Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.772exploits catalogados
35.760CVEs com exploração pública
24.695testados em laboratório
77.724 exploits
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALsob ataqueransomware11 mai 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALsob ataqueransomware11 mai 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir
Exploit-DB
MyBB 1.8.29 - MyBB 1.8.29 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-24734HIGHwebappsphp11 mai 2022
Remote code execution in mybb
78RISCO
abrir
Exploit-DB
Anuko Time Tracker - SQLi (Authenticated)
CVE-2022-24707HIGHwebappsphp11 mai 2022
SQL injection in anuko timetracker
41RISCO
abrir
GitHub PoC
CVE-2022-1388
CVE-2022-1388CRITICALsob ataqueransomware11 mai 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir
Exploit-DB
DLINK DIR850 - Open Redirect
CVE-2021-46379remotehardware11 mai 2022
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrust
43RISCO
abrir
Exploit-DB
TLR-2005KSH - Arbitrary File Upload
CVE-2021-45428webappshardware11 mai 2022
TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can uploa
50RISCO
abrir
Exploit-DB
PHProjekt PhpSimplyGest v1.3. - Stored Cross-Site Scripting (XSS)
CVE-2022-27308webappsphp11 mai 2022
A stored cross-site scripting (XSS) vulnerability in PHProjekt PhpSimplyGest v1.3.0 allows attackers to execute arbitrar
23RISCO
abrir
Exploit-DB
SAP BusinessObjects Intelligence 4.3 - XML External Entity (XXE)
CVE-2022-28213remotemultiple11 mai 2022
When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does n
28RISCO
abrir
Exploit-DB
ManageEngine ADSelfService Plus Build 6118 - NTLMv2 Hash Exposure
CVE-2022-29457remotewindows11 mai 2022
Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131
23RISCO
abrir
GitHub PoC
Research and proof of concept related to CVE-2022-1388.
CVE-2022-1388CRITICALsob ataqueransomware11 mai 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir
Exploit-DB
Akka HTTP 10.1.14 - Denial of Service
CVE-2021-42697remotemultiple11 mai 2022
Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, whic
35RISCO
abrir
Exploit-DB
Explore CMS 1.0 - SQL Injection
CVE-2022-27412webappsphp11 mai 2022
Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request.
23RISCO
abrir
Exploit-DB
WebTareas 2.4 - Blind SQLi (Authenticated)
CVE-2021-43481webappsphp11 mai 2022
An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstag
23RISCO
abrir
Exploit-DB
WordPress Plugin Advanced Uploader 4.2 - Arbitrary File Upload (Authenticated)
CVE-2022-1103webappsphp11 mai 2022
Advanced Uploader <= 4.2 - Subscriber+ Arbitrary File Upload
28RISCO
abrir
GitHub PoC
This repository consists of the python exploit for CVE-2022-1388 (F5's BIG-IP Authentication Bypass to RCE)
CVE-2022-1388CRITICALsob ataqueransomware11 mai 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir
Exploit-DB
ExifTool 12.23 - Arbitrary Code Execution
CVE-2021-22204MEDIUMsob ataquelocallinux11 mai 2022
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISCO
abrir
GitHub PoC7
A Zeek package to detect CVE-2022-26937, a vulnerability in the Network Lock Manager (NLM) protocol in Windows NFS server.
CVE-2022-26937CRITICAL11 mai 2022
Windows Network File System Remote Code Execution Vulnerability
70RISCO
abrir
Exploit-DB
DLINK DIR850 - Insecure Access Control
CVE-2021-46378remotehardware11 mai 2022
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote
35RISCO
abrir
GitHub PoC
ShaikUsaf/external_expact_AOSP10_r33_CVE-2022-25315
CVE-2022-25315CRITICAL11 mai 2022
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
48RISCO
abrir
Exploit-DB
Cyclos 4.14.7 - 'groupId' DOM Based Cross-Site Scripting (XSS)
CVE-2021-31673webappsmultiple11 mai 2022
A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remo
23RISCO
abrir
Exploit-DBVexDay Proof
Wondershare Dr.Fone 12.0.7 - Privilege Escalation (ElevationService)
CVE-2021-44595localwindows11 mai 2022
Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send m
28RISCO
abrir
GitHub PoC5
AmirHoseinTangsiriNET/CVE-2022-1388-Scanner
CVE-2022-1388CRITICALsob ataqueransomware11 mai 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir
GitHub PoC2
CVE-2022-1388 Scanner
CVE-2022-1388CRITICALsob ataqueransomware11 mai 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir
Exploit-DB
Google Chrome 78.0.3904.70 - Remote Code Execution
CVE-2019-13720HIGHsob ataqueremotemultiple11 mai 2022
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap
83RISCO
abrir
Exploit-DB
Ruijie Reyee Mesh Router - Remote Code Execution (RCE) (Authenticated)
CVE-2021-43164remotehardware11 mai 2022
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191
35RISCO
abrir
Exploit-DB
DLINK DAP-1620 A1 v1.01 - Directory Traversal
CVE-2021-46381remotehardware11 mai 2022
Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd]
50RISCO
abrir
GitHub PoC1
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView class, which allows remote attackers to execute arbitrary methods of Java objects or cause a denial of service (reboot) via a crafted web page, as demonstrated by use of the WebView.addJavascriptInterface method, a related issue to CVE-2012-6636.
CVE-2012-663611 mai 2022
The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote atta
50RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-2554010 mai 2022
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on
60RISCO
abrir
Metasploit600
Zip Path Traversal in Zimbra (mboximport) (CVE-2022-27925)
CVE-2022-37042CRITICALsob ataqueransomware10 mai 2022
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts fi
100RISCO
abrir
anteriorpágina 580 / 2.591próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.