Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
13.743 exploits
GitHub PoC4
Utilities for exploiting vulnerability CVE-2022-40684 (FortiOS / FortiProxy / FortiSwitchManager - Authentication bypass on administrative interface).
CVE-2022-40684CRITICALsob ataqueransomware19 out 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir
GitHub PoC
onlyHerold22/CVE-2022-27925-PoC
CVE-2022-27925HIGHsob ataqueransomware19 out 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISCO
abrir
GitHub PoC
CVE-2014-3704 aka Drupalgeddon - Form-Cache Injection Method
CVE-2014-370418 out 2022
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISCO
abrir
GitHub PoC11
A simple application that shows how to exploit the CVE-2022-42889 vulnerability
CVE-2022-4288918 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC39
cve-2022-42889 Text4Shell CVE-2022-42889 affects Apache Commons Text versions 1.5 through 1.9. It has been patched as of Commons Text version 1.10.
CVE-2022-4288918 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC76
Dockerized POC for CVE-2022-42889 Text4Shell
CVE-2022-4288918 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC1
An intentionally vulnerable webapp to get your hands dirty with CVE-2022-42889.
CVE-2022-4288918 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC3
Exploit POC for CVE-2022-0824
CVE-2022-0824HIGH17 out 2022
Improper Access Control to Remote Code Execution in webmin/webmin
78RISCO
abrir
GitHub PoC
puckiestyle/CVE-2022-40684
CVE-2022-40684CRITICALsob ataqueransomware17 out 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir
GitHub PoC4
ClusterImagePolicy demo for cve-2022-42889 text4shell
CVE-2022-4288917 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC4
jsongmax/terraMaster-CVE-2022-24990
CVE-2022-24990CRITICALsob ataqueransomware17 out 2022
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agen
100RISCO
abrir
GitHub PoC34
Proof of Concept for the Apache commons-text vulnerability CVE-2022-42889.
CVE-2022-4288917 out 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC2
Ruby on Rails是一个 Web 应用程序框架,是一个相对较新的 Web 应用程序框架,构建在 Ruby 语言之上。这个漏洞主要是由于Ruby on Rails使用了指定参数的render file来渲染应用之外的视图,我们可以通过修改访问某控制器的请求包,通过“…/…/…/…/”来达到路径穿越的目的,然后再通过“{{”来进行模板查询路径的闭合,使得所要访问的文件被当做外部模板来解析。
CVE-2019-5418HIGHsob ataque17 out 2022
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir
GitHub PoC2
jsongmax/Fortinet-CVE-2022-40684
CVE-2022-40684CRITICALsob ataqueransomware17 out 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir
GitHub PoC
批量检测CVE-2022-26134 RCE漏洞
CVE-2022-26134CRITICALsob ataqueransomware16 out 2022
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC1
Telesquare SDT-CW3B1 1.1.0 版本存在操作系统命令注入漏洞。远程攻击者可利用该漏洞在无需任何身份验证的情况下执行操作系统命令。
CVE-2021-4642216 out 2022
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RISCO
abrir
GitHub PoC4
Linux Kernel 3.10.0-514.21.2.el7.x86_64 / 3.10.0-514.26.1.el7.x86_64 (CentOS 7) - SUID Position Independent Executable 'PIE' Local Privilege Escalation
CVE-2017-1000253HIGHsob ataqueransomware16 out 2022
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb7
76RISCO
abrir
GitHub PoC2
CVE-2021-46422poc
CVE-2021-4642216 out 2022
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RISCO
abrir
GitHub PoC4
Forti CVE-2022-40684 enumeration script built in Rust
CVE-2022-40684CRITICALsob ataqueransomware16 out 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir
GitHub PoC1
NeriaBasha/CVE-2022-40684
CVE-2022-40684CRITICALsob ataqueransomware16 out 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir
GitHub PoC1
CVE-2021-46422
CVE-2021-4642216 out 2022
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RISCO
abrir
GitHub PoC
SDT-CW3B1韩国的无线路由器 os cmd 注入PoC
CVE-2021-4642216 out 2022
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RISCO
abrir
GitHub PoC1
批量检测CVE-2021-46422 RCE漏洞
CVE-2021-4642216 out 2022
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RISCO
abrir
GitHub PoC
韩国的无线路由器 os cmd 注入
CVE-2021-4642216 out 2022
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RISCO
abrir
GitHub PoC
cve-2021-46422
CVE-2021-4642216 out 2022
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RISCO
abrir
GitHub PoC
CVE-2022-26134poc
CVE-2022-26134CRITICALsob ataqueransomware16 out 2022
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC
CVE-2022-26134
CVE-2022-26134CRITICALsob ataqueransomware16 out 2022
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC1
cve-2022-26134
CVE-2022-26134CRITICALsob ataqueransomware16 out 2022
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC1
Confluence Server and Data Center存在一个远程代码执行漏洞,未经身份验证的攻击者可以利用该漏洞向目标服务器注入恶意ONGL表达式,进而在目标服务器上执行任意代码。
CVE-2022-26134CRITICALsob ataqueransomware16 out 2022
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC1
漏洞检测
CVE-2021-4642216 out 2022
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RISCO
abrir
anteriorpágina 293 / 459próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.