Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.192exploits catalogados
37.765CVEs com exploração pública
24.695testados em laboratório
15.542 exploits
GitHub PoC
CVE-2019-18818/19606 Strapi RCE
CVE-2019-1881810 mar 2022
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISCO
abrir
GitHub PoC
PaoPaoLong-lab/Spring-CVE-2022-22947-
CVE-2022-22947CRITICALsob ataque10 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC
Exploit for CVE-2021-3156
CVE-2021-3156HIGHsob ataque10 mar 2022
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC
A root exploit for CVE-2022-0847 (Dirty Pipe)
CVE-2022-0847HIGHsob ataque10 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC4
仅仅是poc,并不是exp
CVE-2022-24990CRITICALsob ataqueransomware10 mar 2022
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agen
100RISCO
abrir
GitHub PoC
osungjinwoo/CVE-2022-0847-Dirty-Pipe
CVE-2022-0847HIGHsob ataque10 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC
CVE-2022-0847-DirtyPipe-Exploit
CVE-2022-0847HIGHsob ataque10 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC25
CVE-2022-0847 POC and Docker and Analysis write up
CVE-2022-0847HIGHsob ataque10 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC
edsonjt81/CVE-2022-0847-Linux
CVE-2022-0847HIGHsob ataque10 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC
babyshen/CVE-2019-13272
CVE-2019-13272HIGHsob ataque10 mar 2022
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
GitHub PoC
osungjinwoo/CVE-2021-22205-gitlab
CVE-2021-22205CRITICALsob ataqueransomware10 mar 2022
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir
GitHub PoC
edsonjt81/CVE-2021-4034-Linux
CVE-2021-4034HIGHsob ataqueransomware10 mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
HERRAMIENTA AUTOMATIZADA PARA LA DETECCION DE LA VULNERABILIDAD CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware10 mar 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
ThinkAdmin CVE-2020-25540 POC
CVE-2020-2554009 mar 2022
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on
60RISCO
abrir
GitHub PoC
Springboot web application accepts a name get parameter and logs its value to log4j2. Vulnerable to CVE-2021-44228.
CVE-2021-44228CRITICALsob ataqueransomware09 mar 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Polkit's Pkexec CVE-2021-4034 Proof Of Concept and Patching
CVE-2021-4034HIGHsob ataqueransomware09 mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
Greetdawn/CVE-2022-0847-DirtyPipe
CVE-2022-0847HIGHsob ataque09 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC
AyoubNajim/cve-2022-0847dirtypipe-exploit
CVE-2022-0847HIGHsob ataque09 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC91
CVE-2022-0847
CVE-2022-0847HIGHsob ataque09 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC6
Mustafa1986/CVE-2022-0847-DirtyPipe-Exploit
CVE-2022-0847HIGHsob ataque09 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC2
A “Dirty Pipe” vulnerability with CVE-2022-0847 and a CVSS score of 7.8 has been identified, affecting Linux Kernel 5.8 and higher. The vulnerability allows attackers to overwrite data in read-only files. Threat actors can exploit this vulnerability to privilege themselves with code injection.
CVE-2022-0847HIGHsob ataque09 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC77
Container Excape PoC for CVE-2022-0847 "DirtyPipe"
CVE-2022-0847HIGHsob ataque09 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC
pentestblogin/pentestblog-CVE-2022-0847
CVE-2022-0847HIGHsob ataque09 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC3
Dirty Pipe POC
CVE-2022-0847HIGHsob ataque09 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC
Dirty Pipe (CVE-2022-0847) PoC that hijacks a SUID binary to spawn. a root shell. (and attempts to restore the damaged binary as well)
CVE-2022-0847HIGHsob ataque09 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC7
CVE-2022-24112: Apache APISIX Remote Code Execution Vulnerability
CVE-2022-24112CRITICALsob ataque08 mar 2022
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RISCO
abrir
GitHub PoC
CVE-2022-0487
CVE-2022-0847HIGHsob ataque08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC
bohr777/cve-2022-0847dirtypipe-exploit
CVE-2022-0847HIGHsob ataque08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC58
Linux Kernel Local Privilege Escalation Vulnerability CVE-2022-0847.
CVE-2022-0847HIGHsob ataque08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC1
ITMarcin2211/CVE-2022-0847-DirtyPipe-Exploit
CVE-2022-0847HIGHsob ataque08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
anteriorpágina 378 / 519próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.