Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
77,813 exploits
GitHub PoC
pentestblogin/pentestblog-CVE-2022-0847
CVE-2022-0847HIGHunder attack09 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC3
Dirty Pipe POC
CVE-2022-0847HIGHunder attack09 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
Metasploit600
MyBB Admin Control Code Injection RCE
CVE-2022-24734HIGH09 Mar 2022
Remote code execution in mybb
78RISK
open
Exploit-DB
Webmin 1.984 - Remote Code Execution (Authenticated)
CVE-2022-0824HIGHwebappslinux09 Mar 2022
Improper Access Control to Remote Code Execution in webmin/webmin
78RISK
open
GitHub PoC1
lucksec/CVE-2022-0847
CVE-2022-0847HIGHunder attack08 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC2
An exploit for CVE-2022-0847 dirty-pipe vulnerability
CVE-2022-0847HIGHunder attack08 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC49
CVE-2022-0847 DirtyPipe Exploit.
CVE-2022-0847HIGHunder attack08 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC21
CVE-2022-0847: Linux Kernel Privilege Escalation Vulnerability
CVE-2022-0847HIGHunder attack08 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC
bohr777/cve-2022-0847dirtypipe-exploit
CVE-2022-0847HIGHunder attack08 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC
CVE-2022-0487
CVE-2022-0847HIGHunder attack08 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALunder attackransomware08 Mar 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-24112CRITICALunder attack08 Mar 2022
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALunder attack08 Mar 2022
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack08 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack08 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware08 Mar 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC35
CVE-2022-22947_EXP,CVE-2022-22947_RCE,CVE-2022-22947反弹shell,CVE-2022-22947 getshell
CVE-2022-22947CRITICALunder attack08 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC58
Linux Kernel Local Privilege Escalation Vulnerability CVE-2022-0847.
CVE-2022-0847HIGHunder attack08 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC1
ITMarcin2211/CVE-2022-0847-DirtyPipe-Exploit
CVE-2022-0847HIGHunder attack08 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC14
Implementation of Max Kellermann's exploit for CVE-2022-0847
CVE-2022-0847HIGHunder attack08 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC70
Bash script to check for CVE-2022-0847 "Dirty Pipe"
CVE-2022-0847HIGHunder attack08 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC1
Docker exploit
CVE-2022-0847HIGHunder attack08 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC6
CVE-2022-0847
CVE-2022-0847HIGHunder attack08 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
Exploit-DB
Linux Kernel 5.8 < 5.16.11 - Local Privilege Escalation (DirtyPipe)
CVE-2022-0847HIGHunder attacklocallinux08 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC
zhangweijie11/CVE-2020-17519
CVE-2020-17519CRITICALunder attack08 Mar 2022
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
GitHub PoC2
CVE-2022-24990:TerraMaster TOS 通过 PHP 对象实例化执行未经身份验证的远程命令
CVE-2022-24990CRITICALunder attackransomware08 Mar 2022
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agen
100RISK
open
GitHub PoC2
puckiestyle/CVE-2022-0847
CVE-2022-0847HIGHunder attack08 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC46
The Dirty Pipe Vulnerability
CVE-2022-0847HIGHunder attack08 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC7
CVE-2022-24112: Apache APISIX Remote Code Execution Vulnerability
CVE-2022-24112CRITICALunder attack08 Mar 2022
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RISK
open
GitHub PoC1,132
A root exploit for CVE-2022-0847 (Dirty Pipe)
CVE-2022-0847HIGHunder attack07 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
previouspage 601 / 2,594next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.