Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.192exploits catalogados
37.765CVEs com exploração pública
24.695testados em laboratório
15.542 exploits
GitHub PoC15
Apache APISIX Remote Code Execution (CVE-2022-24112) proof of concept exploit
CVE-2022-24112CRITICALsob ataque16 mar 2022
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RISCO
abrir
GitHub PoC96
CVE-2022-0543_RCE,Redis Lua沙盒绕过 命令执行
CVE-2022-0543CRITICALsob ataque16 mar 2022
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RISCO
abrir
GitHub PoC
si1ent-le/CVE-2019-5736
CVE-2019-573616 mar 2022
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
GitHub PoC1
bysinks/CVE-2022-22947
CVE-2022-22947CRITICALsob ataque15 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC2
PoC Container Breakout for DirtyPipe Vulnerability CVE-2022-0847
CVE-2022-0847HIGHsob ataque15 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC
NHPT/CVE-2022-24086-RCE
CVE-2022-24086CRITICALsob ataque15 mar 2022
Adobe Commerce checkout improper input validation leads to remote code execution
100RISCO
abrir
GitHub PoC
githublihaha/DirtyPIPE-CVE-2022-0847
CVE-2022-0847HIGHsob ataque15 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC3
Python script to check if your kernel is vulnerable to Dirty pipe CVE-2022-0847
CVE-2022-0847HIGHsob ataque15 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC
Fa1c0n35/CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware14 mar 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
pkexec --> privilege escalation
CVE-2021-4034HIGHsob ataqueransomware14 mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC2
dirtypipe
CVE-2022-0847HIGHsob ataque14 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC3
Implementation of CVE-2022-0847 as a shellcode
CVE-2022-0847HIGHsob ataque14 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC2
Exploits for Hotel Druid 3.0.3 - Remote Code Execution (RCE) CVE-2022-22909
CVE-2022-2290914 mar 2022
HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attack
35RISCO
abrir
GitHub PoC
Exploit for the Rails CVE-2019-5420
CVE-2019-542014 mar 2022
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISCO
abrir
GitHub PoC15
CVE-2022-0847 POC
CVE-2022-0847HIGHsob ataque14 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC12
spring-cloud-gateway-rce CVE-2022-22947
CVE-2022-22947CRITICALsob ataque13 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC1
Dirty Pipe (CVE-2022-0847) zafiyeti kontrolü
CVE-2022-0847HIGHsob ataque13 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC3
CVE-2022-0847 (Dirty Pipe) is an arbitrary file overwrite vulnerability that allows escalation of privileges by modifying or overwriting arbitrary read-only files e.g. /etc/passwd, /etc/shadow.
CVE-2022-0847HIGHsob ataque13 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC
CVE-2021-4034 (PWNKIT).
CVE-2021-4034HIGHsob ataqueransomware13 mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC4
CVE-2022-0847 Python exploit to get root or write a no write permission, immutable or read-only mounted file.
CVE-2022-0847HIGHsob ataque12 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC113
Apache2 2.4.49 - LFI & RCE Exploit - CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware12 mar 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC6
my personal exploit of CVE-2022-0847(dirty pipe)
CVE-2022-0847HIGHsob ataque12 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC735
A collection of exploits and documentation that can be used to exploit the Linux Dirty Pipe vulnerability.
CVE-2022-0847HIGHsob ataque12 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC
Log4j2组件命令执行RCE / Code By:Jun_sheng
CVE-2021-44228CRITICALsob ataqueransomware11 mar 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC10
A Python-based DirtyPipe (CVE-2022-0847) POC to pop a root shell
CVE-2022-0847HIGHsob ataque11 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC
Greetdawn/CVE-2022-0847-DirtyPipe-
CVE-2022-0847HIGHsob ataque11 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC32
CVE-2022-0492 EXP and Analysis write up
CVE-2022-0492HIGHsob ataque11 mar 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RISCO
abrir
GitHub PoC2
dskmehra/CVE-2022-0848
CVE-2022-0848CRITICAL11 mar 2022
OS Command Injection in part-db/part-db
60RISCO
abrir
GitHub PoC
cve-2022-22947-docker
CVE-2022-22947CRITICALsob ataque11 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC
HERRAMIENTA AUTOMATIZADA PARA LA DETECCION DE LA VULNERABILIDAD CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware10 mar 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
anteriorpágina 377 / 519próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.