Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.745exploits catalogados
38.712CVEs com exploração pública
24.695testados em laboratório
82.745 exploits
VulnCheck XDB
local
CVE-2021-3156HIGHsob ataque04 jul 2022
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir ↗
GitHub PoC★ 1
Atlassian, CVE-2022-26134 An interactive lab showcasing the Confluence Server and Data Center un-authenticated RCE vulnerability.
CVE-2022-26134CRITICALsob ataqueransomware04 jul 2022
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALsob ataqueransomware04 jul 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir ↗
GitHub PoC
CVE-2022-1388, bypassing iControl REST authentication
CVE-2022-1388CRITICALsob ataqueransomware04 jul 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir ↗
GitHub PoC★ 5
Visualization, Fuzzing, Exploit and Patch of Baron Samedit Vulnerability
CVE-2021-3156HIGHsob ataque04 jul 2022
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir ↗
GitHub PoC
The above investigation of the ES file browser security weakness allows us to see the issue in its entirety
CVE-2019-6447—03 jul 2022
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISCO
abrir ↗
GitHub PoC★ 5
Ruby反序列化命令执行漏洞(CVE-2019-5420)-vulfocus通关版
CVE-2019-5420—02 jul 2022
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISCO
abrir ↗
GitHub PoC★ 13
CVE-2022-2185 poc
CVE-2022-2185CRITICAL02 jul 2022
A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALsob ataqueransomware01 jul 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir ↗
GitHub PoC★ 1
PoC for exploiting CVE-2022-1388 on BIG IP F5
CVE-2022-1388CRITICALsob ataqueransomware01 jul 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir ↗
GitHub PoC★ 4
Apache Tomcat DoS (CVE-2022-29885) Exploit
CVE-2022-29885—01 jul 2022
EncryptInterceptor does not provide complete protection on insecure networks
45RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-42237CRITICALsob ataqueransomware30 jun 2022
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it
100RISCO
abrir ↗
GitHub PoC★ 136
PoC for Nginx 0.6.18 - 1.20.0 Memory Overwrite Vulnerability CVE-2021-23017
CVE-2021-23017—30 jun 2022
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RISCO
abrir ↗
GitHub PoC★ 5
Apache Tomcat CVE-2022-29885
CVE-2022-29885—30 jun 2022
EncryptInterceptor does not provide complete protection on insecure networks
45RISCO
abrir ↗
GitHub PoC★ 1
vesperp/CVE-2021-42237-SiteCore-XP
CVE-2021-42237CRITICALsob ataqueransomware30 jun 2022
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it
100RISCO
abrir ↗
GitHub PoC
A collection of exploits and documentation that can be used to exploit the Linux Dirty Pipe vulnerability.
CVE-2022-0847HIGHsob ataque30 jun 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2022-0847HIGHsob ataque30 jun 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir ↗
GitHub PoC
PoC for exploiting CVE-2022-26134 on Confluence
CVE-2022-26134CRITICALsob ataqueransomware29 jun 2022
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir ↗
GitHub PoC★ 8
This is exploit of CVE-2022-30190 on PowerPoint.
CVE-2022-30190HIGHsob ataqueransomware29 jun 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir ↗
GitHub PoC★ 41
CVE-2021-34473 Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-34473CRITICALsob ataqueransomware29 jun 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir ↗
Metasploit600
ManageEngine ADAudit Plus CVE-2022-28219
CVE-2022-28219—29 jun 2022
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-34473CRITICALsob ataqueransomware29 jun 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2022-30190HIGHsob ataqueransomware29 jun 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir ↗
Metasploit600
Advantech iView NetworkServlet Command Injection
CVE-2022-2143CRITICAL28 jun 2022
Advantech iView
75RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2019-9670CRITICALsob ataque28 jun 2022
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RISCO
abrir ↗
GitHub PoC★ 5
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call.
CVE-2015-2291HIGHsob ataqueransomware28 jun 2022
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RISCO
abrir ↗
Metasploit600
UnRAR Path Traversal in Zimbra (CVE-2022-30333)
CVE-2022-30333CRITICALsob ataqueransomware28 jun 2022
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) o
100RISCO
abrir ↗
Metasploit600
UnRAR Path Traversal (CVE-2022-30333)
CVE-2022-30333CRITICALsob ataqueransomware28 jun 2022
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) o
100RISCO
abrir ↗
Metasploit600
TAR Path Traversal in Zimbra (CVE-2022-41352)
CVE-2022-41352CRITICALsob ataqueransomware28 jun 2022
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through ama
100RISCO
abrir ↗
GitHub PoC★ 1
Mass Exploit for CVE 2022-29464 on Carbon
CVE-2022-29464CRITICALsob ataqueransomware28 jun 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir ↗
← anteriorpágina 642 / 2.759próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.