Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.419exploits catalogados
38.564CVEs com exploração pública
24.695testados em laboratório
82.419 exploits
VulnCheck XDB
initial-access
CVE-2023-3519CRITICALsob ataqueransomware20 dez 2022
Unauthenticated remote code execution
100RISCO
abrir ↗
GitHub PoC
devengpk/CVE-2022-36804
CVE-2022-36804HIGHsob ataque20 dez 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir ↗
GitHub PoC★ 6
Proof of concept of CVE-2022-24086
CVE-2022-24086CRITICALsob ataque20 dez 2022
Adobe Commerce checkout improper input validation leads to remote code execution
100RISCO
abrir ↗
GitHub PoC★ 1
devengpk/CVE-2022-29464
CVE-2022-29464CRITICALsob ataqueransomware18 dez 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALsob ataqueransomware18 dez 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2022-46689HIGH17 dez 2022
A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macO
68RISCO
abrir ↗
Metasploit600
macOS Dirty Cow Arbitrary File Write Local Privilege Escalation
CVE-2022-46689HIGH17 dez 2022
A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macO
68RISCO
abrir ↗
GitHub PoC
Drupal CVE-2018-7600 RCE Pseudo-Shell PoC
CVE-2018-7600CRITICALsob ataqueransomware17 dez 2022
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir ↗
GitHub PoC
By passing an overly large string when invoking nethack, it is possible to corrupt memory. jnethack and falconseye are also prone to this vulnerability.
CVE-2003-0358—17 dez 2022
Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allow
23RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALsob ataqueransomware17 dez 2022
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALsob ataque16 dez 2022
Unauthenticated Command Injection
100RISCO
abrir ↗
GitHub PoC
Chương trình theo dõi, giám sát lưu lượng mạng được viết bằng Python, nó sẽ đưa ra cảnh báo khi phát hiện tấn công CVE-2017-0144
CVE-2017-0144HIGHsob ataqueransomware16 dez 2022
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir ↗
GitHub PoC★ 1
CVE-2022-46169 - Cacti Blind Remote Code Execution (Pre-Auth)
CVE-2022-46169CRITICALsob ataque16 dez 2022
Unauthenticated Command Injection
100RISCO
abrir ↗
GitHub PoC
CVE-2020-0796-利用工具
CVE-2020-0796CRITICALsob ataqueransomware15 dez 2022
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir ↗
GitHub PoC★ 3
An exploit for CVE-2012-2982 implemented in Rust
CVE-2012-2982—15 dez 2022
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2017-0143HIGHsob ataqueransomware15 dez 2022
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir ↗
GitHub PoC
A Proof of Concept for the CVE-2021-27928 flaw exploitation
CVE-2021-27928—14 dez 2022
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, a
35RISCO
abrir ↗
GitHub PoC★ 3
cve-2019-11510, cve-2019-19781, cve-2020-5902,               cve-2021-1497, cve-2021-20090, cve-2021-22006, cve-2021-22205, cve-2021-26084, cve-2021-26855, cve-2021-26857, cve-2021–26857, cve-2021–26858, cve-2021–26865
CVE-2020-5902CRITICALsob ataqueransomware13 dez 2022
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware13 dez 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗
GitHub PoC★ 3
cve-2019-11510, cve-2019-19781, cve-2020-5902,               cve-2021-1497, cve-2021-20090, cve-2021-22006, cve-2021-22205, cve-2021-26084, cve-2021-26855, cve-2021-26857, cve-2021–26857, cve-2021–26858, cve-2021–26865
CVE-2019-11510CRITICALsob ataqueransomware13 dez 2022
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISCO
abrir ↗
GitHub PoC★ 3
cve-2019-11510, cve-2019-19781, cve-2020-5902,               cve-2021-1497, cve-2021-20090, cve-2021-22006, cve-2021-22205, cve-2021-26084, cve-2021-26855, cve-2021-26857, cve-2021–26857, cve-2021–26858, cve-2021–26865
CVE-2021-1497CRITICALsob ataque13 dez 2022
Cisco HyperFlex HX Command Injection Vulnerabilities
100RISCO
abrir ↗
GitHub PoC★ 3
Improper access control in SAP NetWeaver Process Integration
CVE-2022-41272CRITICAL13 dez 2022
An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Se
48RISCO
abrir ↗
GitHub PoC
Educational Follina PoC Tool
CVE-2022-30190HIGHsob ataqueransomware12 dez 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALsob ataque12 dez 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir ↗
GitHub PoC
devengpk/CVE-2022-22965
CVE-2022-22965CRITICALsob ataque12 dez 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir ↗
GitHub PoC
KaviDk/CVE-2019-6447-in-Mobile-Application
CVE-2019-6447—12 dez 2022
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISCO
abrir ↗
GitHub PoC
CVE-2020-16846
CVE-2020-16846CRITICALsob ataque12 dez 2022
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH clien
100RISCO
abrir ↗
GitHub PoC★ 7
CVE-2021-3129 Exploit Checker By ./MrMad
CVE-2021-3129CRITICALsob ataqueransomware10 dez 2022
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-36537HIGHsob ataqueransomware09 dez 2022
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafte
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-36537HIGHsob ataqueransomware09 dez 2022
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafte
100RISCO
abrir ↗
← anteriorpágina 607 / 2.748próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.