Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
77,900 exploits
GitHub PoC
日常更新一些顺手写的gobypoc,包含高危害EXP
CVE-2022-22947CRITICALunder attack04 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC2
Spring Cloud Gateway Actuator API 远程命令执行 CVE-2022-22947
CVE-2022-22947CRITICALunder attack04 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALunder attack04 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-0185HIGHunder attack04 Mar 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RISK
open
GitHub PoC9
cve-2022-22947 spring cloud gateway 批量扫描脚本
CVE-2022-22947CRITICALunder attack04 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC71
CVE-2022-22947批量
CVE-2022-22947CRITICALunder attack04 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC
CVE-2019-11043 LAB
CVE-2019-11043HIGHunder attackransomware04 Mar 2022
Underflow in PHP-FPM can lead to RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALunder attack04 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC7
批量url检测Spring-Cloud-Gateway-CVE-2022-22947
CVE-2022-22947CRITICALunder attack04 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-11043HIGHunder attackransomware04 Mar 2022
Underflow in PHP-FPM can lead to RCE
100RISK
open
VulnCheck XDB
local
CVE-2021-40449HIGHunder attackransomware04 Mar 2022
Win32k Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALunder attack04 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware04 Mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack04 Mar 2022
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC8
9lyph/CVE-2022-29593
CVE-2022-29593MEDIUM04 Mar 2022
relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post reques
38RISK
open
GitHub PoC
CVE-2022-22947批量检测脚本,回显命令没进行正则,大佬们先用着,后续再更
CVE-2022-22947CRITICALunder attack04 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC
Exp
CVE-2022-22947CRITICALunder attack04 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC
Spring Cloud Gateway远程代码执行漏洞
CVE-2022-22947CRITICALunder attack04 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC5
Greetdawn/CVE-2022-22947
CVE-2022-22947CRITICALunder attack04 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC3
Spring-Cloud-Gateway-CVE-2022-22947
CVE-2022-22947CRITICALunder attack04 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC10
Spring cloud gateway code injection : CVE-2022-22947
CVE-2022-22947CRITICALunder attack03 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC38
Spring Cloud Gateway < 3.0.7 & < 3.1.1 Code Injection (RCE)
CVE-2022-22947CRITICALunder attack03 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC28
SpringCloudGatewayRCE - CVE-2022-22947 / Code By:Tas9er
CVE-2022-22947CRITICALunder attack03 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC77
Spring Cloud Gateway 远程代码执行漏洞Exp Spring_Cloud_Gateway_RCE_Exp-CVE-2022-22947
CVE-2022-22947CRITICALunder attack03 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC
poc for cve-2022-22947
CVE-2022-22947CRITICALunder attack03 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC1
Zero-day-scanning is a Domain Controller vulnerability scanner, that currently includes checks for Zero-day-scanning (CVE-2020-1472), MS-PAR/MS-RPRN and SMBv2 Signing.
CVE-2020-1472MEDIUMunder attackransomware03 Mar 2022
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
Test tool for CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware03 Mar 2022
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALunder attack03 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware03 Mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware03 Mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
previouspage 604 / 2,597next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.