Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.451exploits catalogados
38.590CVEs com exploração pública
24.695testados em laboratório
82.451 exploits
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALsob ataqueransomware22 set 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir ↗
GitHub PoC★ 3
PoC for exploiting CVE-2019-2729 on WebLogic
CVE-2019-2729CRITICAL22 set 2022
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
85RISCO
abrir ↗
GitHub PoC
For detection of sitecore RCE - CVE-2021-42237
CVE-2021-42237CRITICALsob ataqueransomware22 set 2022
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it
100RISCO
abrir ↗
Metasploit600
mySCADA MyPRO Authenticated Command Injection (CVE-2023-28384)
CVE-2023-28384HIGH22 set 2022
CVE-2023-28384
48RISCO
abrir ↗
GitHub PoC★ 3
WSO2 Arbitrary File Upload to Remote Command Execution (RCE)
CVE-2022-29464CRITICALsob ataqueransomware22 set 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir ↗
GitHub PoC★ 73
cve-2022-39197 poc
CVE-2022-39197MEDIUMsob ataque22 set 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2022-39197MEDIUMsob ataque22 set 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISCO
abrir ↗
GitHub PoC
cobaltstrike4.5版本破/解、去除checksum8特征、bypass BeaconEye、修复错误路径泄漏stage、增加totp双因子验证、修复CVE-2022-39197等
CVE-2022-39197MEDIUMsob ataque22 set 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISCO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2019-2729CRITICAL22 set 2022
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
85RISCO
abrir ↗
GitHub PoC★ 2
MoCh3n/CVE-2015-5531-POC
CVE-2015-5531—21 set 2022
Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unsp
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALsob ataqueransomware21 set 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗
GitHub PoC★ 1
CVE-2021-44228 POC / Example
CVE-2021-44228CRITICALsob ataqueransomware21 set 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗
GitHub PoC★ 7
Bitbucket CVE-2022-36804 unauthenticated remote command execution
CVE-2022-36804HIGHsob ataque21 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir ↗
GitHub PoC
A Proof-Of-Concept for the CVE-2021-44228 vulnerability.
CVE-2021-44228CRITICALsob ataqueransomware21 set 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗
GitHub PoC★ 3
CVE-2022-39197
CVE-2022-39197MEDIUMsob ataque21 set 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISCO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2015-8562—21 set 2022
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-36804HIGHsob ataque21 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir ↗
GitHub PoC★ 1
Caihuar/Joomla-cve-2015-8562
CVE-2015-8562—21 set 2022
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-36804HIGHsob ataque20 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir ↗
Exploit-DB
Blink1Control2 2.2.7 - Weak Password Encryption
CVE-2022-35513—localmultiple20 set 2022
The Blink1Control2 application <= 2.2.7 uses weak password encryption and an insecure method of storage.
23RISCO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2022-36804HIGHsob ataque20 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir ↗
GitHub PoC★ 16
Somewhat Reliable PoC Exploit for CVE-2022-36804 (BitBucket Critical Command Injection)
CVE-2022-36804HIGHsob ataque20 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir ↗
Exploit-DB
Airspan AirSpot 5410 version 0.3.4.1 - Remote Code Execution (RCE)
CVE-2022-36267—remotelinux20 set 2022
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerabilit
35RISCO
abrir ↗
GitHub PoC★ 82
Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.
CVE-2007-4559CRITICAL20 set 2022
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows
53RISCO
abrir ↗
GitHub PoC★ 3
CVE-2019-8943 WordPress Crop-Image
CVE-2019-8943—20 set 2022
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware20 set 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗
GitHub PoC
A critical vulnerability (CVE-2022-36804) in Atlassian Bitbucket Server and Data Center could be exploited by unauthorized attackers to execute malicious code on vulnerable instances.
CVE-2022-36804HIGHsob ataque20 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Bookwyrm v0.4.3 - Authentication Bypass
CVE-2022-2651CRITICALwebappsmultiple20 set 2022
Authentication Bypass by Primary Weakness in bookwyrm-social/bookwyrm
53RISCO
abrir ↗
Metasploit300
Remote Control Collection RCE
CVE-2022-4978CRITICAL20 set 2022
Steppschuh Remote Control Server 3.1.1.12 Unauthenticated RCE
63RISCO
abrir ↗
GitHub PoC
dileepdkumar/LayarKacaSiber-CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware20 set 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗
← anteriorpágina 624 / 2.749próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.