Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.533exploits catalogados
35.607CVEs com exploração pública
24.695testados em laboratório
77.533 exploits
GitHub PoC1
Caihuar/Joomla-cve-2015-8562
CVE-2015-856221 set 2022
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISCO
abrir
GitHub PoC3
CVE-2022-39197
CVE-2022-39197MEDIUMsob ataque21 set 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALsob ataqueransomware21 set 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC82
Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.
CVE-2007-4559CRITICAL20 set 2022
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows
53RISCO
abrir
GitHub PoC3
CVE-2022-36804 Atlassian Bitbucket Command Injection Vulnerability
CVE-2022-36804HIGHsob ataque20 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2022-36804HIGHsob ataque20 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-36804HIGHsob ataque20 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
Metasploit300
Mobile Mouse RCE
CVE-2023-31902CRITICAL20 set 2022
RPA Technology Mobile Mouse 3.6.0.4 is vulnerable to Remote Code Execution (RCE).
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware20 set 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
Metasploit300
Remote Control Collection RCE
CVE-2022-4978CRITICAL20 set 2022
Steppschuh Remote Control Server 3.1.1.12 Unauthenticated RCE
63RISCO
abrir
GitHub PoC16
Somewhat Reliable PoC Exploit for CVE-2022-36804 (BitBucket Critical Command Injection)
CVE-2022-36804HIGHsob ataque20 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
GitHub PoC3
CVE-2019-8943 WordPress Crop-Image
CVE-2019-894320 set 2022
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can
60RISCO
abrir
GitHub PoC
dileepdkumar/LayarKacaSiber-CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware20 set 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
A critical vulnerability (CVE-2022-36804) in Atlassian Bitbucket Server and Data Center could be exploited by unauthorized attackers to execute malicious code on vulnerable instances.
CVE-2022-36804HIGHsob ataque20 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
Exploit-DB
Blink1Control2 2.2.7 - Weak Password Encryption
CVE-2022-35513localmultiple20 set 2022
The Blink1Control2 application <= 2.2.7 uses weak password encryption and an insecure method of storage.
23RISCO
abrir
Exploit-DB
Airspan AirSpot 5410 version 0.3.4.1 - Remote Code Execution (RCE)
CVE-2022-36267remotelinux20 set 2022
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerabilit
35RISCO
abrir
Exploit-DBVexDay Proof
Bookwyrm v0.4.3 - Authentication Bypass
CVE-2022-2651CRITICALwebappsmultiple20 set 2022
Authentication Bypass by Primary Weakness in bookwyrm-social/bookwyrm
53RISCO
abrir
VulnCheck XDB
local
CVE-2017-12149CRITICALsob ataqueransomware19 set 2022
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISCO
abrir
GitHub PoC18
Multithreaded exploit script for CVE-2022-36804 affecting BitBucket versions <8.3.1
CVE-2022-36804HIGHsob ataque19 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-36804HIGHsob ataque19 set 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-31814CRITICAL18 set 2022
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir
GitHub PoC2
All Credit to MaherAzzouzi (https://github.com/MaherAzzouzi/CVE-2022-37706-LPE-exploit). This is a copy of the exploit for CTFs
CVE-2022-37706HIGH18 set 2022
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RISCO
abrir
GitHub PoC4
CVE-2022-31814 Exploitation Toolkit.
CVE-2022-31814CRITICAL18 set 2022
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir
GitHub PoC1
touchmycrazyredhat/CVE-2022-27925-Revshell
CVE-2022-27925HIGHsob ataqueransomware17 set 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISCO
abrir
GitHub PoC4
CVE-2019-0708, A tool which mass hunts for bluekeep vulnerability for exploitation.
CVE-2019-0708CRITICALsob ataqueransomware17 set 2022
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-27925HIGHsob ataqueransomware17 set 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISCO
abrir
GitHub PoC
cve-2010-2553复现
CVE-2010-255316 set 2022
The Cinepak codec in Microsoft Windows XP SP2 and SP3, Windows Vista SP1 and SP2, and Windows 7 does not properly decomp
35RISCO
abrir
GitHub PoC1
pswalia2u/CVE-2020-7246
CVE-2020-724616 set 2022
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISCO
abrir
GitHub PoC
mightysai1997/CVE-2021-41773.git1
CVE-2021-41773HIGHsob ataqueransomware15 set 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
mightysai1997/cve-2021-42013
CVE-2021-42013CRITICALsob ataqueransomware15 set 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
anteriorpágina 552 / 2.585próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.