Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.107exploits catalogados
34.679CVEs com exploração pública
24.695testados em laboratório
13.758 exploits
GitHub PoC1
CyberKimathi/Py3-CVE-2017-0785
CVE-2017-078513 nov 2022
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RISCO
abrir
GitHub PoC
ivilpez/cve-2017-16995.c
CVE-2017-1699512 nov 2022
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISCO
abrir
GitHub PoC359
Unsigned driver loader using CVE-2018-19320
CVE-2018-19320HIGHsob ataqueransomware12 nov 2022
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RISCO
abrir
GitHub PoC109
Zimbra <9.0.0.p27 RCE
CVE-2022-41352CRITICALsob ataque11 nov 2022
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through ama
100RISCO
abrir
GitHub PoC4
Exploit WordPress Media Library XML External Entity Injection (XXE) to exfiltrate files.
CVE-2021-29447HIGH11 nov 2022
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir
GitHub PoC
Joanmei/CVE-2017-0785
CVE-2017-078510 nov 2022
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RISCO
abrir
GitHub PoC
Implementation of CVE-2022-30190 in C
CVE-2022-30190HIGHsob ataqueransomware10 nov 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
SPRING DATA REST CVE-2017-8046 DEMO
CVE-2017-804610 nov 2022
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISCO
abrir
GitHub PoC1
bantu2301/CVE-2018-16858
CVE-2018-16858HIGH09 nov 2022
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could
68RISCO
abrir
GitHub PoC1
CVE-2020-0796
CVE-2020-0796CRITICALsob ataqueransomware09 nov 2022
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC2
A simple tool to enumerate users in gitlab
CVE-2022-1162CRITICAL09 nov 2022
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE
85RISCO
abrir
GitHub PoC4
CVE-2022-22965图形化检测工具
CVE-2022-22965CRITICALsob ataque08 nov 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC1
DO NOT USE FOR ANYTHING REAL. Simple springboot sample app with vulnerability CVE-2021-44228 aka "Log4Shell"
CVE-2021-44228CRITICALsob ataqueransomware08 nov 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
The first poc video presenting the sql injection test from ( WordPress Core 5.8.2-'WP_Query' / CVE-2022-21661)
CVE-2022-21661HIGH08 nov 2022
SQL injection in WordPress
78RISCO
abrir
GitHub PoC
CVE-2022-0824, CVE-2022-0829, File Manger privilege exploit
CVE-2022-0824HIGH08 nov 2022
Improper Access Control to Remote Code Execution in webmin/webmin
78RISCO
abrir
GitHub PoC2
yilin1203/CVE-2018-20062
CVE-2018-20062CRITICALsob ataque07 nov 2022
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RISCO
abrir
GitHub PoC
adarshpv9746/Text4shell--Automated-exploit---CVE-2022-42889
CVE-2022-4288907 nov 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC1
Proof of Concept for CVE-2021-29447 written in Python
CVE-2021-29447HIGH06 nov 2022
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir
GitHub PoC3
Arbitrary file read controller based on CVE-2021-29447
CVE-2021-29447HIGH06 nov 2022
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir
GitHub PoC3
gcc exploit.c -o exploit -lmnl -lnftnl -no-pie -lpthread
CVE-2022-2586MEDIUMsob ataque06 nov 2022
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-a
68RISCO
abrir
GitHub PoC2
Unauthenticated RCE in GLPI 10.0.2
CVE-2022-35914CRITICALsob ataque06 nov 2022
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISCO
abrir
GitHub PoC7
Script to handle CVE 2022-42889
CVE-2022-4288905 nov 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC7
This repo contains payload for the CVE-2022-36067
CVE-2022-36067CRITICAL05 nov 2022
vm2 vulnerable to Sandbox Escape before v3.9.11
60RISCO
abrir
GitHub PoC2
CVE-2022-42889 (a.k.a. Text4Shell) RCE Proof of Concept
CVE-2022-4288905 nov 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC1
b-abderrahmane/CVE-2021-29447-POC
CVE-2021-29447HIGH05 nov 2022
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir
GitHub PoC15
Proof of Concept for CVE-2022-42889 (Text4Shell Vulnerability)
CVE-2022-4288904 nov 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC35
A project demonstrating an app that is vulnerable to Spring Security authorization bypass CVE-2022-31692
CVE-2022-31692CRITICAL03 nov 2022
Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass v
48RISCO
abrir
GitHub PoC30
利用sudo提权,只针对cnetos7
CVE-2021-3156HIGHsob ataque03 nov 2022
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC2
CVE-2022-42889 Blind-RCE Nuclei Template
CVE-2022-4288902 nov 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC
POCsuite与goland实现华为HG532路由器命令注入CVE-2017-17215 POC
CVE-2017-1721502 nov 2022
Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could se
45RISCO
abrir
anteriorpágina 291 / 459próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.