Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.772exploits catalogados
35.760CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.455Referência 22.523GitHub PoC 14.289VulnCheck XDB 8.710Nuclei 4.319Metasploit 3.476✓ só verificadosrecentespopularesrisco
77.724 exploits
VulnCheck XDB
initial-access
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir ↗VulnCheck XDB
initial-access
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir ↗Exploit-DB
MyBB 1.8.29 - MyBB 1.8.29 - Remote Code Execution (RCE) (Authenticated)
Remote code execution in mybb
78RISCO
abrir ↗GitHub PoC
CVE-2022-1388
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir ↗Exploit-DB
DLINK DIR850 - Open Redirect
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrust
43RISCO
abrir ↗Exploit-DB
TLR-2005KSH - Arbitrary File Upload
TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can uploa
50RISCO
abrir ↗Exploit-DB
PHProjekt PhpSimplyGest v1.3. - Stored Cross-Site Scripting (XSS)
A stored cross-site scripting (XSS) vulnerability in PHProjekt PhpSimplyGest v1.3.0 allows attackers to execute arbitrar
23RISCO
abrir ↗Exploit-DB
SAP BusinessObjects Intelligence 4.3 - XML External Entity (XXE)
When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does n
28RISCO
abrir ↗Exploit-DB
ManageEngine ADSelfService Plus Build 6118 - NTLMv2 Hash Exposure
Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131
23RISCO
abrir ↗GitHub PoC
Research and proof of concept related to CVE-2022-1388.
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir ↗Exploit-DB
Akka HTTP 10.1.14 - Denial of Service
Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, whic
35RISCO
abrir ↗Exploit-DB
Explore CMS 1.0 - SQL Injection
Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request.
23RISCO
abrir ↗Exploit-DB
WebTareas 2.4 - Blind SQLi (Authenticated)
An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstag
23RISCO
abrir ↗Exploit-DB
WordPress Plugin Advanced Uploader 4.2 - Arbitrary File Upload (Authenticated)
Advanced Uploader <= 4.2 - Subscriber+ Arbitrary File Upload
28RISCO
abrir ↗GitHub PoC
This repository consists of the python exploit for CVE-2022-1388 (F5's BIG-IP Authentication Bypass to RCE)
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir ↗Exploit-DB
ExifTool 12.23 - Arbitrary Code Execution
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISCO
abrir ↗GitHub PoC★ 7
A Zeek package to detect CVE-2022-26937, a vulnerability in the Network Lock Manager (NLM) protocol in Windows NFS server.
Windows Network File System Remote Code Execution Vulnerability
70RISCO
abrir ↗Exploit-DB
DLINK DIR850 - Insecure Access Control
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote
35RISCO
abrir ↗GitHub PoC
ShaikUsaf/external_expact_AOSP10_r33_CVE-2022-25315
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
48RISCO
abrir ↗Exploit-DB
Cyclos 4.14.7 - 'groupId' DOM Based Cross-Site Scripting (XSS)
A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Wondershare Dr.Fone 12.0.7 - Privilege Escalation (ElevationService)
Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send m
28RISCO
abrir ↗GitHub PoC★ 5
AmirHoseinTangsiriNET/CVE-2022-1388-Scanner
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir ↗GitHub PoC★ 2
CVE-2022-1388 Scanner
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir ↗Exploit-DB
Google Chrome 78.0.3904.70 - Remote Code Execution
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap
83RISCO
abrir ↗Exploit-DB
Ruijie Reyee Mesh Router - Remote Code Execution (RCE) (Authenticated)
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191
35RISCO
abrir ↗Exploit-DB
DLINK DAP-1620 A1 v1.01 - Directory Traversal
Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd]
50RISCO
abrir ↗GitHub PoC★ 1
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView class, which allows remote attackers to execute arbitrary methods of Java objects or cause a denial of service (reboot) via a crafted web page, as demonstrated by use of the WebView.addJavascriptInterface method, a related issue to CVE-2012-6636.
The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote atta
50RISCO
abrir ↗VulnCheck XDB
initial-access
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on
60RISCO
abrir ↗Metasploit600
Zip Path Traversal in Zimbra (mboximport) (CVE-2022-27925)
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts fi
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.