitHub PoC14
cve-2017-5638 Vulnerable site sample
CVE-2017-5638CRITICALunder attackransomware15 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC1
CVE-2014-0050 Vulnerable site sample
CVE-2014-005015 Mar 2017
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products,
60RISK
open
GitHub PoC83
MS16-032(CVE-2016-0099) for SERVICE ONLY
CVE-2016-0099HIGHunder attackransomware15 Mar 2017
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RISK
open
GitHub PoC3
CVE-2016-4657 for NintendoSwitch rwx
CVE-2016-4657HIGHunder attack13 Mar 2017
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RISK
open
GitHub PoC1
Example PHP Exploiter for CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware13 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC442
An exploit for Apache Struts CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware12 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC16
These are just some script which you can use to detect and exploit the Apache Struts Vulnerability (CVE-2017-5638)
CVE-2017-5638CRITICALunder attackransomware12 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC2
A php based exploiter for CVE-2017-5638.
CVE-2017-5638CRITICALunder attackransomware12 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC1
This is Valve for Tomcat7 to block Struts 2 Remote Code Execution vulnerability (CVE-2017-5638)
CVE-2017-5638CRITICALunder attackransomware11 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
CVE: 2017-5638 in different formats
CVE-2017-5638CRITICALunder attackransomware11 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC8
detection for Apache Struts recon and compromise
CVE-2017-5638CRITICALunder attackransomware11 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC2
Tweaking original PoC (https://github.com/rapid7/metasploit-framework/issues/8064) to work on self-signed certificates
CVE-2017-5638CRITICALunder attackransomware11 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
test struts2 vulnerability CVE-2017-5638 in Mac OS X
CVE-2017-5638CRITICALunder attackransomware11 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
jrrombaldo/CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware11 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC35
Demo Application and Exploit
CVE-2017-5638CRITICALunder attackransomware10 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
Telegram Bot to manage botnets created with struts vulnerability(CVE-2017-5638)
CVE-2017-5638CRITICALunder attackransomware10 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC21
Example PoC Code for CVE-2017-5638 | Apache Struts Exploit
CVE-2017-5638CRITICALunder attackransomware10 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC25
S2-045 漏洞 POC-TOOLS CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware09 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
bongbongco/cve-2017-5638
CVE-2017-5638CRITICALunder attackransomware08 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC23
Struts2 S2-045(CVE-2017-5638)Vulnerability environment - http://www.mottoin.com/97954.html
CVE-2017-5638CRITICALunder attackransomware07 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC61
Struts2 S2-045(CVE-2017-5638)Exp with GUI
CVE-2017-5638CRITICALunder attackransomware07 Mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC81
An exploit for CVE-2016-7255 on Windows 7/8/8.1/10(pre-anniversary) 64 bit
CVE-2016-7255HIGHunder attack02 Mar 2017
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RISK
open
GitHub PoC1
A brief report on CVE-2016-4117 (A vulnerability in Adobe Flash)
CVE-2016-4117HIGHunder attack23 Feb 2017
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as
100RISK
open
GitHub PoC
不完美的利用代码,只能用于学习:)
CVE-2016-466921 Feb 2017
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS b
38RISK
open
GitHub PoC
Proof of concept exploit for CVE-2012-1723
CVE-2012-1723CRITICALunder attackransomware20 Feb 2017
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 up
100RISK
open
GitHub PoC1
CVE-2017-2370
CVE-2017-237013 Feb 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RISK
open
GitHub PoC
CVE-2013-1775 Exploit written in Perl
CVE-2013-177511 Feb 2017
sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypas
38RISK
open
GitHub PoC30
This is a tool for exploiting Ticketbleed (CVE-2016-9244) vulnerability.
CVE-2016-924410 Feb 2017
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may
45RISK
open
GitHub PoC
Minion plugin for checking Ticketbleed (CVE-2016-9244)
CVE-2016-924410 Feb 2017
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may
45RISK
open
GitHub PoC1
CVE-2016-9079 exploit code as it appeared on https://lists.torproject.org/pipermail/tor-talk/2016-November/042639.html
CVE-2016-9079HIGHunder attack08 Feb 2017
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RISK
open
previouspage 458 / 470next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.