Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
77,772 exploits
GitHub PoC
Proof-of-concept exploit for CVE-2016-1827 on OS X Yosemite.
CVE-2016-182704 Apr 2022
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RISK
open
VulnCheck XDB
denial-of-service
CVE-2022-21907CRITICAL04 Apr 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
GitHub PoC2
Spring Cloud Function SpEL - cve-2022-22963
CVE-2022-22963CRITICALunder attack03 Apr 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-40438CRITICALunder attackransomware03 Apr 2022
mod_proxy SSRF
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack03 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-21975HIGHunder attackransomware03 Apr 2022
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2017-950603 Apr 2022
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-21551HIGHunder attack03 Apr 2022
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RISK
open
GitHub PoC8
Nmap Spring4Shell NSE script for Spring Boot RCE (CVE-2022-22965)
CVE-2022-22965CRITICALunder attack03 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC
Linux “Dirty Pipe” vulnerability gives unprivileged users root access
CVE-2022-0847HIGHunder attack03 Apr 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC16
Docker PoC for CVE-2022-22965 with Spring Boot version 2.6.5
CVE-2022-22965CRITICALunder attack03 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC
mwojterski/cve-2022-22965
CVE-2022-22965CRITICALunder attack02 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC
Local privilege escalation for OS X 10.10.5 via CVE-2016-1828.
CVE-2016-182802 Apr 2022
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RISK
open
GitHub PoC16
CVE-2022-22965\Spring-Core-RCE堪比关于 Apache Log4j2核弹级别漏洞exp的rce一键利用
CVE-2022-22965CRITICALunder attack02 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC4
ShellShock interactive-shell exploit
CVE-2014-6271CRITICALunder attack02 Apr 2022
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC7
CVE-2022-22965 POC
CVE-2022-22965CRITICALunder attack02 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC18
ActiveMQ系列漏洞探测利用工具,包括ActiveMQ 默认口令漏洞及ActiveMQ任意文件写入漏洞(CVE-2016-3088),支持批量探测利用。
CVE-2016-3088CRITICALunder attack02 Apr 2022
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open
GitHub PoC10
tess-ss/SAP-memory-pipes-desynchronization-vulnerability-MPI-CVE-2022-22536
CVE-2022-22536CRITICALunder attack02 Apr 2022
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RISK
open
GitHub PoC7
DirtyPipe: Exploit for a new Linux vulnerability known as 'Dirty Pipe(CVE-2022-0847)' allows local users to gain root privileges. The vulnerability is tracked as CVE-2022-0847 and allows a non-privileged user to inject and overwrite data in read-only files, including SUID processes that run as root.
CVE-2022-0847HIGHunder attack02 Apr 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack02 Apr 2022
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack02 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
infoleak
CVE-2022-23131CRITICALunder attack02 Apr 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALunder attackransomware02 Apr 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC11
CVE-2022-23131漏洞利用工具开箱即用。
CVE-2022-23131CRITICALunder attack02 Apr 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISK
open
GitHub PoC
Environment for CVE-2021-41773 recreation.
CVE-2021-41773HIGHunder attackransomware02 Apr 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
Metasploit400
ALLMediaServer 1.6 SEH Buffer Overflow
CVE-2022-2838101 Apr 2022
Mediaserver.exe in ALLMediaServer 1.6 has a stack-based buffer overflow that allows remote attackers to execute arbitrar
30RISK
open
GitHub PoC1
lcarea/CVE-2022-22965
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC1
helsecert/CVE-2022-22965
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC39
批量无损检测CVE-2022-22965
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC1
Spring-Cloud-Gateway-CVE-2022-22947
CVE-2022-22947CRITICALunder attack01 Apr 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
previouspage 592 / 2,593next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.