Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
77,900 exploits
GitHub PoC
Spring4Shell PoC (CVE-2022-22965)
CVE-2022-22965CRITICALunder attack07 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC63
CVE-2022-22965写入冰蝎webshell脚本
CVE-2022-22965CRITICALunder attack07 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC6
CVE-2022-22965 pocsuite3 POC
CVE-2022-22965CRITICALunder attack07 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
Exploit-DB
binutils 2.37 - Objdump Segmentation Fault
CVE-2021-43149locallinux07 Apr 2022
20RISK
open
Exploit-DB
Kramer VIAware - Remote Code Execution (RCE) (Root)
CVE-2021-35064remotehardware07 Apr 2022
KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits runn
60RISK
open
GitHub PoC
Spring Cloud Config CVE-2019-3799|CVE_2020_5410 漏洞检测
CVE-2019-379907 Apr 2022
Directory Traversal with spring-cloud-config-server
60RISK
open
Exploit-DB
Sherpa Connector Service v2020.2.20328.2050 - Unquoted Service Path
CVE-2022-23909localwindows07 Apr 2022
There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might
23RISK
open
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALunder attack07 Apr 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
Exploit-DB
Kramer VIAware - Remote Code Execution (RCE) (Root)
CVE-2021-36356remotehardware07 Apr 2022
KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePa
50RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-2865307 Apr 2022
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution v
60RISK
open
Metasploit400
VMware Workspace ONE Access CVE-2022-22960
CVE-2022-22960HIGHunder attack06 Apr 2022
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due t
98RISK
open
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALunder attack06 Apr 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC12
Spring-Cloud-Spel-RCE
CVE-2022-22947CRITICALunder attack06 Apr 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC1
sh-ubh/CVE-2018-1002105
CVE-2018-1002105CRITICAL06 Apr 2022
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISK
open
Metasploit600
VMware Workspace ONE Access VMSA-2022-0011 exploit chain
CVE-2022-2295606 Apr 2022
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth
30RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware06 Apr 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
Metasploit600
VMware Workspace ONE Access CVE-2022-22954
CVE-2022-22954CRITICALunder attackransomware06 Apr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open
Metasploit600
VMware Workspace ONE Access VMSA-2022-0011 exploit chain
CVE-2022-2295706 Apr 2022
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities
23RISK
open
GitHub PoC3
Unquoted Service Path privilege escalation vulnerability in Sherpa Connector Service.
CVE-2022-2390906 Apr 2022
There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might
23RISK
open
GitHub PoC2
Navigate CMS <= 2.9.4 - Server-Side Request Forgery (Authenticated)
CVE-2022-2811706 Apr 2022
A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the ap
43RISK
open
GitHub PoC2
irgoncalves/irule-cve-2022-22965
CVE-2022-22965CRITICALunder attack06 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC1
🚨 Exploit the CVE-2025-49844 Redis Lua interpreter UAF vulnerability to execute arbitrary shellcode and gain persistent backdoor access.
CVE-2025-49844CRITICAL06 Apr 2022
Redis Lua Use-After-Free may lead to remote code execution
85RISK
open
GitHub PoC2
The demo code showing the recent Spring4Shell RCE (CVE-2022-22965)
CVE-2022-22965CRITICALunder attack06 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC2
Dirty Pipe Vulnerability Detection Script - RHSB-2022-002 Dirty Pipe - kernel arbitrary file manipulation - (CVE-2022-0847)
CVE-2022-0847HIGHunder attack06 Apr 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC
Spring Framework RCE Exploit
CVE-2022-22965CRITICALunder attack05 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC1
CVE-2022-22963 research
CVE-2022-22963CRITICALunder attack05 Apr 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC2
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
CVE-2022-22965CRITICALunder attack05 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC1
Spring has Confirmed the RCE in Spring Framework. The team has just published the statement along with the mitigation guides for the issue. Now, this vulnerability can be tracked as CVE-2022-22965.
CVE-2022-22965CRITICALunder attack05 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC
CVE-2022-22947 reproduce
CVE-2022-22947CRITICALunder attack05 Apr 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC
Spring4Shell is a critical RCE vulnerability in the Java Spring Framework and is one of three related vulnerabilities published on March 30
CVE-2022-22965CRITICALunder attack05 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
previouspage 592 / 2,597next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.