Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
77,772 exploits
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALunder attackransomware01 Apr 2022
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware01 Apr 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42287HIGHunder attackransomware01 Apr 2022
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC4
CVE-2022-22965
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC4
Spring-0day/CVE-2022-22965
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC
Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and systems, allowing you to get insight on versions used. Unpacks JARs and analyses their Manifest files.
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC14
Spring Framework RCE via Data Binding on JDK 9+ / spring4shell / CVE-2022-22965
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC1
CVE-2022-22965 Environment
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
Metasploit400
ALLMediaServer 1.6 SEH Buffer Overflow
CVE-2022-2838101 Apr 2022
Mediaserver.exe in ALLMediaServer 1.6 has a stack-based buffer overflow that allows remote attackers to execute arbitrar
30RISK
open
GitHub PoC3
CVE-2022-22965 EXP
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC
Showcase of overridding the Spring Framework version in older Spring Boot versions
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC1
lcarea/CVE-2022-22965
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC72
SpringFramework 远程代码执行漏洞CVE-2022-22965
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC39
批量无损检测CVE-2022-22965
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
Metasploit600
WSO2 Arbitrary File Upload to RCE
CVE-2022-29464CRITICALunder attackransomware01 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC1
helsecert/CVE-2022-22965
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC12
Spring4Shell (CVE-2022-22965)
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC1
POC for CVE-2022-22963
CVE-2022-22963CRITICALunder attack01 Apr 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC1
Spring-Cloud-Gateway-CVE-2022-22947
CVE-2022-22947CRITICALunder attack01 Apr 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42278HIGHunder attackransomware01 Apr 2022
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC19
CVE-2022-22965 - CVE-2010-1622 redux
CVE-2010-162231 Mar 2022
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote at
35RISK
open
GitHub PoC
Threat Intelligence on Zero-Day for Spring4Shell (CVE-2010-1622)
CVE-2010-162231 Mar 2022
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote at
35RISK
open
GitHub PoC1
puckiestyle/CVE-2022-22963
CVE-2022-22963CRITICALunder attack31 Mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC14
This includes CVE-2022-22963, a Spring SpEL / Expression Resource Access Vulnerability, as well as CVE-2022-22965, the spring-webmvc/spring-webflux RCE termed "SpringShell".
CVE-2022-22963CRITICALunder attack31 Mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC19
Spring Cloud Function Vulnerable Application / CVE-2022-22963
CVE-2022-22963CRITICALunder attack31 Mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC26
springFramework_CVE-2022-22965_RCE简单利用
CVE-2022-22965CRITICALunder attack31 Mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC13
CVE-2022-22965 poc including reverse-shell support
CVE-2022-22965CRITICALunder attack31 Mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
previouspage 593 / 2,593next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.