Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.064exploits catalogados
37.667CVEs com exploração pública
24.695testados em laboratório
15.521 exploits
GitHub PoC
CVE-2020-16846
CVE-2020-16846CRITICALsob ataque12 dez 2022
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH clien
100RISCO
abrir
GitHub PoC
KaviDk/CVE-2019-6447-in-Mobile-Application
CVE-2019-644712 dez 2022
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISCO
abrir
GitHub PoC
devengpk/CVE-2022-22965
CVE-2022-22965CRITICALsob ataque12 dez 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC7
CVE-2021-3129 Exploit Checker By ./MrMad
CVE-2021-3129CRITICALsob ataqueransomware10 dez 2022
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC89
[PoC] Command injection via PDF import in Markdown Preview Enhanced (VSCode, Atom)
CVE-2022-45025CRITICAL09 dez 2022
Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerabi
60RISCO
abrir
GitHub PoC
Scan IP ranges for IP's vulnerable to the F5 Big IP exploit (CVE-2022-1388)
CVE-2022-1388CRITICALsob ataqueransomware09 dez 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir
GitHub PoC36
POC of CVE-2022-36537
CVE-2022-36537HIGHsob ataqueransomware09 dez 2022
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafte
100RISCO
abrir
GitHub PoC9
CVE-2022-36537
CVE-2022-36537HIGHsob ataqueransomware09 dez 2022
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafte
100RISCO
abrir
GitHub PoC20
text4shell(CVE-2022-42889) BurpSuite Scanner
CVE-2022-4288909 dez 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC47
CVE-2022-46169 Cacti remote_agent.php Unauthenticated Command Injection.
CVE-2022-46169CRITICALsob ataque08 dez 2022
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC
CVE-2022-46169
CVE-2022-46169CRITICALsob ataque07 dez 2022
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC1
CVE-2022-42889 - Text4Shell exploit
CVE-2022-4288907 dez 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC5
PHPunit Checker CVE-2017-9841 By MrMad
CVE-2017-9841CRITICALsob ataque07 dez 2022
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISCO
abrir
GitHub PoC1
amitlttwo/CVE-2022-1388
CVE-2022-1388CRITICALsob ataqueransomware06 dez 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir
GitHub PoC
For CVE-2022-33891 Apache Spark: Emulation and Detection by West Shepherd
CVE-2022-33891HIGHsob ataque06 dez 2022
Apache Spark shell command injection vulnerability via Spark UI
100RISCO
abrir
GitHub PoC1
Exploit for path transversal vulnerability in apache
CVE-2021-41773HIGHsob ataqueransomware05 dez 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
Spring-CVE-2010-1622
CVE-2010-162205 dez 2022
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote at
35RISCO
abrir
GitHub PoC
Exploit from perception point
CVE-2016-072804 dez 2022
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISCO
abrir
GitHub PoC
XiangSi-Howard/CTF---CVE-2011-2523
CVE-2011-252303 dez 2022
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC5
CVE-2022-24112_POC
CVE-2022-24112CRITICALsob ataque03 dez 2022
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RISCO
abrir
GitHub PoC1
JoshMorrison99/CVE-2016-3714
CVE-2016-3714HIGHsob ataque02 dez 2022
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RISCO
abrir
GitHub PoC2
Exchange CVE '22
CVE-2022-41082HIGHsob ataqueransomware01 dez 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
A Terraform module to launch Rancher 2.6.6 for blog article about CVE-2021-36782
CVE-2021-36782CRITICAL01 dez 2022
Rancher: Plaintext storage and exposure of credentials in Rancher API and cluster.management.cattle.io object
63RISCO
abrir
GitHub PoC
SilasSpringer/CVE-2018-10933
CVE-2018-10933CRITICAL01 dez 2022
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC
lkduy2602/Detecting-CVE-2018-15708-Vulnerabilities
CVE-2018-1570801 dez 2022
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP r
60RISCO
abrir
GitHub PoC3
revanmalang/CVE-2022-1388
CVE-2022-1388CRITICALsob ataqueransomware30 nov 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir
GitHub PoC2
Validation of Arbitrary File Read Vulnerabilities in Dell OpenManage Server Administrator (OMSA) - CVE-2016-4004, CVE-2021-21514 and CVE-2020-5377.
CVE-2016-400430 nov 2022
Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated adminis
23RISCO
abrir
GitHub PoC2
Validation of Arbitrary File Read Vulnerabilities in Dell OpenManage Server Administrator (OMSA) - CVE-2016-4004, CVE-2021-21514 and CVE-2020-5377.
CVE-2020-5377CRITICAL30 nov 2022
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.
60RISCO
abrir
GitHub PoC
fei9747/CVE-2016-5195
CVE-2016-5195HIGHsob ataque29 nov 2022
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC1
fei9747/CVE-2021-3493
CVE-2021-3493HIGHsob ataque29 nov 2022
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir
anteriorpágina 341 / 518próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.