Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
77,900 exploits
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack31 Mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALunder attack31 Mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
Metasploit0
Spring Framework Class property RCE (Spring4Shell)
CVE-2022-22965CRITICALunder attack31 Mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALunder attack31 Mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack31 Mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware31 Mar 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack31 Mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack31 Mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack31 Mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack31 Mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack31 Mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC14
This includes CVE-2022-22963, a Spring SpEL / Expression Resource Access Vulnerability, as well as CVE-2022-22965, the spring-webmvc/spring-webflux RCE termed "SpringShell".
CVE-2022-22963CRITICALunder attack31 Mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC1
Exploit for Dirty-Pipe (CVE-2022-0847)
CVE-2022-0847HIGHunder attack31 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC34
darryk10/CVE-2022-22963
CVE-2022-22963CRITICALunder attack30 Mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
Exploit-DB
Kramer VIAware 2.5.0719.1034 - Remote Code Execution (RCE)
CVE-2019-17124remotehardware30 Mar 2022
Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.
28RISK
open
GitHub PoC3
{ Spring Core 0day CVE-2022-22963 }
CVE-2022-22963CRITICALunder attack30 Mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC
Spring Cloud Gateway Actuator API SpEL Code Injection.
CVE-2022-22947CRITICALunder attack30 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC
CVE-2022-28080
CVE-2022-2808030 Mar 2022
Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter.
50RISK
open
GitHub PoC3
A TLS server using a vendored fork of the Go TLS stack that has renegotation indication extension forcibly disabled.
CVE-2009-3555CRITICAL30 Mar 2022
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS
70RISK
open
GitHub PoC9
Kirill89/CVE-2022-22963-PoC
CVE-2022-22963CRITICALunder attack30 Mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC
scopion/CVE-2022-22947-exp
CVE-2022-22947CRITICALunder attack30 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC4
Spring Cloud Gateway RCE - CVE-2022-22947
CVE-2022-22947CRITICALunder attack30 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
Exploit-DB
WordPress Plugin Easy Cookie Policy 1.6.2 - Broken Access Control to Stored XSS
CVE-2021-24405webappsphp30 Mar 2022
Easy Cookie Policy <= 1.6.2 - Broken Access Control to Stored Cross-Site Scripting
28RISK
open
GitHub PoC50
CVE-2022-22965 : about spring core rce
CVE-2022-22965CRITICALunder attack30 Mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC377
Spring4Shell Proof Of Concept/And vulnerable application CVE-2022-22965
CVE-2022-22965CRITICALunder attack30 Mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC115
CVE-2022-22963 PoC
CVE-2022-22963CRITICALunder attack30 Mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
VulnCheck XDB
initial-access
CVE-2009-3555CRITICAL30 Mar 2022
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS
70RISK
open
GitHub PoC15
CVE-2022-22963 Spring-Cloud-Function-SpEL_RCE_exploit
CVE-2022-22963CRITICALunder attack30 Mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC131
Spring4Shell - Spring Core RCE - CVE-2022-22965
CVE-2022-22965CRITICALunder attack30 Mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
Exploit-DB
ImpressCMS 1.4.2 - Remote Code Execution (RCE)
CVE-2021-26599webappsphp30 Mar 2022
ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.
43RISK
open
previouspage 596 / 2,597next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.