Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
77,900 exploits
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack30 Mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC15
CVE-2022-22963 Spring-Cloud-Function-SpEL_RCE_exploit
CVE-2022-22963CRITICALunder attack30 Mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC
scopion/CVE-2022-22947-exp
CVE-2022-22947CRITICALunder attack30 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC50
CVE-2022-22965 : about spring core rce
CVE-2022-22965CRITICALunder attack30 Mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC4
Spring Cloud Gateway RCE - CVE-2022-22947
CVE-2022-22947CRITICALunder attack30 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC3
{ Spring Core 0day CVE-2022-22963 }
CVE-2022-22963CRITICALunder attack30 Mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC131
Spring4Shell - Spring Core RCE - CVE-2022-22965
CVE-2022-22965CRITICALunder attack30 Mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC115
CVE-2022-22963 PoC
CVE-2022-22963CRITICALunder attack30 Mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC377
Spring4Shell Proof Of Concept/And vulnerable application CVE-2022-22965
CVE-2022-22965CRITICALunder attack30 Mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
Exploit-DB
ImpressCMS 1.4.2 - Remote Code Execution (RCE)
CVE-2021-26599webappsphp30 Mar 2022
ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.
43RISK
open
GitHub PoC2
Vancomycin-g/CVE-2022-22947
CVE-2022-22947CRITICALunder attack29 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
Metasploit600
Spring Cloud Function SpEL Injection
CVE-2022-22963CRITICALunder attack29 Mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
Metasploit600
Wordpress Plugin Elementor Authenticated Upload Remote Code Execution
CVE-2022-1329HIGH29 Mar 2022
Elementor Website Builder 3.6.0 - 3.6.2 - Missing Authorization to Remote Code Execution
78RISK
open
GitHub PoC21
CVE-2019–9193 - PostgreSQL 9.3-12.3 Authenticated Remote Code Execution
CVE-2019-919329 Mar 2022
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open
GitHub PoC2
Powershell script that dumps Chrome and Edge version to a text file in order to determine if you need to update due to CVE-2022-1096
CVE-2022-1096HIGHunder attack29 Mar 2022
Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corrup
76RISK
open
GitHub PoC
Set of scripts, to test and exploit the zerologon vulnerability (CVE-2020-1472).
CVE-2020-1472MEDIUMunder attackransomware29 Mar 2022
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-4034HIGHunder attackransomware29 Mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-919329 Mar 2022
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open
VulnCheck XDB
client-side
CVE-2021-21017HIGHunder attack29 Mar 2022
Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution
93RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware29 Mar 2022
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44142HIGH29 Mar 2022
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SM
63RISK
open
VulnCheck XDB
infoleak
CVE-2021-44142HIGH29 Mar 2022
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SM
63RISK
open
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALunder attackransomware28 Mar 2022
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware28 Mar 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-26318CRITICALunder attack28 Mar 2022
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulner
100RISK
open
GitHub PoC
Description of Exploit SMBGhost CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware28 Mar 2022
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
Tankirat/CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware28 Mar 2022
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
chattopadhyaykittu/CVE-2017-0037
CVE-2017-0037HIGHunder attack28 Mar 2022
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilde
93RISK
open
GitHub PoC11
misterxid/watchguard_cve-2022-26318
CVE-2022-26318CRITICALunder attack28 Mar 2022
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulner
100RISK
open
GitHub PoC354
spring-cloud / spring-cloud-function,spring.cloud.function.routing-expression,RCE,0day,0-day,POC,EXP,CVE-2022-22963
CVE-2022-22963CRITICALunder attack26 Mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
previouspage 597 / 2,597next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.