Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.107exploits catalogados
34.679CVEs com exploração pública
24.695testados em laboratório
13.812 exploits
GitHub PoC
CVE-2022-26809-RCE
CVE-2022-26809CRITICAL23 abr 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC5
mariomamo/CVE-2022-22965
CVE-2022-22965CRITICALsob ataque23 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC
A python script/generator, for generating and exploiting Microsoft vulnerability
CVE-2017-0199HIGHsob ataqueransomware22 abr 2022
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir
GitHub PoC
This repository contains a PoC for remote code execution CVE-2022-26809
CVE-2022-26809CRITICAL22 abr 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC1
0xAgun/CVE-2022-29464
CVE-2022-29464CRITICALsob ataqueransomware22 abr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir
GitHub PoC5
cve-2022-29464 批量脚本
CVE-2022-29464CRITICALsob ataqueransomware22 abr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir
GitHub PoC5
WSO2 RCE (CVE-2022-29464)
CVE-2022-29464CRITICALsob ataqueransomware22 abr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir
GitHub PoC3
Repository containing nse script for vulnerability CVE-2022-29464 known as WSO2 RCE.
CVE-2022-29464CRITICALsob ataqueransomware22 abr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir
GitHub PoC2
Pre-auth RCE bug CVE-2022-29464
CVE-2022-29464CRITICALsob ataqueransomware21 abr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir
GitHub PoC2
tufanturhan/wso2-rce-cve-2022-29464
CVE-2022-29464CRITICALsob ataqueransomware21 abr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir
GitHub PoC1
c4mx/CVE-2022-22965_PoC
CVE-2022-22965CRITICALsob ataque21 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC1
Phantomlancer123/CVE-2017-0199
CVE-2017-0199HIGHsob ataqueransomware20 abr 2022
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir
GitHub PoC
MS CVE 2019-0708 Python Exploit
CVE-2019-0708CRITICALsob ataqueransomware20 abr 2022
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC
CVE-2021-4034 PoC
CVE-2021-4034HIGHsob ataque20 abr 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC377
WSO2 RCE (CVE-2022-29464) exploit and writeup.
CVE-2022-29464CRITICALsob ataqueransomware20 abr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir
GitHub PoC
CVE-2017-9841批量扫描及利用脚本。PHPUnit是其中的一个基于PHP的测试框架。 PHPUnit 4.8.28之前的版本和5.6.3之前的5.x版本中的Util/PHP/eval-stdin.php文件存在安全漏洞。远程攻击者可通过发送以‘<?php’字符串开头的HTTP POST数据利用该漏洞执行任意PHP代码。
CVE-2017-9841CRITICALsob ataque20 abr 2022
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISCO
abrir
GitHub PoC
ms15-034 or CVE-2015-1635 批量扫描
CVE-2015-1635CRITICALsob ataque19 abr 2022
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISCO
abrir
GitHub PoC
CVE-2019-15107
CVE-2019-15107CRITICALsob ataqueransomware18 abr 2022
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC
CVE-2021-42013 - Apache 2.4.50
CVE-2021-42013CRITICALsob ataqueransomware18 abr 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC2
Watchguard RCE POC CVE-2022-26318
CVE-2022-26318CRITICALsob ataque18 abr 2022
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulner
100RISCO
abrir
GitHub PoC9
Scripted Linux Privilege Escalation for the CVE-2022-0847 "Dirty Pipe" vulnerability
CVE-2022-0847HIGHsob ataque17 abr 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC1
CVE-2015-1635-POC,指定IP与端口验证HTTP.sys漏洞是否存在
CVE-2015-1635CRITICALsob ataque17 abr 2022
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISCO
abrir
GitHub PoC
mhurts/CVE-2022-22954-POC
CVE-2022-22954CRITICALsob ataqueransomware16 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir
GitHub PoC2
Repository containing nse script for vulnerability CVE-2022-21907. It is a component (IIS) vulnerability on Windows. It allows remote code execution. The vulnerability affects the kernel module http. sys, which handles most basic IIS operations.
CVE-2022-21907CRITICAL16 abr 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC53
Exploit for CVE-2021-22204 (ExifTool) - Arbitrary Code Execution
CVE-2021-22204MEDIUMsob ataque16 abr 2022
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISCO
abrir
GitHub PoC148
Laravel RCE Exploit PoC - CVE-2021-3129 (user-friendly with automatic log path detection)
CVE-2021-3129CRITICALsob ataqueransomware16 abr 2022
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC2
tufanturhan/CVE-2022-21971-Windows-Runtime-RCE
CVE-2022-21971HIGHsob ataque15 abr 2022
Windows Runtime Remote Code Execution Vulnerability
83RISCO
abrir
GitHub PoC4
CVE-2022-22954 VMware Workspace ONE Access free marker SSTI
CVE-2022-22954CRITICALsob ataqueransomware15 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir
GitHub PoC
tufanturhan/CVE-2022-0847-L-nux-PrivEsc
CVE-2022-0847HIGHsob ataque15 abr 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC11
Spring Cloud Gateway Actuator API SpEL Code Injection (CVE-2022-22947)
CVE-2022-22947CRITICALsob ataque15 abr 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
anteriorpágina 318 / 461próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.