Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.192exploits catalogados
37.765CVEs com exploração pública
24.695testados em laboratório
15.542 exploits
GitHub PoC4
CVE-2022-22965
CVE-2022-22965CRITICALsob ataque01 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC3
Prova de conceito para a vulnerabilidade Polkit Pkexec: CVE-2021-4034(Pkexec Local Privilege Escalation)
CVE-2021-4034HIGHsob ataqueransomware01 abr 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC1
Spring-Cloud-Gateway-CVE-2022-22947
CVE-2022-22947CRITICALsob ataque01 abr 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC39
批量无损检测CVE-2022-22965
CVE-2022-22965CRITICALsob ataque01 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC
Showcase of overridding the Spring Framework version in older Spring Boot versions
CVE-2022-22965CRITICALsob ataque01 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC1
helsecert/CVE-2022-22965
CVE-2022-22965CRITICALsob ataque01 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC1
puckiestyle/CVE-2022-22963
CVE-2022-22963CRITICALsob ataque31 mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
GitHub PoC19
Spring Cloud Function Vulnerable Application / CVE-2022-22963
CVE-2022-22963CRITICALsob ataque31 mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
GitHub PoC
Threat Intelligence on Zero-Day for Spring4Shell (CVE-2010-1622)
CVE-2010-162231 mar 2022
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote at
35RISCO
abrir
GitHub PoC26
springFramework_CVE-2022-22965_RCE简单利用
CVE-2022-22965CRITICALsob ataque31 mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC28
spring框架RCE漏洞 CVE-2022-22965
CVE-2022-22965CRITICALsob ataque31 mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC14
This includes CVE-2022-22963, a Spring SpEL / Expression Resource Access Vulnerability, as well as CVE-2022-22965, the spring-webmvc/spring-webflux RCE termed "SpringShell".
CVE-2022-22963CRITICALsob ataque31 mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
GitHub PoC19
CVE-2022-22965 - CVE-2010-1622 redux
CVE-2010-162231 mar 2022
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote at
35RISCO
abrir
GitHub PoC324
Dockerized Spring4Shell (CVE-2022-22965) PoC application and exploit
CVE-2022-22965CRITICALsob ataque31 mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC17
spring-core单个图形化利用工具,CVE-2022-22965及修复方案已出
CVE-2022-22965CRITICALsob ataque31 mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC13
CVE-2022-22965 poc including reverse-shell support
CVE-2022-22965CRITICALsob ataque31 mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC2
rwincey/spring4shell-CVE-2022-22965
CVE-2022-22965CRITICALsob ataque31 mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC44
A Safer PoC for CVE-2022-22965 (Spring4Shell)
CVE-2022-22965CRITICALsob ataque31 mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC6
Vulnerabilidad RCE en Spring Framework vía Data Binding on JDK 9+ (CVE-2022-22965 aka "Spring4Shell")
CVE-2022-22965CRITICALsob ataque31 mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC17
Spring Framework RCE (Quick pentest notes)
CVE-2022-22965CRITICALsob ataque31 mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC19
CVE-2022-22965 - CVE-2010-1622 redux
CVE-2022-22965CRITICALsob ataque31 mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC44
Exploit a vulnerable Spring application with the Spring4Shell (CVE-2022-22965) Vulnerability.
CVE-2022-22965CRITICALsob ataque31 mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC
DoTuan1/Reserch-CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware31 mar 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC32
Kirill89/CVE-2022-22965-PoC
CVE-2022-22965CRITICALsob ataque31 mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC1
tuo4n8/CVE-2022-24760
CVE-2022-24760CRITICAL31 mar 2022
Command Injection in Parse server
60RISCO
abrir
GitHub PoC1
Exploit for Dirty-Pipe (CVE-2022-0847)
CVE-2022-0847HIGHsob ataque31 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC9
Kirill89/CVE-2022-22963-PoC
CVE-2022-22963CRITICALsob ataque30 mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
GitHub PoC34
darryk10/CVE-2022-22963
CVE-2022-22963CRITICALsob ataque30 mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
GitHub PoC3
A TLS server using a vendored fork of the Go TLS stack that has renegotation indication extension forcibly disabled.
CVE-2009-3555CRITICAL30 mar 2022
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS
70RISCO
abrir
GitHub PoC
Spring Cloud Gateway Actuator API SpEL Code Injection.
CVE-2022-22947CRITICALsob ataque30 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
anteriorpágina 374 / 519próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.