Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.107exploits catalogados
34.679CVEs com exploração pública
24.695testados em laboratório
13.812 exploits
GitHub PoC17
POC for CVE-2022-21907: HTTP Protocol Stack Remote Code Execution Vulnerability.
CVE-2022-21907CRITICAL29 out 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC11
hughink/CVE-2022-40684
CVE-2022-40684CRITICALsob ataqueransomware28 out 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir
GitHub PoC2
Exploit Fortigate - CVE-2022-40684
CVE-2022-40684CRITICALsob ataqueransomware27 out 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir
GitHub PoC14
An authentication bypass using an alternate path or channel in Fortinet product
CVE-2022-40684CRITICALsob ataqueransomware27 out 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir
GitHub PoC14
CVE-2023-29478 - BiblioCraft File Manipulation/Remote Code Execution exploit affecting BiblioCraft versions prior to v2.4.6
CVE-2023-29478CRITICAL27 out 2022
BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to a
48RISCO
abrir
GitHub PoC5
pdf_info <= 0.5.3 OS Command Injection
CVE-2022-36231CRITICAL26 out 2022
pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3.
48RISCO
abrir
GitHub PoC9
qingsiweisan/CVE-2022-40684
CVE-2022-40684CRITICALsob ataqueransomware26 out 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir
GitHub PoC5
ELIZEUOPAIN/CVE-2019-9053-CMS-Made-Simple-2.2.10---SQL-Injection-Exploit
CVE-2019-905325 out 2022
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC5
Exploit Samba smbd 3.0.20-Debian
CVE-2007-244725 out 2022
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC2
Vulnmachines/text4shell-CVE-2022-42889
CVE-2022-4288925 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC1
cURL one-liner to test for CVE-2022-1388 BIG-IP iControl REST RCE
CVE-2022-1388CRITICALsob ataqueransomware25 out 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir
GitHub PoC
cURL one-liner to test for CVE-2022-1388 BIG-IP iControl REST RCE
CVE-2022-1388CRITICALsob ataqueransomware25 out 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir
GitHub PoC29
CVE-2022-37042 Zimbra Auth Bypass leads to RCE
CVE-2022-37042CRITICALsob ataqueransomware24 out 2022
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts fi
100RISCO
abrir
GitHub PoC2
b4dboy17/CVE-2022-26134
CVE-2022-26134CRITICALsob ataqueransomware24 out 2022
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC5
Vulnerability Scanner for CVE-2022-42889 (Text4Shell)
CVE-2022-4288923 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC4
Apache Text4Shell (CVE-2022-42889) Burp Bounty Profile
CVE-2022-4288923 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC5
A simple dockerize application that shows how to exploit the CVE-2022-42889 vulnerability.
CVE-2022-4288923 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC20
CVE-2022-42889 aka Text4Shell research & PoC
CVE-2022-4288923 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC
CVE-2017-0785
CVE-2017-078522 out 2022
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RISCO
abrir
GitHub PoC1
CVE-2022-42889 Text4Shell Exploit POC
CVE-2022-4288922 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC13
CVE-2022-39197 RCE POC
CVE-2022-39197MEDIUMsob ataque22 out 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISCO
abrir
GitHub PoC3
python script for CVE-2022-42889
CVE-2022-4288922 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC
Dockerized PoC for CVE-2022-42889 Text4Shell
CVE-2022-4288922 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC2
humbss/CVE-2022-42889
CVE-2022-4288921 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC3
This project includes a python script which generates malicious commands leveraging CVE-2022-42889 vulnerability
CVE-2022-4288921 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC
CVE-2007-4559 - Polemarch exploit
CVE-2007-4559CRITICAL21 out 2022
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows
53RISCO
abrir
GitHub PoC3
通过 jvm 启动参数 以及 jps pid进行拦截非法参数
CVE-2022-4288920 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC8
Proof of Concept Appliction for testing CVE-2022-42889
CVE-2022-4288920 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC
A fully automated, accurate, and extensive scanner for finding text4shell RCE CVE-2022-42889
CVE-2022-4288920 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC35
the metasploit script(POC) about CVE-2022-41040. Microsoft Exchange are vulnerable to a server-side request forgery (SSRF) attack. An authenticated attacker can use the vulnerability to elevate privileges.
CVE-2022-41040HIGHsob ataqueransomware20 out 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISCO
abrir
anteriorpágina 294 / 461próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.