Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
77,900 exploits
GitHub PoC32
Detects attempts and successful exploitation of CVE-2022-26809
CVE-2022-26809CRITICAL14 Apr 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISK
open
GitHub PoC19
The poc for CVE-2022-26809 RCE via RPC will be updated here.
CVE-2022-26809CRITICAL14 Apr 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISK
open
GitHub PoC7
auduongxuan/CVE-2022-26809
CVE-2022-26809CRITICAL14 Apr 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISK
open
GitHub PoC27
Remote Code Execution Exploit in the RPC Library
CVE-2022-26809CRITICAL14 Apr 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2017-12149CRITICALunder attackransomware14 Apr 2022
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISK
open
GitHub PoC3
A Zeek CVE-2022-24491 detector.
CVE-2022-24491CRITICAL13 Apr 2022
Windows Network File System Remote Code Execution Vulnerability
60RISK
open
GitHub PoC3
A Zeek detector for CVE-2022-24497.
CVE-2022-24497CRITICAL13 Apr 2022
Windows Network File System Remote Code Execution Vulnerability
60RISK
open
GitHub PoC16
VMware Workspace ONE Access and Identity Manager RCE via SSTI - Test script for shodan, file or manual.
CVE-2022-22954CRITICALunder attackransomware13 Apr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open
GitHub PoC68
CVE-2022-22954 VMware Workspace ONE Access freemarker SSTI 漏洞 命令执行、批量检测脚本、文件写入
CVE-2022-22954CRITICALunder attackransomware13 Apr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open
GitHub PoC
exploitation script tryhackme
CVE-2022-22965CRITICALunder attack13 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC
VMware Workspace ONE Access远程代码执行漏洞 / Code By:Jun_sheng
CVE-2022-22954CRITICALunder attackransomware13 Apr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open
GitHub PoC3
Easy!Appointments < 1.4.3 - Unauthenticated PII (events) disclosure
CVE-2022-0482CRITICAL13 Apr 2022
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
75RISK
open
VulnCheck XDB
initial-access
CVE-2022-26501CRITICALunder attackransomware13 Apr 2022
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
78RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack13 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22954CRITICALunder attackransomware13 Apr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22954CRITICALunder attackransomware13 Apr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open
GitHub PoC2
AkuCyberSec/CVE-2017-8917-Joomla-370-SQL-Injection
CVE-2017-891713 Apr 2022
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISK
open
VulnCheck XDB
initial-access
CVE-2022-22954CRITICALunder attackransomware12 Apr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22954CRITICALunder attackransomware12 Apr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open
GitHub PoC10
PoC for CVE-2022-22954 - VMware Workspace ONE Access Freemarker Server-Side Template Injection
CVE-2022-22954CRITICALunder attackransomware12 Apr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open
GitHub PoC23
spring4shell | CVE-2022-22965
CVE-2022-22965CRITICALunder attack12 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC1
corelight/cve-2022-22954
CVE-2022-22954CRITICALunder attackransomware12 Apr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open
GitHub PoC1
CVE-2022-22954 Açığı test etme
CVE-2022-22954CRITICALunder attackransomware12 Apr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open
GitHub PoC1
mumu2020629/-CVE-2022-22954-scanner
CVE-2022-22954CRITICALunder attackransomware12 Apr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open
GitHub PoC
lucksec/VMware-CVE-2022-22954
CVE-2022-22954CRITICALunder attackransomware12 Apr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open
GitHub PoC12
提供批量扫描URL以及执行命令功能。Workspace ONE Access 模板注入漏洞,可执行任意代码
CVE-2022-22954CRITICALunder attackransomware12 Apr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open
GitHub PoC3
TerraMaster TOS Unauthenticated Remote Command Execution(RCE) Vulnerability CVE-2022-24990
CVE-2022-24990CRITICALunder attackransomware12 Apr 2022
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agen
100RISK
open
GitHub PoC1
Greenwolf/CVE-2022-1175
CVE-2022-1175HIGH12 Apr 2022
Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 befor
63RISK
open
GitHub PoC4
Greenwolf/CVE-2022-1162
CVE-2022-1162CRITICAL12 Apr 2022
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE
85RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware12 Apr 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
previouspage 590 / 2,597next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.