Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.533exploits catalogados
35.607CVEs com exploração pública
24.695testados em laboratório
77.533 exploits
GitHub PoC
this is a demo attack of FOLLINA exploit , a vulnerability that has been discovered in May 2022 and stood unpatched until June 2022
CVE-2022-30190HIGHsob ataqueransomware06 out 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC5
Code set relating to CVE-2022-41040
CVE-2022-41040HIGHsob ataqueransomware06 out 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISCO
abrir
Exploit-DBVexDay Proof
Wordpress Plugin Zephyr Project Manager 3.2.42 - Multiple SQLi
CVE-2022-2840webappsphp06 out 2022
Zephyr Project Manager < 3.2.5 - Multiple Unauthenticated SQLi
28RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-41040HIGHsob ataqueransomware06 out 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2022-30190HIGHsob ataqueransomware06 out 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir
Metasploit600
GitLab GitHub Repo Import Deserialization RCE
CVE-2022-2992CRITICAL06 out 2022
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-21972CRITICALsob ataqueransomware04 out 2022
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
GitHub PoC1.483
一款针对Vcenter的综合利用工具,包含目前最主流的CVE-2021-21972、CVE-2021-21985以及CVE-2021-22005、One Access的CVE-2022-22954、CVE-2022-22972/31656以及log4j,提供一键上传webshell,命令执行或者上传公钥使用SSH免密连接
CVE-2021-21972CRITICALsob ataqueransomware04 out 2022
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-22005CRITICALsob ataqueransomware04 out 2022
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-36804HIGHsob ataque04 out 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-9248CRITICALsob ataque04 out 2022
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RISCO
abrir
GitHub PoC1.475
一款针对Vcenter的综合利用工具,包含目前最主流的CVE-2021-21972、CVE-2021-21985以及CVE-2021-22005、One Access的CVE-2022-22954、CVE-2022-22972/31656以及log4j,提供一键上传webshell,命令执行或者上传公钥使用SSH免密连接
CVE-2022-22954CRITICALsob ataqueransomware04 out 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-21985CRITICALsob ataqueransomware04 out 2022
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RISCO
abrir
GitHub PoC7
Atlassian Bitbucket Server and Data Center - Command Injection Vulnerability (CVE-2022-36804)
CVE-2022-36804HIGHsob ataque04 out 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
GitHub PoC5
mitigation script for MS Exchange server vuln
CVE-2022-41040HIGHsob ataqueransomware04 out 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-22954CRITICALsob ataqueransomware04 out 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-41082HIGHsob ataqueransomware04 out 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-2297204 out 2022
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability aff
50RISCO
abrir
GitHub PoC60
Another tool for exploiting CVE-2017-9248, a cryptographic weakness in Telerik UI for ASP.NET AJAX dialog handler.
CVE-2017-9248CRITICALsob ataque04 out 2022
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RISCO
abrir
GitHub PoC49
SecLabResearchBV/CVE-2022-34718-PoC
CVE-2022-34718CRITICAL03 out 2022
Windows TCP/IP Remote Code Execution Vulnerability
60RISCO
abrir
VulnCheck XDB
client-side
CVE-2020-28949HIGHsob ataque03 out 2022
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-9805HIGHsob ataque03 out 2022
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir
GitHub PoC
CentarisCyber/CVE-2022-41040_Mitigation
CVE-2022-41040HIGHsob ataqueransomware03 out 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC3
CVE-2017-9805 POC
CVE-2017-9805HIGHsob ataque03 out 2022
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir
GitHub PoC19
CVE-2022-41040 nuclei template
CVE-2022-41040HIGHsob ataqueransomware02 out 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2022-41040HIGHsob ataqueransomware02 out 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISCO
abrir
Metasploit600
Oracle E-Business Suite (EBS) Unauthenticated Arbitrary File Upload
CVE-2022-21587CRITICALsob ataqueransomware01 out 2022
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-27925HIGHsob ataqueransomware01 out 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISCO
abrir
GitHub PoC80
Nmap scripts to detect exchange 0-day (CVE-2022-41082) vulnerability
CVE-2022-41082HIGHsob ataqueransomware01 out 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC18
A loader for zimbra 2022 rce (cve-2022-27925)
CVE-2022-27925HIGHsob ataqueransomware01 out 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISCO
abrir
anteriorpágina 549 / 2.585próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.