Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.451exploits catalogados
38.590CVEs com exploração pública
24.695testados em laboratório
82.451 exploits
GitHub PoC★ 16
Somewhat Reliable PoC Exploit for CVE-2022-36804 (BitBucket Critical Command Injection)
CVE-2022-36804HIGHsob ataque20 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir ↗
Exploit-DB
Airspan AirSpot 5410 version 0.3.4.1 - Remote Code Execution (RCE)
CVE-2022-36267—remotelinux20 set 2022
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerabilit
35RISCO
abrir ↗
GitHub PoC★ 18
Multithreaded exploit script for CVE-2022-36804 affecting BitBucket versions <8.3.1
CVE-2022-36804HIGHsob ataque19 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-36804HIGHsob ataque19 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2017-12149CRITICALsob ataqueransomware19 set 2022
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISCO
abrir ↗
GitHub PoC★ 4
CVE-2022-31814 Exploitation Toolkit.
CVE-2022-31814CRITICAL18 set 2022
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir ↗
GitHub PoC★ 2
All Credit to MaherAzzouzi (https://github.com/MaherAzzouzi/CVE-2022-37706-LPE-exploit). This is a copy of the exploit for CTFs
CVE-2022-37706HIGH18 set 2022
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-31814CRITICAL18 set 2022
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-27925HIGHsob ataqueransomware17 set 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISCO
abrir ↗
GitHub PoC★ 1
touchmycrazyredhat/CVE-2022-27925-Revshell
CVE-2022-27925HIGHsob ataqueransomware17 set 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISCO
abrir ↗
GitHub PoC★ 4
CVE-2019-0708, A tool which mass hunts for bluekeep vulnerability for exploitation.
CVE-2019-0708CRITICALsob ataqueransomware17 set 2022
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir ↗
GitHub PoC
cve-2010-2553复现
CVE-2010-2553—16 set 2022
The Cinepak codec in Microsoft Windows XP SP2 and SP3, Windows Vista SP1 and SP2, and Windows 7 does not properly decomp
35RISCO
abrir ↗
GitHub PoC★ 1
pswalia2u/CVE-2020-7246
CVE-2020-7246—16 set 2022
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISCO
abrir ↗
GitHub PoC
mightysai1997/cve-2021-42013
CVE-2021-42013CRITICALsob ataqueransomware15 set 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗
GitHub PoC★ 1
kernel-cyber/CVE-2009-4623
CVE-2009-4623—15 set 2022
Multiple PHP remote file inclusion vulnerabilities in Advanced Comment System 1.0 allow remote attackers to execute arbi
23RISCO
abrir ↗
GitHub PoC★ 1
mightysai1997/CVE-2021-41773S
CVE-2021-41773HIGHsob ataqueransomware15 set 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗
GitHub PoC
mightysai1997/cve-2021-41773-v-
CVE-2021-41773HIGHsob ataqueransomware15 set 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗
GitHub PoC
CVE-2022-37204 POC
CVE-2022-37204CRITICAL15 set 2022
Final CMS 5.1.0 is vulnerable to SQL Injection.
48RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Gitea 1.16.6 - Remote Code Execution (RCE) (Metasploit)
CVE-2022-30781—webappsmultiple15 set 2022
Gitea before 1.16.7 does not escape git fetch remote.
60RISCO
abrir ↗
GitHub PoC
mightysai1997/CVE-2021-41773h
CVE-2021-41773HIGHsob ataqueransomware15 set 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2022-30190HIGHsob ataqueransomware15 set 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir ↗
GitHub PoC
mightysai1997/CVE-2021-41773-PoC
CVE-2021-41773HIGHsob ataqueransomware15 set 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2021-42013CRITICALsob ataqueransomware15 set 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2021-42013CRITICALsob ataqueransomware15 set 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗
GitHub PoC
mightysai1997/cve-2021-41773
CVE-2021-41773HIGHsob ataqueransomware15 set 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗
GitHub PoC
mightysai1997/CVE-2021-41773-L-
CVE-2021-41773HIGHsob ataqueransomware15 set 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗
GitHub PoC★ 2
A proof of concept for CVE-2022-30190 (Follina).
CVE-2022-30190HIGHsob ataqueransomware15 set 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir ↗
GitHub PoC
mightysai1997/CVE-2021-41773.git1
CVE-2021-41773HIGHsob ataqueransomware15 set 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗
GitHub PoC★ 1
mightysai1997/CVE-2021-41773m
CVE-2021-41773HIGHsob ataqueransomware15 set 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗
GitHub PoC
mightysai1997/CVE-2021-41773-i-
CVE-2021-41773HIGHsob ataqueransomware15 set 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗
← anteriorpágina 625 / 2.749próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.