Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.313exploits catalogados
34.834CVEs com exploração pública
24.695testados em laboratório
13.885 exploits
GitHub PoC2
Watchguard RCE POC CVE-2022-26318
CVE-2022-26318CRITICALsob ataque18 abr 2022
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulner
100RISCO
abrir
GitHub PoC
CVE-2019-15107
CVE-2019-15107CRITICALsob ataqueransomware18 abr 2022
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC
CVE-2021-42013 - Apache 2.4.50
CVE-2021-42013CRITICALsob ataqueransomware18 abr 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC1
CVE-2015-1635-POC,指定IP与端口验证HTTP.sys漏洞是否存在
CVE-2015-1635CRITICALsob ataque17 abr 2022
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISCO
abrir
GitHub PoC9
Scripted Linux Privilege Escalation for the CVE-2022-0847 "Dirty Pipe" vulnerability
CVE-2022-0847HIGHsob ataque17 abr 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC53
Exploit for CVE-2021-22204 (ExifTool) - Arbitrary Code Execution
CVE-2021-22204MEDIUMsob ataque16 abr 2022
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISCO
abrir
GitHub PoC148
Laravel RCE Exploit PoC - CVE-2021-3129 (user-friendly with automatic log path detection)
CVE-2021-3129CRITICALsob ataqueransomware16 abr 2022
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC
mhurts/CVE-2022-22954-POC
CVE-2022-22954CRITICALsob ataqueransomware16 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir
GitHub PoC2
Repository containing nse script for vulnerability CVE-2022-21907. It is a component (IIS) vulnerability on Windows. It allows remote code execution. The vulnerability affects the kernel module http. sys, which handles most basic IIS operations.
CVE-2022-21907CRITICAL16 abr 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC11
Spring Cloud Gateway Actuator API SpEL Code Injection (CVE-2022-22947)
CVE-2022-22947CRITICALsob ataque15 abr 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC2
tufanturhan/CVE-2022-21971-Windows-Runtime-RCE
CVE-2022-21971HIGHsob ataque15 abr 2022
Windows Runtime Remote Code Execution Vulnerability
83RISCO
abrir
GitHub PoC4
CVE-2022-22954 VMware Workspace ONE Access free marker SSTI
CVE-2022-22954CRITICALsob ataqueransomware15 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir
GitHub PoC
tufanturhan/CVE-2022-0847-L-nux-PrivEsc
CVE-2022-0847HIGHsob ataque15 abr 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC27
Remote Code Execution Exploit in the RPC Library
CVE-2022-26809CRITICAL14 abr 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC8
Spring Cloud Function SPEL表达式注入漏洞(CVE-2022-22963)
CVE-2022-22963CRITICALsob ataque14 abr 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
GitHub PoC
VVeakee/CVE-2017-12149
CVE-2017-12149CRITICALsob ataqueransomware14 abr 2022
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISCO
abrir
GitHub PoC32
Detects attempts and successful exploitation of CVE-2022-26809
CVE-2022-26809CRITICAL14 abr 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC7
auduongxuan/CVE-2022-26809
CVE-2022-26809CRITICAL14 abr 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC19
The poc for CVE-2022-26809 RCE via RPC will be updated here.
CVE-2022-26809CRITICAL14 abr 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC1
Proof of Concept for exploiting VMware CVE-2022-22954
CVE-2022-22954CRITICALsob ataqueransomware14 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir
GitHub PoC3
CVE-2022-0185 exploit
CVE-2022-0185HIGHsob ataque14 abr 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RISCO
abrir
GitHub PoC
exploitation script tryhackme
CVE-2022-22965CRITICALsob ataque13 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC3
A Zeek CVE-2022-24491 detector.
CVE-2022-24491CRITICAL13 abr 2022
Windows Network File System Remote Code Execution Vulnerability
60RISCO
abrir
GitHub PoC2
AkuCyberSec/CVE-2017-8917-Joomla-370-SQL-Injection
CVE-2017-891713 abr 2022
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISCO
abrir
GitHub PoC16
VMware Workspace ONE Access and Identity Manager RCE via SSTI - Test script for shodan, file or manual.
CVE-2022-22954CRITICALsob ataqueransomware13 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir
GitHub PoC
VMware Workspace ONE Access远程代码执行漏洞 / Code By:Jun_sheng
CVE-2022-22954CRITICALsob ataqueransomware13 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir
GitHub PoC3
A Zeek detector for CVE-2022-24497.
CVE-2022-24497CRITICAL13 abr 2022
Windows Network File System Remote Code Execution Vulnerability
60RISCO
abrir
GitHub PoC3
Easy!Appointments < 1.4.3 - Unauthenticated PII (events) disclosure
CVE-2022-0482CRITICAL13 abr 2022
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
75RISCO
abrir
GitHub PoC68
CVE-2022-22954 VMware Workspace ONE Access freemarker SSTI 漏洞 命令执行、批量检测脚本、文件写入
CVE-2022-22954CRITICALsob ataqueransomware13 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir
GitHub PoC1
Greenwolf/CVE-2022-1175
CVE-2022-1175HIGH12 abr 2022
Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 befor
63RISCO
abrir
anteriorpágina 321 / 463próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.