Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.063exploits catalogados
37.667CVEs com exploração pública
24.695testados em laboratório
15.520 exploits
GitHub PoC129
POC for CVE-2022-47966 affecting multiple ManageEngine products
CVE-2022-47966CRITICALsob ataqueransomware17 jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISCO
abrir
GitHub PoC
Project for the Cyberspace Security class.
CVE-2017-891717 jan 2023
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISCO
abrir
GitHub PoC2
A POC on how to exploit CVE-2022-27518
CVE-2022-27518CRITICALsob ataque17 jan 2023
Unauthenticated remote arbitrary code execution
78RISCO
abrir
GitHub PoC
notareaperbutDR34P3r/CVE-2022-40684-Rust
CVE-2022-40684CRITICALsob ataqueransomware17 jan 2023
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir
GitHub PoC1
test for the ioc described for FG-IR-22-398
CVE-2022-42475CRITICALsob ataqueransomware17 jan 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISCO
abrir
GitHub PoC2
CVE-2014-5460
CVE-2014-546017 jan 2023
Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remot
60RISCO
abrir
GitHub PoC
Exploit For OverlayFS
CVE-2021-3493HIGHsob ataque16 jan 2023
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir
GitHub PoC3
RCE POC for CVE-2022-46169
CVE-2022-46169CRITICALsob ataque16 jan 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC3
cbk914/CVE-2022-26134_check
CVE-2022-26134CRITICALsob ataqueransomware15 jan 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC2
Cacti: Unauthenticated Remote Code Execution Exploit in Ruby
CVE-2022-46169CRITICALsob ataque15 jan 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC4
iliass-dahman/CVE-2022-22963-POC
CVE-2022-22963CRITICALsob ataque15 jan 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
GitHub PoC
nhamle2/CVE-2015-8660
CVE-2015-866015 jan 2023
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RISCO
abrir
GitHub PoC2
cbk914/CVE-2022-30525_check
CVE-2022-30525CRITICALsob ataque15 jan 2023
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RISCO
abrir
GitHub PoC1
CVE 2022-45299
CVE-2022-45299CRITICAL13 jan 2023
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplyi
48RISCO
abrir
GitHub PoC9
Exploit to CVE-2022-46169 vulnerability
CVE-2022-46169CRITICALsob ataque13 jan 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC6
Study and exploit the vulnerability CVE-2022-21661 that allows SQL Injections through plugins POST requests to WordPress versions below 5.8.3.
CVE-2022-21661HIGH13 jan 2023
SQL injection in WordPress
78RISCO
abrir
GitHub PoC2
cve-2010-1622 Learning Environment
CVE-2010-162211 jan 2023
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote at
35RISCO
abrir
GitHub PoC328
Wh04m1001/CVE-2023-21752
CVE-2023-21752HIGH10 jan 2023
Windows Backup Service Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC
CVE-2021-29447 - Authenticated XXE Injection - WordPress < 5.7.1 & PHP > 8
CVE-2021-29447HIGH10 jan 2023
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir
GitHub PoC1
.NET console application that exploits CVE-2018-9995 vulnerability
CVE-2018-999509 jan 2023
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
GitHub PoC
CVE-2017-7308 POC
CVE-2017-730809 jan 2023
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate cer
43RISCO
abrir
GitHub PoC28
CVE-2023-0297: The Story of Finding Pre-auth RCE in pyLoad
CVE-2023-0297CRITICAL09 jan 2023
Code Injection in pyload/pyload
85RISCO
abrir
GitHub PoC
G01d3nW01f/CVE-2021-43798
CVE-2021-43798HIGHsob ataque09 jan 2023
Grafana path traversal
100RISCO
abrir
GitHub PoC
CVE-2017-16995 Linux POC
CVE-2017-1699509 jan 2023
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISCO
abrir
GitHub PoC
zabbix saml bypass
CVE-2022-23131CRITICALsob ataque09 jan 2023
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISCO
abrir
GitHub PoC
Sophos EXploit
CVE-2022-1040CRITICALsob ataque08 jan 2023
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISCO
abrir
GitHub PoC37
CVE-2021-38003 exploits extracted from https://twitter.com/WhichbufferArda/status/1609604183535284224
CVE-2021-38003HIGHsob ataque07 jan 2023
Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially explo
83RISCO
abrir
GitHub PoC1
wr0x00/cve-2022-23131
CVE-2022-23131CRITICALsob ataque07 jan 2023
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISCO
abrir
GitHub PoC2
CVE-2018-19321
CVE-2018-19321HIGHsob ataqueransomware07 jan 2023
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, X
71RISCO
abrir
GitHub PoC26
Dell Driver EoP (CVE-2021-21551)
CVE-2021-21551HIGHsob ataque07 jan 2023
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISCO
abrir
anteriorpágina 338 / 518próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.