Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
77,900 exploits
GitHub PoC16
Docker PoC for CVE-2022-22965 with Spring Boot version 2.6.5
CVE-2022-22965CRITICALunder attack03 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC7
CVE-2022-22965 POC
CVE-2022-22965CRITICALunder attack02 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC
mwojterski/cve-2022-22965
CVE-2022-22965CRITICALunder attack02 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC18
ActiveMQ系列漏洞探测利用工具,包括ActiveMQ 默认口令漏洞及ActiveMQ任意文件写入漏洞(CVE-2016-3088),支持批量探测利用。
CVE-2016-3088CRITICALunder attack02 Apr 2022
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open
GitHub PoC
Environment for CVE-2021-41773 recreation.
CVE-2021-41773HIGHunder attackransomware02 Apr 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC16
CVE-2022-22965\Spring-Core-RCE堪比关于 Apache Log4j2核弹级别漏洞exp的rce一键利用
CVE-2022-22965CRITICALunder attack02 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC
Local privilege escalation for OS X 10.10.5 via CVE-2016-1828.
CVE-2016-182802 Apr 2022
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
28RISK
open
GitHub PoC10
tess-ss/SAP-memory-pipes-desynchronization-vulnerability-MPI-CVE-2022-22536
CVE-2022-22536CRITICALunder attack02 Apr 2022
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RISK
open
VulnCheck XDB
infoleak
CVE-2022-23131CRITICALunder attack02 Apr 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISK
open
GitHub PoC4
ShellShock interactive-shell exploit
CVE-2014-6271CRITICALunder attack02 Apr 2022
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack02 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack02 Apr 2022
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALunder attackransomware02 Apr 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC7
DirtyPipe: Exploit for a new Linux vulnerability known as 'Dirty Pipe(CVE-2022-0847)' allows local users to gain root privileges. The vulnerability is tracked as CVE-2022-0847 and allows a non-privileged user to inject and overwrite data in read-only files, including SUID processes that run as root.
CVE-2022-0847HIGHunder attack02 Apr 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC11
CVE-2022-23131漏洞利用工具开箱即用。
CVE-2022-23131CRITICALunder attack02 Apr 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISK
open
GitHub PoC4
Spring-0day/CVE-2022-22965
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC4
CVE-2022-22965
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC1
CVE-2022-22965 Environment
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC
Showcase of overridding the Spring Framework version in older Spring Boot versions
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC14
Spring Framework RCE via Data Binding on JDK 9+ / spring4shell / CVE-2022-22965
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC12
Spring4Shell (CVE-2022-22965)
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC
Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and systems, allowing you to get insight on versions used. Unpacks JARs and analyses their Manifest files.
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC
Presentation slides and supplementary material
CVE-2022-0847HIGHunder attack01 Apr 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC3
CVE-2022-22965 EXP
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALunder attack01 Apr 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-42278HIGHunder attackransomware01 Apr 2022
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC72
SpringFramework 远程代码执行漏洞CVE-2022-22965
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC39
批量无损检测CVE-2022-22965
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC1
helsecert/CVE-2022-22965
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC1
lcarea/CVE-2022-22965
CVE-2022-22965CRITICALunder attack01 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
previouspage 594 / 2,597next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.