Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.192exploits catalogados
37.765CVEs com exploração pública
24.695testados em laboratório
15.542 exploits
GitHub PoC7
CVE-2022-24112: Apache APISIX Remote Code Execution Vulnerability
CVE-2022-24112CRITICALsob ataque08 mar 2022
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RISCO
abrir
GitHub PoC1
ITMarcin2211/CVE-2022-0847-DirtyPipe-Exploit
CVE-2022-0847HIGHsob ataque08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC72
Bash script to check for CVE-2022-0847 "Dirty Pipe"
CVE-2022-0847HIGHsob ataque08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC1
Docker exploit
CVE-2022-0847HIGHsob ataque08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC21
CVE-2022-0847: Linux Kernel Privilege Escalation Vulnerability
CVE-2022-0847HIGHsob ataque08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC49
CVE-2022-0847 DirtyPipe Exploit.
CVE-2022-0847HIGHsob ataque08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC2
An exploit for CVE-2022-0847 dirty-pipe vulnerability
CVE-2022-0847HIGHsob ataque08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC1
These Metasploit, Nmap, Python and Ruby scripts detects and exploits CVE-2021-41773 with RCE and local file disclosure.
CVE-2021-41773HIGHsob ataqueransomware08 mar 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC35
CVE-2022-22947_EXP,CVE-2022-22947_RCE,CVE-2022-22947反弹shell,CVE-2022-22947 getshell
CVE-2022-22947CRITICALsob ataque08 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC58
Linux Kernel Local Privilege Escalation Vulnerability CVE-2022-0847.
CVE-2022-0847HIGHsob ataque08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC2
puckiestyle/CVE-2022-0847
CVE-2022-0847HIGHsob ataque08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC14
Implementation of Max Kellermann's exploit for CVE-2022-0847
CVE-2022-0847HIGHsob ataque08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC6
CVE-2022-0847
CVE-2022-0847HIGHsob ataque08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC2
CVE-2022-24990:TerraMaster TOS 通过 PHP 对象实例化执行未经身份验证的远程命令
CVE-2022-24990CRITICALsob ataqueransomware08 mar 2022
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agen
100RISCO
abrir
GitHub PoC46
The Dirty Pipe Vulnerability
CVE-2022-0847HIGHsob ataque08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC6
Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947)批量检测工具
CVE-2022-22947CRITICALsob ataque07 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC9
Vulnerability in the Linux kernel since 5.8
CVE-2022-0847HIGHsob ataque07 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC10
CVE-2022-0847 exploit one liner
CVE-2022-0847HIGHsob ataque07 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC281
CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞,可覆盖重写任意可读文件中的数据,从而可将普通权限的用户提升到特权 root。 CVE-2022-0847 的漏洞原理类似于 CVE-2016-5195 脏牛漏洞(Dirty Cow),但它更容易被利用。漏洞作者将此漏洞命名为“Dirty Pipe”
CVE-2022-0847HIGHsob ataque07 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC50
CVE-2022-0847
CVE-2022-0847HIGHsob ataque07 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC7
Spring Cloud Gateway Actuator API SpEL Code Injection (CVE-2022-22947)
CVE-2022-22947CRITICALsob ataque07 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC1
SpringCloudGatewayRCE / Code By:Jun_sheng
CVE-2022-22947CRITICALsob ataque07 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC281
CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞,可覆盖重写任意可读文件中的数据,从而可将普通权限的用户提升到特权 root。 CVE-2022-0847 的漏洞原理类似于 CVE-2016-5195 脏牛漏洞(Dirty Cow),但它更容易被利用。漏洞作者将此漏洞命名为“Dirty Pipe”
CVE-2016-5195HIGHsob ataque07 mar 2022
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC6
darkb1rd/cve-2022-22947
CVE-2022-22947CRITICALsob ataque07 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC1.131
A root exploit for CVE-2022-0847 (Dirty Pipe)
CVE-2022-0847HIGHsob ataque07 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC14
Spring Cloud Gateway远程代码执行漏洞POC,基于命令执行的基础上,增加了反弹shell操作
CVE-2022-22947CRITICALsob ataque07 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC113
Webmin <=1.984, CVE-2022-0824 Post-Auth Reverse Shell PoC
CVE-2022-0824HIGH06 mar 2022
Improper Access Control to Remote Code Execution in webmin/webmin
78RISCO
abrir
GitHub PoC11
A script to check if a container environment is vulnerable to container escapes via CVE-2022-0492
CVE-2022-0492HIGHsob ataque06 mar 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RISCO
abrir
GitHub PoC2
22ke/CVE-2022-22947
CVE-2022-22947CRITICALsob ataque05 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC8
9lyph/CVE-2022-29593
CVE-2022-29593MEDIUM04 mar 2022
relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post reques
38RISCO
abrir
anteriorpágina 379 / 519próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.