Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
13.743 exploits
GitHub PoC1
CVE-2022-0441 - MasterStudy LMS 2.7.6
CVE-2022-044118 nov 2022
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
60RISCO
abrir
GitHub PoC1
A write-up of my (so far inconclusive) look into CVE-2022-31691
CVE-2022-31691CRITICAL17 nov 2022
Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI
48RISCO
abrir
GitHub PoC2
Abdulazizalsewedy/CVE-2021-29447
CVE-2021-29447HIGH17 nov 2022
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir
GitHub PoC2
A massive scanner for CVE-2021-34473 Microsoft Exchange Windows Vulnerability
CVE-2021-34473CRITICALsob ataqueransomware16 nov 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
Resources required for building Pluralsight CVE-2022-0847 lab
CVE-2022-0847HIGHsob ataque16 nov 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC4
FIxed exploit for CVE-2022-24637 (original xplt: https://www.exploit-db.com/exploits/51026)
CVE-2022-2463715 nov 2022
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISCO
abrir
GitHub PoC3
Social WarFare Plugin (<=3.5.2) Remote Code Execution
CVE-2019-9978MEDIUMsob ataque15 nov 2022
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
GitHub PoC1
qq87234770/CVE-2022-22947
CVE-2022-22947CRITICALsob ataque15 nov 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC3
A Golang program to automate the execution of CVE-2021-29447
CVE-2021-29447HIGH15 nov 2022
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir
GitHub PoC7
mega8bit/exploit_cve-2021-29447
CVE-2021-29447HIGH14 nov 2022
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir
GitHub PoC
fall2022 secure coding CVE-2019-13272 : Linux Kernel Improper Privilege Management Vulnerability
CVE-2019-13272HIGHsob ataque14 nov 2022
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
GitHub PoC7
RCE exploit for WSO2
CVE-2022-29464CRITICALsob ataqueransomware14 nov 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir
GitHub PoC3
Microsoft Exchange Server Remote Code Execution Vulnerability.
CVE-2022-41082HIGHsob ataqueransomware14 nov 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC256
Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含
CVE-2017-12615HIGHsob ataqueransomware13 nov 2022
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir
GitHub PoC1
CyberKimathi/Py3-CVE-2017-0785
CVE-2017-078513 nov 2022
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RISCO
abrir
GitHub PoC256
Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含
CVE-2020-1938CRITICALsob ataque13 nov 2022
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC359
Unsigned driver loader using CVE-2018-19320
CVE-2018-19320HIGHsob ataqueransomware12 nov 2022
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RISCO
abrir
GitHub PoC
ivilpez/cve-2017-16995.c
CVE-2017-1699512 nov 2022
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISCO
abrir
GitHub PoC109
Zimbra <9.0.0.p27 RCE
CVE-2022-41352CRITICALsob ataque11 nov 2022
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through ama
100RISCO
abrir
GitHub PoC4
Exploit WordPress Media Library XML External Entity Injection (XXE) to exfiltrate files.
CVE-2021-29447HIGH11 nov 2022
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir
GitHub PoC
Joanmei/CVE-2017-0785
CVE-2017-078510 nov 2022
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RISCO
abrir
GitHub PoC
Implementation of CVE-2022-30190 in C
CVE-2022-30190HIGHsob ataqueransomware10 nov 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
SPRING DATA REST CVE-2017-8046 DEMO
CVE-2017-804610 nov 2022
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISCO
abrir
GitHub PoC1
bantu2301/CVE-2018-16858
CVE-2018-16858HIGH09 nov 2022
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could
68RISCO
abrir
GitHub PoC2
A simple tool to enumerate users in gitlab
CVE-2022-1162CRITICAL09 nov 2022
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE
85RISCO
abrir
GitHub PoC1
CVE-2020-0796
CVE-2020-0796CRITICALsob ataqueransomware09 nov 2022
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC
The first poc video presenting the sql injection test from ( WordPress Core 5.8.2-'WP_Query' / CVE-2022-21661)
CVE-2022-21661HIGH08 nov 2022
SQL injection in WordPress
78RISCO
abrir
GitHub PoC1
DO NOT USE FOR ANYTHING REAL. Simple springboot sample app with vulnerability CVE-2021-44228 aka "Log4Shell"
CVE-2021-44228CRITICALsob ataqueransomware08 nov 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC4
CVE-2022-22965图形化检测工具
CVE-2022-22965CRITICALsob ataque08 nov 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC
CVE-2022-0824, CVE-2022-0829, File Manger privilege exploit
CVE-2022-0824HIGH08 nov 2022
Improper Access Control to Remote Code Execution in webmin/webmin
78RISCO
abrir
anteriorpágina 290 / 459próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.