Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.533exploits catalogados
35.607CVEs com exploração pública
24.695testados em laboratório
77.533 exploits
GitHub PoC2
CVE-2016-2098 POC
CVE-2016-209824 set 2022
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-39197MEDIUMsob ataque24 set 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISCO
abrir
GitHub PoC3
You can find a python script to exploit the vulnerability on Bitbucket related CVE-2022-36804.
CVE-2022-36804HIGHsob ataque24 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
GitHub PoC1
purple-WL/Cobaltstrike-RCE-CVE-2022-39197
CVE-2022-39197MEDIUMsob ataque24 set 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISCO
abrir
GitHub PoC17
Cobalt Strike RCE CVE-2022-39197
CVE-2022-39197MEDIUMsob ataque24 set 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-36804HIGHsob ataque24 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
GitHub PoC
PoC exploit for CVE-2022-36804 (BitBucket Critical Command Injection)
CVE-2022-36804HIGHsob ataque24 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
Exploit-DB
Teleport v10.1.1 - Remote Code Execution (RCE)
CVE-2022-36633remotemultiple23 set 2022
Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ss
35RISCO
abrir
Exploit-DB
TP-Link Tapo c200 1.1.15 - Remote Code Execution (RCE)
CVE-2021-4045CRITICALwebappshardware23 set 2022
TP-LINK Tapo C200 remote code execution vulnerability
70RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2022-36804HIGHsob ataque23 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
Exploit-DBVexDay Proof
Wordpress Plugin WP-UserOnline 2.88.0 - Stored Cross Site Scripting (XSS)
CVE-2022-2941MEDIUMwebappsphp23 set 2022
WP-UserOnline <= 2.88.0 - Authenticated (Admin+) Stored Cross-Site Scripting
33RISCO
abrir
GitHub PoC46
CVE-2022-39197(CobaltStrike XSS <=4.7) POC
CVE-2022-39197MEDIUMsob ataque23 set 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-39197MEDIUMsob ataque23 set 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISCO
abrir
Exploit-DB
Feehi CMS 2.1.1 - Remote Code Execution (Authenticated)
CVE-2022-34140webappsphp23 set 2022
A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to
23RISCO
abrir
GitHub PoC4
PoC exploit for CVE-2022-36804 (BitBucket Critical Command Injection)
CVE-2022-36804HIGHsob ataque23 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
GitHub PoC3
WSO2 Arbitrary File Upload to Remote Command Execution (RCE)
CVE-2022-29464CRITICALsob ataqueransomware22 set 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir
GitHub PoC
cobaltstrike4.5版本破/解、去除checksum8特征、bypass BeaconEye、修复错误路径泄漏stage、增加totp双因子验证、修复CVE-2022-39197等
CVE-2022-39197MEDIUMsob ataque22 set 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISCO
abrir
GitHub PoC73
cve-2022-39197 poc
CVE-2022-39197MEDIUMsob ataque22 set 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALsob ataqueransomware22 set 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir
GitHub PoC3
PoC for exploiting CVE-2019-2729 on WebLogic
CVE-2019-2729CRITICAL22 set 2022
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
85RISCO
abrir
Metasploit600
mySCADA MyPRO Authenticated Command Injection (CVE-2023-28384)
CVE-2023-28384HIGH22 set 2022
CVE-2023-28384
48RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-2729CRITICAL22 set 2022
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
85RISCO
abrir
GitHub PoC
For detection of sitecore RCE - CVE-2021-42237
CVE-2021-42237CRITICALsob ataqueransomware22 set 2022
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2022-39197MEDIUMsob ataque22 set 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2015-856221 set 2022
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISCO
abrir
GitHub PoC2
MoCh3n/CVE-2015-5531-POC
CVE-2015-553121 set 2022
Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unsp
60RISCO
abrir
GitHub PoC1
Caihuar/Joomla-cve-2015-8562
CVE-2015-856221 set 2022
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISCO
abrir
GitHub PoC7
Bitbucket CVE-2022-36804 unauthenticated remote command execution
CVE-2022-36804HIGHsob ataque21 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-36804HIGHsob ataque21 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
GitHub PoC1
CVE-2021-44228 POC / Example
CVE-2021-44228CRITICALsob ataqueransomware21 set 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
anteriorpágina 551 / 2.585próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.