Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.449exploits catalogados
35.552CVEs com exploração pública
24.695testados em laboratório
77.449 exploits
GitHub PoC3
An exploit for CVE-2012-2982 implemented in Rust
CVE-2012-298215 dez 2022
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISCO
abrir
GitHub PoC
CVE-2020-0796-利用工具
CVE-2020-0796CRITICALsob ataqueransomware15 dez 2022
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC
A Proof of Concept for the CVE-2021-27928 flaw exploitation
CVE-2021-2792814 dez 2022
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, a
35RISCO
abrir
GitHub PoC3
cve-2019-11510, cve-2019-19781, cve-2020-5902,               cve-2021-1497, cve-2021-20090, cve-2021-22006, cve-2021-22205, cve-2021-26084, cve-2021-26855, cve-2021-26857, cve-2021–26857, cve-2021–26858, cve-2021–26865
CVE-2019-11510CRITICALsob ataqueransomware13 dez 2022
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware13 dez 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC3
cve-2019-11510, cve-2019-19781, cve-2020-5902,               cve-2021-1497, cve-2021-20090, cve-2021-22006, cve-2021-22205, cve-2021-26084, cve-2021-26855, cve-2021-26857, cve-2021–26857, cve-2021–26858, cve-2021–26865
CVE-2020-5902CRITICALsob ataqueransomware13 dez 2022
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC3
cve-2019-11510, cve-2019-19781, cve-2020-5902,               cve-2021-1497, cve-2021-20090, cve-2021-22006, cve-2021-22205, cve-2021-26084, cve-2021-26855, cve-2021-26857, cve-2021–26857, cve-2021–26858, cve-2021–26865
CVE-2021-1497CRITICALsob ataque13 dez 2022
Cisco HyperFlex HX Command Injection Vulnerabilities
100RISCO
abrir
GitHub PoC3
Improper access control in SAP NetWeaver Process Integration
CVE-2022-41272CRITICAL13 dez 2022
An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Se
48RISCO
abrir
GitHub PoC
Educational Follina PoC Tool
CVE-2022-30190HIGHsob ataqueransomware12 dez 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
devengpk/CVE-2022-22965
CVE-2022-22965CRITICALsob ataque12 dez 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC
KaviDk/CVE-2019-6447-in-Mobile-Application
CVE-2019-644712 dez 2022
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALsob ataque12 dez 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC
CVE-2020-16846
CVE-2020-16846CRITICALsob ataque12 dez 2022
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH clien
100RISCO
abrir
GitHub PoC7
CVE-2021-3129 Exploit Checker By ./MrMad
CVE-2021-3129CRITICALsob ataqueransomware10 dez 2022
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC20
text4shell(CVE-2022-42889) BurpSuite Scanner
CVE-2022-4288909 dez 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC89
[PoC] Command injection via PDF import in Markdown Preview Enhanced (VSCode, Atom)
CVE-2022-45025CRITICAL09 dez 2022
Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerabi
60RISCO
abrir
GitHub PoC
Scan IP ranges for IP's vulnerable to the F5 Big IP exploit (CVE-2022-1388)
CVE-2022-1388CRITICALsob ataqueransomware09 dez 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir
GitHub PoC36
POC of CVE-2022-36537
CVE-2022-36537HIGHsob ataqueransomware09 dez 2022
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafte
100RISCO
abrir
GitHub PoC9
CVE-2022-36537
CVE-2022-36537HIGHsob ataqueransomware09 dez 2022
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafte
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-36537HIGHsob ataqueransomware09 dez 2022
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafte
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-36537HIGHsob ataqueransomware09 dez 2022
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafte
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALsob ataqueransomware09 dez 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALsob ataque08 dez 2022
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC47
CVE-2022-46169 Cacti remote_agent.php Unauthenticated Command Injection.
CVE-2022-46169CRITICALsob ataque08 dez 2022
Unauthenticated Command Injection
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALsob ataque07 dez 2022
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC5
PHPunit Checker CVE-2017-9841 By MrMad
CVE-2017-9841CRITICALsob ataque07 dez 2022
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISCO
abrir
GitHub PoC
CVE-2022-46169
CVE-2022-46169CRITICALsob ataque07 dez 2022
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC1
CVE-2022-42889 - Text4Shell exploit
CVE-2022-4288907 dez 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-4288907 dez 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
VulnCheck XDB
infoleak
CVE-2022-241406 dez 2022
Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a
60RISCO
abrir
anteriorpágina 534 / 2.582próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.