Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.107exploits catalogados
34.679CVEs com exploração pública
24.695testados em laboratório
13.812 exploits
GitHub PoC4
CVE-2021-38163 - exploit for SAP Netveawer
CVE-2021-38163CRITICALsob ataque10 set 2022
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated
90RISCO
abrir
GitHub PoC5
CVE-2022-31188 - OpenCV CVAT (Computer Vision Annotation Tool) SSRF
CVE-2022-31188HIGH09 set 2022
Server-Side Request Forgery Vulnerability in Computer Vision Annotation Tool (CVAT)
53RISCO
abrir
GitHub PoC19
exploit for CVE-2017-1000486 vulnerability with SOCKS proxy support
CVE-2017-1000486CRITICALsob ataque09 set 2022
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISCO
abrir
GitHub PoC3
CVE-2022-36446 - Webmin 1.996 Remote Code Execution
CVE-2022-3644609 set 2022
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
60RISCO
abrir
GitHub PoC
[CVE-2014-6271] Apache Shellshock Remote Command Injection tool for quick reverse shell and file browsing
CVE-2014-6271CRITICALsob ataque09 set 2022
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
This powershell script is intended to be used by anyone looking to remediate the Log4j Vulnerability within their environment. It can target multiple machines and run remotely as a job on all or only affected devices.
CVE-2021-44228CRITICALsob ataqueransomware08 set 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC35
A real exploit for BitBucket RCE CVE-2022-36804
CVE-2022-36804HIGHsob ataque07 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
GitHub PoC
Remediation for CVE-2013-3900
CVE-2013-3900MEDIUMsob ataque06 set 2022
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir
GitHub PoC1
Redis RCE through Lua Sandbox Escape vulnerability
CVE-2022-0543CRITICALsob ataque05 set 2022
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RISCO
abrir
GitHub PoC23
CVE-2021-34527 AddPrinterDriverEx() Privilege Escalation
CVE-2021-34527HIGHsob ataqueransomware05 set 2022
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC22
CVE-2022-2586: Linux kernel nft_object UAF
CVE-2022-2586MEDIUMsob ataque03 set 2022
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-a
68RISCO
abrir
GitHub PoC1
0xrobiul/CVE-2018-15473
CVE-2018-15473MEDIUM03 set 2022
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC4
Powertek PDU身份绕过
CVE-2022-33174CRITICAL02 set 2022
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypas
68RISCO
abrir
GitHub PoC2
Zabbix-SAML-Bypass: CVE-2022-23131
CVE-2022-23131CRITICALsob ataque02 set 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISCO
abrir
GitHub PoC5
Win10 20H2 LPE for CVE-2021-31956
CVE-2021-31956HIGHsob ataque02 set 2022
Windows NTFS Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC
75ACOL/CVE-2022-22963
CVE-2022-22963CRITICALsob ataque01 set 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
GitHub PoC6
OpenSSL
CVE-2022-1292CRITICAL01 set 2022
The c_rehash script allows command injection
70RISCO
abrir
GitHub PoC
shavchen/CVE-2022-26138
CVE-2022-26138CRITICALsob ataque01 set 2022
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in th
100RISCO
abrir
GitHub PoC
Proof-of-concept exploit for the Dirty Pipe vulnerability (CVE-2022-0847)
CVE-2022-0847HIGHsob ataque31 ago 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC2
CVE-2022-24124 exploit
CVE-2022-2412431 ago 2022
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as d
50RISCO
abrir
GitHub PoC84
CVE-2020-1472 C++
CVE-2020-1472MEDIUMsob ataqueransomware31 ago 2022
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC3
Oracle Weblogic RCE - CVE-2022-2109
CVE-2021-2109HIGH30 ago 2022
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
63RISCO
abrir
GitHub PoC5
Unauthenticated RCE in Open Web Analytics (OWA) 1.7.3
CVE-2022-2463730 ago 2022
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISCO
abrir
GitHub PoC
CVE-2017-8917 - Joomla 3.7.0 'com_fields' SQL Injection
CVE-2017-891729 ago 2022
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISCO
abrir
GitHub PoC1
Apache Spark RCE - CVE-2022-33891
CVE-2022-33891HIGHsob ataque29 ago 2022
Apache Spark shell command injection vulnerability via Spark UI
100RISCO
abrir
GitHub PoC
CVE-2017-7269 implemented in C#
CVE-2017-7269CRITICALsob ataque29 ago 2022
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir
GitHub PoC
Adobe Acrobat Reader UAF vulnerability Exploit code
CVE-2020-9715HIGHsob ataque29 ago 2022
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3
83RISCO
abrir
GitHub PoC
CVE-2017-7269 implemented in python3
CVE-2017-7269CRITICALsob ataque28 ago 2022
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir
GitHub PoC2
CVE-2022-0492-Container-Escape
CVE-2022-0492HIGHsob ataque27 ago 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RISCO
abrir
GitHub PoC
A Docker image vulnerable to CVE-2020-7246.
CVE-2020-724627 ago 2022
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISCO
abrir
anteriorpágina 301 / 461próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.