Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.451exploits catalogados
38.590CVEs com exploração pública
24.695testados em laboratório
82.451 exploits
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALsob ataqueransomware25 out 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALsob ataqueransomware25 out 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir ↗
GitHub PoC★ 5
ELIZEUOPAIN/CVE-2019-9053-CMS-Made-Simple-2.2.10---SQL-Injection-Exploit
CVE-2019-9053—25 out 2022
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir ↗
GitHub PoC
cURL one-liner to test for CVE-2022-1388 BIG-IP iControl REST RCE
CVE-2022-1388CRITICALsob ataqueransomware25 out 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir ↗
Metasploit600
VMware NSX Manager XStream unauthenticated RCE
CVE-2021-39144HIGHsob ataque25 out 2022
XStream is vulnerable to a Remote Command Execution attack
100RISCO
abrir ↗
GitHub PoC★ 1
cURL one-liner to test for CVE-2022-1388 BIG-IP iControl REST RCE
CVE-2022-1388CRITICALsob ataqueransomware25 out 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir ↗
GitHub PoC★ 5
Exploit Samba smbd 3.0.20-Debian
CVE-2007-2447—25 out 2022
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir ↗
GitHub PoC★ 2
Vulnmachines/text4shell-CVE-2022-42889
CVE-2022-42889—25 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗
GitHub PoC★ 2
b4dboy17/CVE-2022-26134
CVE-2022-26134CRITICALsob ataqueransomware24 out 2022
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir ↗
GitHub PoC★ 29
CVE-2022-37042 Zimbra Auth Bypass leads to RCE
CVE-2022-37042CRITICALsob ataqueransomware24 out 2022
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts fi
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-37042CRITICALsob ataqueransomware24 out 2022
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts fi
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALsob ataqueransomware24 out 2022
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2022-0847HIGHsob ataque24 out 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-42889—23 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗
GitHub PoC★ 5
A simple dockerize application that shows how to exploit the CVE-2022-42889 vulnerability.
CVE-2022-42889—23 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-42889—23 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗
GitHub PoC★ 4
Apache Text4Shell (CVE-2022-42889) Burp Bounty Profile
CVE-2022-42889—23 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗
GitHub PoC★ 20
CVE-2022-42889 aka Text4Shell research & PoC
CVE-2022-42889—23 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗
VulnCheck XDB
local
CVE-2022-42045—23 out 2022
Certain Zemana products are vulnerable to Arbitrary code injection. This affects Watchdog Anti-Malware 4.1.422 and Zeman
23RISCO
abrir ↗
GitHub PoC★ 5
Vulnerability Scanner for CVE-2022-42889 (Text4Shell)
CVE-2022-42889—23 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-39197MEDIUMsob ataque22 out 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISCO
abrir ↗
GitHub PoC★ 13
CVE-2022-39197 RCE POC
CVE-2022-39197MEDIUMsob ataque22 out 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2020-15568—22 out 2022
TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic cla
43RISCO
abrir ↗
GitHub PoC
CVE-2017-0785
CVE-2017-0785—22 out 2022
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RISCO
abrir ↗
GitHub PoC★ 3
python script for CVE-2022-42889
CVE-2022-42889—22 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗
GitHub PoC★ 1
CVE-2022-42889 Text4Shell Exploit POC
CVE-2022-42889—22 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-42889—22 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2022-42889—22 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗
GitHub PoC
Dockerized PoC for CVE-2022-42889 Text4Shell
CVE-2022-42889—22 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗
GitHub PoC★ 3
This project includes a python script which generates malicious commands leveraging CVE-2022-42889 vulnerability
CVE-2022-42889—21 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗
← anteriorpágina 615 / 2.749próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.