Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.313exploits catalogados
34.834CVEs com exploração pública
24.695testados em laboratório
13.885 exploits
GitHub PoC2
irgoncalves/irule-cve-2022-22965
CVE-2022-22965CRITICALsob ataque06 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC2
Navigate CMS <= 2.9.4 - Server-Side Request Forgery (Authenticated)
CVE-2022-2811706 abr 2022
A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the ap
43RISCO
abrir
GitHub PoC2
The demo code showing the recent Spring4Shell RCE (CVE-2022-22965)
CVE-2022-22965CRITICALsob ataque06 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC12
Spring-Cloud-Spel-RCE
CVE-2022-22947CRITICALsob ataque06 abr 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC1
🚨 Exploit the CVE-2025-49844 Redis Lua interpreter UAF vulnerability to execute arbitrary shellcode and gain persistent backdoor access.
CVE-2025-49844CRITICAL06 abr 2022
Redis Lua Use-After-Free may lead to remote code execution
85RISCO
abrir
GitHub PoC3
Unquoted Service Path privilege escalation vulnerability in Sherpa Connector Service.
CVE-2022-2390906 abr 2022
There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might
23RISCO
abrir
GitHub PoC1
sh-ubh/CVE-2018-1002105
CVE-2018-1002105CRITICAL06 abr 2022
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISCO
abrir
GitHub PoC3
Exploit Of Spring4Shell!
CVE-2022-22965CRITICALsob ataque05 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC2
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
CVE-2022-22965CRITICALsob ataque05 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC1
CVE-2022-22963 research
CVE-2022-22963CRITICALsob ataque05 abr 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
GitHub PoC
Spring Framework RCE Exploit
CVE-2022-22965CRITICALsob ataque05 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC
Spring4Shell is a critical RCE vulnerability in the Java Spring Framework and is one of three related vulnerabilities published on March 30
CVE-2022-22965CRITICALsob ataque05 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC1
Spring has Confirmed the RCE in Spring Framework. The team has just published the statement along with the mitigation guides for the issue. Now, this vulnerability can be tracked as CVE-2022-22965.
CVE-2022-22965CRITICALsob ataque05 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC3
CVE-2020-24186的攻击脚本
CVE-2020-24186CRITICAL05 abr 2022
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RISCO
abrir
GitHub PoC
CVE-2022-22947 reproduce
CVE-2022-22947CRITICALsob ataque05 abr 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC40
CVE-2021-22555 exploit rewritten with pipe primitive
CVE-2021-22555HIGHsob ataque05 abr 2022
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISCO
abrir
GitHub PoC16
CVE-2022-0185 exploit rewritten with pipe primitive
CVE-2022-0185HIGHsob ataque05 abr 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RISCO
abrir
GitHub PoC12
Vulnerability scanner for Spring4Shell (CVE-2022-22965)
CVE-2022-22965CRITICALsob ataque04 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC3
Another spring4shell (Spring core RCE) POC
CVE-2022-22965CRITICALsob ataque04 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC2
Spring4Shell - CVE-2022-22965
CVE-2022-22965CRITICALsob ataque04 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC2
Intentionally vulnerable Spring app to test CVE-2022-22965
CVE-2022-22965CRITICALsob ataque04 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC1
PowerShell port of CVE-2022-22965 vulnerability check by colincowie.
CVE-2022-22965CRITICALsob ataque04 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC128
A REAL DoS exploit for CVE-2022-21907
CVE-2022-21907CRITICAL04 abr 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC7
CVE-2022-22965 (Spring4Shell) Proof of Concept
CVE-2022-22965CRITICALsob ataque04 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC
Proof-of-concept exploit for CVE-2016-1827 on OS X Yosemite.
CVE-2016-182704 abr 2022
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RISCO
abrir
GitHub PoC2
Spring Cloud Function SpEL - cve-2022-22963
CVE-2022-22963CRITICALsob ataque03 abr 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
GitHub PoC
Linux “Dirty Pipe” vulnerability gives unprivileged users root access
CVE-2022-0847HIGHsob ataque03 abr 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC8
Nmap Spring4Shell NSE script for Spring Boot RCE (CVE-2022-22965)
CVE-2022-22965CRITICALsob ataque03 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC16
Docker PoC for CVE-2022-22965 with Spring Boot version 2.6.5
CVE-2022-22965CRITICALsob ataque03 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC
mwojterski/cve-2022-22965
CVE-2022-22965CRITICALsob ataque02 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
anteriorpágina 323 / 463próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.