Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.419exploits catalogados
38.564CVEs com exploração pública
24.695testados em laboratório
82.445 exploits
GitHub PoC★ 257
Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含
CVE-2017-12615HIGHsob ataqueransomware13 nov 2022
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2019-9193—13 nov 2022
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir ↗
GitHub PoC★ 257
Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含
CVE-2020-1938CRITICALsob ataque13 nov 2022
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2018-19320HIGHsob ataqueransomware12 nov 2022
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RISCO
abrir ↗
GitHub PoC★ 359
Unsigned driver loader using CVE-2018-19320
CVE-2018-19320HIGHsob ataqueransomware12 nov 2022
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RISCO
abrir ↗
GitHub PoC
ivilpez/cve-2017-16995.c
CVE-2017-16995—12 nov 2022
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISCO
abrir ↗
Exploit-DB
CVAT 2.0 - Server Side Request Forgery
CVE-2022-31188HIGHwebappspython11 nov 2022
Server-Side Request Forgery Vulnerability in Computer Vision Annotation Tool (CVAT)
53RISCO
abrir ↗
GitHub PoC★ 109
Zimbra <9.0.0.p27 RCE
CVE-2022-41352CRITICALsob ataqueransomware11 nov 2022
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through ama
100RISCO
abrir ↗
Exploit-DB
SmartRG Router SR510n 2.6.13 - Remote Code Execution
CVE-2022-37661—remotehardware11 nov 2022
SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature.
35RISCO
abrir ↗
GitHub PoC★ 4
Exploit WordPress Media Library XML External Entity Injection (XXE) to exfiltrate files.
CVE-2021-29447HIGH11 nov 2022
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir ↗
Exploit-DB
MSNSwitch Firmware MNT.2408 - Remote Code Execution
CVE-2022-32429—remotehardware11 nov 2022
An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technolog
60RISCO
abrir ↗
Exploit-DB
AVEVA InTouch Access Anywhere Secure Gateway 2020 R2 - Path Traversal
CVE-2022-23854HIGHremotehardware11 nov 2022
AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an
68RISCO
abrir ↗
Exploit-DB
Open Web Analytics 1.7.3 - Remote Code Execution
CVE-2022-24637—webappsphp11 nov 2022
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISCO
abrir ↗
VulnCheck XDB
local
CVE-2022-0185HIGHsob ataque10 nov 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-42889—10 nov 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗
Metasploit300
POWERCOM UPSMON PRO Path Traversal (CVE-2022-38120) and Credential Harvester (CVE-2022-38121)
CVE-2022-38120MEDIUM10 nov 2022
POWERCOM CO., LTD. UPSMON PRO - Path Traversal
28RISCO
abrir ↗
Metasploit300
POWERCOM UPSMON PRO Path Traversal (CVE-2022-38120) and Credential Harvester (CVE-2022-38121)
CVE-2022-38121MEDIUM10 nov 2022
POWERCOM CO., LTD. UPSMON PRO - Insufficiently Protected Credentials
28RISCO
abrir ↗
GitHub PoC
Implementation of CVE-2022-30190 in C
CVE-2022-30190HIGHsob ataqueransomware10 nov 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir ↗
GitHub PoC
Joanmei/CVE-2017-0785
CVE-2017-0785—10 nov 2022
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RISCO
abrir ↗
GitHub PoC
SPRING DATA REST CVE-2017-8046 DEMO
CVE-2017-8046—10 nov 2022
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISCO
abrir ↗
GitHub PoC★ 1
CVE-2020-0796
CVE-2020-0796CRITICALsob ataqueransomware09 nov 2022
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir ↗
GitHub PoC★ 1
bantu2301/CVE-2018-16858
CVE-2018-16858HIGH09 nov 2022
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could
68RISCO
abrir ↗
GitHub PoC★ 2
A simple tool to enumerate users in gitlab
CVE-2022-1162CRITICAL09 nov 2022
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE
85RISCO
abrir ↗
Metasploit400
Lenovo Diagnostics Driver IOCTL memmove
CVE-2022-3699HIGH09 nov 2022
A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo
56RISCO
abrir ↗
VulnCheck XDB
local
CVE-2022-3699HIGH09 nov 2022
A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo
56RISCO
abrir ↗
GitHub PoC
The first poc video presenting the sql injection test from ( WordPress Core 5.8.2-'WP_Query' / CVE-2022-21661)
CVE-2022-21661HIGH08 nov 2022
SQL injection in WordPress
78RISCO
abrir ↗
GitHub PoC★ 1
DO NOT USE FOR ANYTHING REAL. Simple springboot sample app with vulnerability CVE-2021-44228 aka "Log4Shell"
CVE-2021-44228CRITICALsob ataqueransomware08 nov 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALsob ataque08 nov 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir ↗
Metasploit600
Acronis Cyber Protect/Backup remote code execution
CVE-2022-3405CRITICAL08 nov 2022
Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following
43RISCO
abrir ↗
GitHub PoC★ 4
CVE-2022-22965图形化检测工具
CVE-2022-22965CRITICALsob ataque08 nov 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir ↗
← anteriorpágina 612 / 2.749próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.