Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.451exploits catalogados
38.590CVEs com exploração pública
24.695testados em laboratório
82.451 exploits
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALsob ataque09 set 2022
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗
GitHub PoC
[CVE-2014-6271] Apache Shellshock Remote Command Injection tool for quick reverse shell and file browsing
CVE-2014-6271CRITICALsob ataque09 set 2022
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗
GitHub PoC★ 5
CVE-2022-31188 - OpenCV CVAT (Computer Vision Annotation Tool) SSRF
CVE-2022-31188HIGH09 set 2022
Server-Side Request Forgery Vulnerability in Computer Vision Annotation Tool (CVAT)
53RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2017-1000486CRITICALsob ataque09 set 2022
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISCO
abrir ↗
GitHub PoC★ 19
exploit for CVE-2017-1000486 vulnerability with SOCKS proxy support
CVE-2017-1000486CRITICALsob ataque09 set 2022
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISCO
abrir ↗
GitHub PoC★ 19
exploit for CVE-2017-1000486 vulnerability with SOCKS proxy support
CVE-2017-1000486CRITICALsob ataque09 set 2022
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISCO
abrir ↗
GitHub PoC★ 3
CVE-2022-36446 - Webmin 1.996 Remote Code Execution
CVE-2022-36446—09 set 2022
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
60RISCO
abrir ↗
GitHub PoC
This powershell script is intended to be used by anyone looking to remediate the Log4j Vulnerability within their environment. It can target multiple machines and run remotely as a job on all or only affected devices.
CVE-2021-44228CRITICALsob ataqueransomware08 set 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗
GitHub PoC★ 35
A real exploit for BitBucket RCE CVE-2022-36804
CVE-2022-36804HIGHsob ataque07 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-36804HIGHsob ataque07 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir ↗
Metasploit600
Syncovery For Linux Web-GUI Authenticated Remote Command Execution
CVE-2022-36534—06 set 2022
Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote c
30RISCO
abrir ↗
GitHub PoC
Remediation for CVE-2013-3900
CVE-2013-3900MEDIUMsob ataque06 set 2022
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir ↗
Metasploit300
Syncovery For Linux Web-GUI Session Token Brute-Forcer
CVE-2022-36536—06 set 2022
An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and be
18RISCO
abrir ↗
Metasploit500
pfSense plugin pfBlockerNG unauthenticated RCE as root
CVE-2022-31814CRITICAL05 set 2022
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir ↗
VulnCheck XDB
local
CVE-2021-34527HIGHsob ataqueransomware05 set 2022
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir ↗
GitHub PoC★ 1
Redis RCE through Lua Sandbox Escape vulnerability
CVE-2022-0543CRITICALsob ataque05 set 2022
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RISCO
abrir ↗
GitHub PoC★ 23
CVE-2021-34527 AddPrinterDriverEx() Privilege Escalation
CVE-2021-34527HIGHsob ataqueransomware05 set 2022
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir ↗
GitHub PoC★ 1
0xrobiul/CVE-2018-15473
CVE-2018-15473MEDIUM03 set 2022
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALsob ataqueransomware03 set 2022
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2022-2586MEDIUMsob ataque03 set 2022
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-a
68RISCO
abrir ↗
GitHub PoC★ 22
CVE-2022-2586: Linux kernel nft_object UAF
CVE-2022-2586MEDIUMsob ataque03 set 2022
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-a
68RISCO
abrir ↗
GitHub PoC★ 5
Win10 20H2 LPE for CVE-2021-31956
CVE-2021-31956HIGHsob ataque02 set 2022
Windows NTFS Elevation of Privilege Vulnerability
76RISCO
abrir ↗
GitHub PoC★ 2
Zabbix-SAML-Bypass: CVE-2022-23131
CVE-2022-23131CRITICALsob ataque02 set 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2021-31956HIGHsob ataque02 set 2022
Windows NTFS Elevation of Privilege Vulnerability
76RISCO
abrir ↗
GitHub PoC★ 4
Powertek PDU身份绕过
CVE-2022-33174CRITICAL02 set 2022
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypas
68RISCO
abrir ↗
GitHub PoC★ 6
OpenSSL
CVE-2022-1292CRITICAL01 set 2022
The c_rehash script allows command injection
70RISCO
abrir ↗
GitHub PoC
75ACOL/CVE-2022-22963
CVE-2022-22963CRITICALsob ataque01 set 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-0543CRITICALsob ataque01 set 2022
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RISCO
abrir ↗
GitHub PoC
shavchen/CVE-2022-26138
CVE-2022-26138CRITICALsob ataque01 set 2022
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in th
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2022-0847HIGHsob ataque31 ago 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir ↗
← anteriorpágina 627 / 2.749próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.