Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
77,813 exploits
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack07 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack07 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC1
SpringCloudGatewayRCE / Code By:Jun_sheng
CVE-2022-22947CRITICALunder attack07 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC6
darkb1rd/cve-2022-22947
CVE-2022-22947CRITICALunder attack07 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC7
Spring Cloud Gateway Actuator API SpEL Code Injection (CVE-2022-22947)
CVE-2022-22947CRITICALunder attack07 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2021-31166CRITICALunder attack07 Mar 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open
Exploit-DB
part-db 0.5.11 - Remote Code Execution (RCE)
CVE-2022-0848CRITICALwebappsphp07 Mar 2022
OS Command Injection in part-db/part-db
60RISK
open
GitHub PoC14
Spring Cloud Gateway远程代码执行漏洞POC,基于命令执行的基础上,增加了反弹shell操作
CVE-2022-22947CRITICALunder attack07 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack07 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC50
CVE-2022-0847
CVE-2022-0847HIGHunder attack07 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC9
Vulnerability in the Linux kernel since 5.8
CVE-2022-0847HIGHunder attack07 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC282
CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞,可覆盖重写任意可读文件中的数据,从而可将普通权限的用户提升到特权 root。 CVE-2022-0847 的漏洞原理类似于 CVE-2016-5195 脏牛漏洞(Dirty Cow),但它更容易被利用。漏洞作者将此漏洞命名为“Dirty Pipe”
CVE-2022-0847HIGHunder attack07 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC9
CVE-2022-0847 exploit one liner
CVE-2022-0847HIGHunder attack07 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC282
CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞,可覆盖重写任意可读文件中的数据,从而可将普通权限的用户提升到特权 root。 CVE-2022-0847 的漏洞原理类似于 CVE-2016-5195 脏牛漏洞(Dirty Cow),但它更容易被利用。漏洞作者将此漏洞命名为“Dirty Pipe”
CVE-2016-5195HIGHunder attack07 Mar 2022
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC1,132
A root exploit for CVE-2022-0847 (Dirty Pipe)
CVE-2022-0847HIGHunder attack07 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack07 Mar 2022
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware07 Mar 2022
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
Metasploit600
TerraMaster TOS 4.2.29 or lower - Unauthenticated RCE chaining CVE-2022-24990 and CVE-2022-24989
CVE-2022-24990CRITICALunder attackransomware07 Mar 2022
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agen
100RISK
open
Metasploit600
TerraMaster TOS 4.2.29 or lower - Unauthenticated RCE chaining CVE-2022-24990 and CVE-2022-24989
CVE-2022-2498907 Mar 2022
TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskst
30RISK
open
Exploit-DB
Spring Cloud Gateway 3.1.0 - Remote Code Execution (RCE)
CVE-2022-22947CRITICALunder attackwebappsjava07 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC113
Webmin <=1.984, CVE-2022-0824 Post-Auth Reverse Shell PoC
CVE-2022-0824HIGH06 Mar 2022
Improper Access Control to Remote Code Execution in webmin/webmin
78RISK
open
VulnCheck XDB
local
CVE-2022-0492HIGHunder attack06 Mar 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RISK
open
GitHub PoC11
A script to check if a container environment is vulnerable to container escapes via CVE-2022-0492
CVE-2022-0492HIGHunder attack06 Mar 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RISK
open
GitHub PoC2
22ke/CVE-2022-22947
CVE-2022-22947CRITICALunder attack05 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC
CVE-2022-22947批量检测脚本,回显命令没进行正则,大佬们先用着,后续再更
CVE-2022-22947CRITICALunder attack04 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC3
Spring-Cloud-Gateway-CVE-2022-22947
CVE-2022-22947CRITICALunder attack04 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware04 Mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
CVE-2019-11043 LAB
CVE-2019-11043HIGHunder attackransomware04 Mar 2022
Underflow in PHP-FPM can lead to RCE
100RISK
open
GitHub PoC
日常更新一些顺手写的gobypoc,包含高危害EXP
CVE-2022-22947CRITICALunder attack04 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC2
Spring Cloud Gateway Actuator API 远程命令执行 CVE-2022-22947
CVE-2022-22947CRITICALunder attack04 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
previouspage 602 / 2,594next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.