Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,866cataloged exploits
35,812CVEs with public exploitation
24,695lab-tested
77,772 exploits
VulnCheck XDB
initial-access
CVE-2022-3137419 May 2022
An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute
23RISK
open
GitHub PoC1
CVE-2022-22965 Spring4Shell research & PoC
CVE-2022-22965CRITICALunder attack19 May 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC6
Verifed Proof of Concept on CVE-2022-24086
CVE-2022-24086CRITICALunder attack19 May 2022
Adobe Commerce checkout improper input validation leads to remote code execution
100RISK
open
GitHub PoC2
Simple python script to exploit CVE-2022-30525 (FIXED): Zyxel Firewall Unauthenticated Remote Command Injection
CVE-2022-30525CRITICALunder attack18 May 2022
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RISK
open
GitHub PoC
Franklin Fueling Systems Colibri Controller Module - Local File Inclusion
CVE-2021-4641718 May 2022
Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privilege
50RISK
open
VulnCheck XDB
initial-access
CVE-2021-4641718 May 2022
Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privilege
50RISK
open
VulnCheck XDB
initial-access
CVE-2020-4450CRITICAL18 May 2022
IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the
60RISK
open
GitHub PoC1
The Repository contains documents that explains the explotation of CVE-2016-5195
CVE-2016-5195HIGHunder attack18 May 2022
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALunder attackransomware17 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
VulnCheck XDB
info-leak
CVE-2021-4082217 May 2022
GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.
43RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack17 May 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
Exploit-DB
Showdoc 2.10.3 - Stored Cross-Site Scripting (XSS)
CVE-2022-0967MEDIUMwebappsphp17 May 2022
Stored XSS via File Upload in star7th/showdoc in star7th/showdoc in star7th/showdoc
33RISK
open
GitHub PoC2
CVE-2022-1388 F5 BIG-IP iControl REST Auth Bypass RCE written in Rust
CVE-2022-1388CRITICALunder attackransomware17 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
Exploit-DB
SolarView Compact 6.0 - OS Command Injection
CVE-2022-29303CRITICALunder attackremotehardware17 May 2022
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
100RISK
open
Exploit-DB
Survey Sparrow Enterprise Survey Software 2022 - Stored Cross-Site Scripting (XSS)
CVE-2022-29727webappsmultiple17 May 2022
Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup param
23RISK
open
Exploit-DB
SDT-CW3B1 1.1.0 - OS Command Injection
CVE-2021-46422remotehardware17 May 2022
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RISK
open
GitHub PoC2
This repository is developed to analysis and understand DirtyPipe exploit CVE-2022-0847
CVE-2022-0847HIGHunder attack17 May 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC60
Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947) 注入哥斯拉内存马
CVE-2022-22947CRITICALunder attack16 May 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC
Wrin9/CVE-2022-1388
CVE-2022-1388CRITICALunder attackransomware16 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC1
Multithread Golang application
CVE-2022-21907CRITICAL16 May 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
GitHub PoC1
CVE-2022-30525 POC exploit
CVE-2022-30525CRITICALunder attack16 May 2022
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RISK
open
GitHub PoC
Persistent XSS on 'last_known_version' field (My Settings)
CVE-2022-2859816 May 2022
Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-contro
23RISK
open
Metasploit600
Gitea Git Fetch Remote Code Execution
CVE-2022-3078116 May 2022
Gitea before 1.16.7 does not escape git fetch remote.
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALunder attackransomware16 May 2022
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
VulnCheck XDB
client-side
CVE-2022-22947CRITICALunder attack16 May 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-30525CRITICALunder attack16 May 2022
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RISK
open
GitHub PoC
user16-et/cve-2021-21972_PoC
CVE-2021-21972CRITICALunder attackransomware16 May 2022
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
GitHub PoC3
CVE-2022-30525(Zxyel 防火墙命令注入)的概念证明漏洞利用
CVE-2022-30525CRITICALunder attack16 May 2022
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RISK
open
GitHub PoC11
A bots loader for CVE-2022-29464 with multithreading
CVE-2022-29464CRITICALunder attackransomware15 May 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC1
MyBB 1.8.29 - Remote Code Execution
CVE-2022-24734HIGH15 May 2022
Remote code execution in mybb
78RISK
open
previouspage 578 / 2,593next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.