Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.064exploits catalogados
37.667CVEs com exploração pública
24.695testados em laboratório
15.521 exploits
GitHub PoC2
PoC of CVE-2022-24086
CVE-2022-24086CRITICALsob ataque01 out 2022
Adobe Commerce checkout improper input validation leads to remote code execution
100RISCO
abrir
GitHub PoC18
A loader for zimbra 2022 rce (cve-2022-27925)
CVE-2022-27925HIGHsob ataqueransomware01 out 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISCO
abrir
GitHub PoC
WonderCMS 3.1.3 - Authenticated Remote Code Execution
CVE-2020-3531401 out 2022
A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, al
28RISCO
abrir
GitHub PoC3
Tool for mass testing ZeroLogon vulnerability CVE-2020-1472
CVE-2020-1472MEDIUMsob ataqueransomware30 set 2022
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
Laravel debug mode - Remote Code Execution (RCE)
CVE-2021-3129CRITICALsob ataqueransomware30 set 2022
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC
Tool for mass testing ZeroLogon vulnerability CVE-2020-1472
CVE-2020-1472MEDIUMsob ataqueransomware30 set 2022
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC51
cosad3s/CVE-2022-35914-poc
CVE-2022-35914CRITICALsob ataque30 set 2022
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISCO
abrir
GitHub PoC7
CVE-2020-8813 - RCE through graph_realtime.php in Cacti 1.2.8
CVE-2020-881330 set 2022
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RISCO
abrir
GitHub PoC2
Golang Proof of Concept Exploit for CVE-2021-44077: PreAuth RCE in ManageEngine ServiceDesk Plus < 11306
CVE-2021-44077CRITICALsob ataque29 set 2022
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014
100RISCO
abrir
GitHub PoC7
CVE-2022-39197
CVE-2022-39197MEDIUMsob ataque27 set 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISCO
abrir
GitHub PoC12
A loader for bitbucket 2022 rce (cve-2022-36804)
CVE-2022-36804HIGHsob ataque26 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
GitHub PoC18
cobaltstrike4.5版本破解、去除checksum8特征、bypass BeaconEye、修复错误路径泄漏stage、增加totp双因子验证、修复CVE-2022-39197等
CVE-2022-39197MEDIUMsob ataque26 set 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISCO
abrir
GitHub PoC317
CVE-2022-39197 漏洞补丁. CVE-2022-39197 Vulnerability Patch.
CVE-2022-39197MEDIUMsob ataque26 set 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISCO
abrir
GitHub PoC
Pandora-research/CVE-2018-0114-Exploit
CVE-2018-011426 set 2022
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISCO
abrir
GitHub PoC12
A loader for bitbucket 2022 rce (cve-2022-36804)
CVE-2022-36804HIGHsob ataque26 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
GitHub PoC8
CVE-2022-27925
CVE-2022-27925HIGHsob ataqueransomware25 set 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISCO
abrir
GitHub PoC7
A simple PoC for Atlassian Bitbucket RCE [CVE-2022-36804]
CVE-2022-36804HIGHsob ataque25 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
GitHub PoC18
CVE-2022-1040
CVE-2022-1040CRITICALsob ataque25 set 2022
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISCO
abrir
GitHub PoC3
You can find a python script to exploit the vulnerability on Bitbucket related CVE-2022-36804.
CVE-2022-36804HIGHsob ataque24 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
GitHub PoC
PoC exploit for CVE-2022-36804 (BitBucket Critical Command Injection)
CVE-2022-36804HIGHsob ataque24 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
GitHub PoC2
CVE-2016-2098 POC
CVE-2016-209824 set 2022
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISCO
abrir
GitHub PoC17
Cobalt Strike RCE CVE-2022-39197
CVE-2022-39197MEDIUMsob ataque24 set 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISCO
abrir
GitHub PoC1
purple-WL/Cobaltstrike-RCE-CVE-2022-39197
CVE-2022-39197MEDIUMsob ataque24 set 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISCO
abrir
GitHub PoC46
CVE-2022-39197(CobaltStrike XSS <=4.7) POC
CVE-2022-39197MEDIUMsob ataque23 set 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISCO
abrir
GitHub PoC4
PoC exploit for CVE-2022-36804 (BitBucket Critical Command Injection)
CVE-2022-36804HIGHsob ataque23 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
GitHub PoC
For detection of sitecore RCE - CVE-2021-42237
CVE-2021-42237CRITICALsob ataqueransomware22 set 2022
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it
100RISCO
abrir
GitHub PoC3
WSO2 Arbitrary File Upload to Remote Command Execution (RCE)
CVE-2022-29464CRITICALsob ataqueransomware22 set 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir
GitHub PoC
cobaltstrike4.5版本破/解、去除checksum8特征、bypass BeaconEye、修复错误路径泄漏stage、增加totp双因子验证、修复CVE-2022-39197等
CVE-2022-39197MEDIUMsob ataque22 set 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISCO
abrir
GitHub PoC73
cve-2022-39197 poc
CVE-2022-39197MEDIUMsob ataque22 set 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISCO
abrir
GitHub PoC3
PoC for exploiting CVE-2019-2729 on WebLogic
CVE-2019-2729CRITICAL22 set 2022
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
85RISCO
abrir
anteriorpágina 349 / 518próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.