Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.192exploits catalogados
37.765CVEs com exploração pública
24.695testados em laboratório
15.542 exploits
GitHub PoC
qq1549176285/CVE-2022-23131
CVE-2022-23131CRITICALsob ataque18 fev 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISCO
abrir
GitHub PoC154
cve-2022-23131 zabbix-saml-bypass-exp
CVE-2022-23131CRITICALsob ataque18 fev 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISCO
abrir
GitHub PoC3
1mxml/CVE-2022-23131
CVE-2022-23131CRITICALsob ataque18 fev 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISCO
abrir
GitHub PoC37
CVE-2022-0185 POC and Docker and Analysis write up
CVE-2022-0185HIGHsob ataque18 fev 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RISCO
abrir
GitHub PoC5
Hotel Druid 3.0.3 Code Injection to Remote Code Execution
CVE-2022-2290917 fev 2022
HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attack
35RISCO
abrir
GitHub PoC1
An exploit script of CVE-2016-5195
CVE-2016-5195HIGHsob ataque17 fev 2022
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC2
pkexec EoP exploit
CVE-2021-4034HIGHsob ataqueransomware17 fev 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
POC en Python para el CVE-2012-2982 mejorado del original por el usuario @OstojaOfficial
CVE-2012-298216 fev 2022
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISCO
abrir
GitHub PoC
Rust implementation of the Log 4 Shell (log 4 j - CVE-2021-44228)
CVE-2021-44228CRITICALsob ataqueransomware16 fev 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Build the struts-2.3.31 (CVE-2017-5638) environment
CVE-2017-5638CRITICALsob ataqueransomware15 fev 2022
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC28
CVE-2021-4034 centos8可用版本
CVE-2021-4034HIGHsob ataqueransomware15 fev 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC51
SAP memory pipes(MPI) desynchronization vulnerability CVE-2022-22536.
CVE-2022-22536CRITICALsob ataque15 fev 2022
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RISCO
abrir
GitHub PoC4
SQL Injection Vulnerability on PhpIPAM v1.4.4
CVE-2022-2304615 fev 2022
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su
28RISCO
abrir
GitHub PoC6
r1l4-i3pur1l4/CVE-2022-21882
CVE-2022-21882HIGHsob ataqueransomware14 fev 2022
Win32k Elevation of Privilege Vulnerability
98RISCO
abrir
GitHub PoC
CVE-2021-3156 deep dive.
CVE-2021-3156HIGHsob ataque14 fev 2022
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC2
All stages of exploring the polkit CVE-2021-4034 using codeql
CVE-2021-4034HIGHsob ataqueransomware14 fev 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC8
f4T1H's PoC script for CVE-2021-3560 Polkit D-Bus Privilege Escalation
CVE-2021-3560HIGHsob ataque13 fev 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir
GitHub PoC32
pwncat module that automatically exploits CVE-2021-4034 (pwnkit)
CVE-2021-4034HIGHsob ataqueransomware13 fev 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC3
A simple PWNKIT file to convert you to root
CVE-2021-4034HIGHsob ataqueransomware13 fev 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
Python exploit for CVE-2017-8917 - Joomla 3.7.0 'com_fields' SQL Injection
CVE-2017-891713 fev 2022
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISCO
abrir
GitHub PoC2
A tool to automate the exploit PWNKIT (CVE-2021-4034)
CVE-2021-4034HIGHsob ataqueransomware13 fev 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC3
Log4j vulner testing environment based on CVE-2021-44228. It provide guidance to build the sample infrastructure and the exploit scripts. Supporting cooki3 script as the main exploit tools & integration
CVE-2021-44228CRITICALsob ataqueransomware12 fev 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
an0n7os/CVE-2021-4034
CVE-2021-4034HIGHsob ataqueransomware12 fev 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
This repository is for Log4j 2021 (CVE-2021-44228) Vulnerability demonstration and mitigation.
CVE-2021-44228CRITICALsob ataqueransomware12 fev 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC17
purple-WL/wordpress-CVE-2022-21661
CVE-2022-21661HIGH12 fev 2022
SQL injection in WordPress
78RISCO
abrir
GitHub PoC1
purple-WL/Jenkins_CVE-2019-1003000
CVE-2019-100300012 fev 2022
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISCO
abrir
GitHub PoC
CVE-2014-1767在win7_x64平台的EXP和分析文章
CVE-2014-176712 fev 2022
Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Wind
28RISCO
abrir
GitHub PoC
pwnkit exploit
CVE-2021-4034HIGHsob ataqueransomware11 fev 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
docker lab setup for kibana-7609
CVE-2019-7609CRITICALsob ataque10 fev 2022
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISCO
abrir
GitHub PoC2
An "Incorrect Use of a Privileged API" vulnerability in PrintixService.exe, in Printix's "Printix Secure Cloud Print Management", Version 1.3.1106.0 and below allows a Local Or Remote attacker the ability change all HKEY Windows Registry values as SYSTEM context via the UITasks.PersistentRegistryData parameter.
CVE-2022-2508910 fev 2022
Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL
28RISCO
abrir
anteriorpágina 382 / 519próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.