Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.419exploits catalogados
38.564CVEs com exploração pública
24.695testados em laboratório
82.419 exploits
GitHub PoC★ 7
The manage engine mass loader for CVE-2022-47966
CVE-2022-47966CRITICALsob ataqueransomware23 jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISCO
abrir ↗
GitHub PoC★ 2
Run on your ManageEngine server
CVE-2022-47966CRITICALsob ataqueransomware23 jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISCO
abrir ↗
GitHub PoC★ 28
Python scanner for CVE-2022-47966. Supports ~10 of the 24 affected products.
CVE-2022-47966CRITICALsob ataqueransomware23 jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISCO
abrir ↗
GitHub PoC★ 8
A critical command injection vulnerability was found in multiple API endpoints of the Atlassian Bit bucket Server and Data center. This vulnerability affects all versions of Bitbucket Server and Data Center released before versions <7.6.17, <7.17.10, <7.21.4, <8.0.3, <8.1.2, <8.2.2, and <8.3.1
CVE-2022-36804HIGHsob ataque23 jan 2023
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-47966CRITICALsob ataqueransomware23 jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2022-47966CRITICALsob ataqueransomware23 jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISCO
abrir ↗
GitHub PoC
it is the official Fix of Wordpress CVE-2018-6389.
CVE-2018-6389—23 jan 2023
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2020-25213CRITICALsob ataque22 jan 2023
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISCO
abrir ↗
GitHub PoC★ 6
Python exploit for RCE in Wordpress
CVE-2020-25213CRITICALsob ataque22 jan 2023
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISCO
abrir ↗
GitHub PoC★ 2
Tool to search for IOCs related to HAFNIUM: CVE-2021-26855 CVE-2021-26857 CVE-2021-26858 CVE-2021-27065
CVE-2021-26855CRITICALsob ataqueransomware22 jan 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir ↗
GitHub PoC★ 164
A script to automate privilege escalation with CVE-2023-22809 vulnerability
CVE-2023-22809HIGH21 jan 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir ↗
GitHub PoC★ 1
Demo webapp vulnerable to CVE-2022-44900
CVE-2022-44900CRITICAL21 jan 2023
A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and ea
48RISCO
abrir ↗
GitHub PoC★ 4
Remote Code Execution in Social Warfare Plugin before 3.5.3 for Wordpress.
CVE-2019-9978MEDIUMsob ataque20 jan 2023
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2019-9978MEDIUMsob ataque20 jan 2023
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-47966CRITICALsob ataqueransomware19 jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISCO
abrir ↗
GitHub PoC
PoC for cve-2022-47966
CVE-2022-47966CRITICALsob ataqueransomware19 jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISCO
abrir ↗
VulnCheck XDB
denial-of-service
CVE-2022-42864HIGH19 jan 2023
A race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, ma
41RISCO
abrir ↗
Metasploit600
Sudoedit Extra Arguments Priv Esc
CVE-2023-22809HIGH18 jan 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir ↗
Metasploit600
Oracle Weblogic PreAuth Remote Command Execution via ForeignOpaqueReference IIOP Deserialization
CVE-2023-21839HIGHsob ataque17 jan 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-47966CRITICALsob ataqueransomware17 jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISCO
abrir ↗
GitHub PoC
Project for the Cyberspace Security class.
CVE-2017-8917—17 jan 2023
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-40684CRITICALsob ataqueransomware17 jan 2023
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir ↗
GitHub PoC
notareaperbutDR34P3r/CVE-2022-40684-Rust
CVE-2022-40684CRITICALsob ataqueransomware17 jan 2023
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir ↗
GitHub PoC★ 2
CVE-2014-5460
CVE-2014-5460—17 jan 2023
Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remot
60RISCO
abrir ↗
GitHub PoC★ 1
test for the ioc described for FG-IR-22-398
CVE-2022-42475CRITICALsob ataqueransomware17 jan 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISCO
abrir ↗
GitHub PoC★ 129
POC for CVE-2022-47966 affecting multiple ManageEngine products
CVE-2022-47966CRITICALsob ataqueransomware17 jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISCO
abrir ↗
GitHub PoC★ 2
A POC on how to exploit CVE-2022-27518
CVE-2022-27518CRITICALsob ataque17 jan 2023
Unauthenticated remote arbitrary code execution
78RISCO
abrir ↗
GitHub PoC★ 3
RCE POC for CVE-2022-46169
CVE-2022-46169CRITICALsob ataque16 jan 2023
Unauthenticated Command Injection
100RISCO
abrir ↗
GitHub PoC
Exploit For OverlayFS
CVE-2021-3493HIGHsob ataque16 jan 2023
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALsob ataque16 jan 2023
Unauthenticated Command Injection
100RISCO
abrir ↗
← anteriorpágina 602 / 2.748próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.