Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
77,900 exploits
Exploit-DB
Tiny File Manager 2.4.6 - Remote Code Execution (RCE)
CVE-2021-45010webappsphp16 Mar 2022
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7
45RISK
open
Exploit-DB
Tiny File Manager 2.4.6 - Remote Code Execution (RCE)
CVE-2021-40964webappsphp16 Mar 2022
A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to
23RISK
open
GitHub PoC96
CVE-2022-0543_RCE,Redis Lua沙盒绕过 命令执行
CVE-2022-0543CRITICALunder attack16 Mar 2022
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RISK
open
Exploit-DB
Apache APISIX 2.12.1 - Remote Code Execution (RCE)
CVE-2022-24112CRITICALunder attackremotemultiple16 Mar 2022
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-0543CRITICALunder attack16 Mar 2022
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-29441HIGH15 Mar 2022
Authentication bypass
68RISK
open
GitHub PoC
NHPT/CVE-2022-24086-RCE
CVE-2022-24086CRITICALunder attack15 Mar 2022
Adobe Commerce checkout improper input validation leads to remote code execution
100RISK
open
GitHub PoC1
bysinks/CVE-2022-22947
CVE-2022-22947CRITICALunder attack15 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC2
PoC Container Breakout for DirtyPipe Vulnerability CVE-2022-0847
CVE-2022-0847HIGHunder attack15 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC3
Python script to check if your kernel is vulnerable to Dirty pipe CVE-2022-0847
CVE-2022-0847HIGHunder attack15 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC
githublihaha/DirtyPIPE-CVE-2022-0847
CVE-2022-0847HIGHunder attack15 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC3
Implementation of CVE-2022-0847 as a shellcode
CVE-2022-0847HIGHunder attack14 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC15
CVE-2022-0847 POC
CVE-2022-0847HIGHunder attack14 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC2
Exploits for Hotel Druid 3.0.3 - Remote Code Execution (RCE) CVE-2022-22909
CVE-2022-2290914 Mar 2022
HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attack
35RISK
open
Metasploit300
WordPress Photo Gallery Plugin SQL Injection (CVE-2022-0169)
CVE-2022-016914 Mar 2022
Photo Gallery by 10Web < 1.6.0 - Unauthenticated SQL Injection
60RISK
open
Metasploit500
Watch Queue Out of Bounds Write
CVE-2022-099514 Mar 2022
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This
38RISK
open
GitHub PoC2
dirtypipe
CVE-2022-0847HIGHunder attack14 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware14 Mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware14 Mar 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
Exploit for the Rails CVE-2019-5420
CVE-2019-542014 Mar 2022
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware13 Mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC1
Dirty Pipe (CVE-2022-0847) zafiyeti kontrolü
CVE-2022-0847HIGHunder attack13 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC3
CVE-2022-0847 (Dirty Pipe) is an arbitrary file overwrite vulnerability that allows escalation of privileges by modifying or overwriting arbitrary read-only files e.g. /etc/passwd, /etc/shadow.
CVE-2022-0847HIGHunder attack13 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC12
spring-cloud-gateway-rce CVE-2022-22947
CVE-2022-22947CRITICALunder attack13 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack12 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack12 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware12 Mar 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC6
my personal exploit of CVE-2022-0847(dirty pipe)
CVE-2022-0847HIGHunder attack12 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC729
A collection of exploits and documentation that can be used to exploit the Linux Dirty Pipe vulnerability.
CVE-2022-0847HIGHunder attack12 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC4
CVE-2022-0847 Python exploit to get root or write a no write permission, immutable or read-only mounted file.
CVE-2022-0847HIGHunder attack12 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
previouspage 600 / 2,597next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.