Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.772exploits catalogados
35.760CVEs com exploração pública
24.695testados em laboratório
77.772 exploits
GitHub PoC
h3x0v3rl0rd/CVE-2014-0160_Heartbleed
CVE-2014-0160HIGHsob ataque24 abr 2022
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
CVE-2022-26809-RCE
CVE-2022-26809CRITICAL23 abr 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALsob ataque23 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC5
mariomamo/CVE-2022-22965
CVE-2022-22965CRITICALsob ataque23 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC1
0xAgun/CVE-2022-29464
CVE-2022-29464CRITICALsob ataqueransomware22 abr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir
GitHub PoC3
Repository containing nse script for vulnerability CVE-2022-29464 known as WSO2 RCE.
CVE-2022-29464CRITICALsob ataqueransomware22 abr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir
GitHub PoC5
WSO2 RCE (CVE-2022-29464)
CVE-2022-29464CRITICALsob ataqueransomware22 abr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2017-0199HIGHsob ataqueransomware22 abr 2022
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir
GitHub PoC5
cve-2022-29464 批量脚本
CVE-2022-29464CRITICALsob ataqueransomware22 abr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALsob ataqueransomware22 abr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir
GitHub PoC
A python script/generator, for generating and exploiting Microsoft vulnerability
CVE-2017-0199HIGHsob ataqueransomware22 abr 2022
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir
GitHub PoC
This repository contains a PoC for remote code execution CVE-2022-26809
CVE-2022-26809CRITICAL22 abr 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISCO
abrir
VulnCheck XDB
initial-access
CVE-2016-1092421 abr 2022
The ebook-download plugin before 1.2 for WordPress has directory traversal.
43RISCO
abrir
GitHub PoC2
tufanturhan/wso2-rce-cve-2022-29464
CVE-2022-29464CRITICALsob ataqueransomware21 abr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir
GitHub PoC1
c4mx/CVE-2022-22965_PoC
CVE-2022-22965CRITICALsob ataque21 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC2
Pre-auth RCE bug CVE-2022-29464
CVE-2022-29464CRITICALsob ataqueransomware21 abr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALsob ataque20 abr 2022
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2017-0199HIGHsob ataqueransomware20 abr 2022
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir
GitHub PoC377
WSO2 RCE (CVE-2022-29464) exploit and writeup.
CVE-2022-29464CRITICALsob ataqueransomware20 abr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALsob ataqueransomware20 abr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir
GitHub PoC
CVE-2021-4034 PoC
CVE-2021-4034HIGHsob ataqueransomware20 abr 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
MS CVE 2019-0708 Python Exploit
CVE-2019-0708CRITICALsob ataqueransomware20 abr 2022
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataqueransomware20 abr 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
CVE-2017-9841批量扫描及利用脚本。PHPUnit是其中的一个基于PHP的测试框架。 PHPUnit 4.8.28之前的版本和5.6.3之前的5.x版本中的Util/PHP/eval-stdin.php文件存在安全漏洞。远程攻击者可通过发送以‘<?php’字符串开头的HTTP POST数据利用该漏洞执行任意PHP代码。
CVE-2017-9841CRITICALsob ataque20 abr 2022
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISCO
abrir
GitHub PoC1
Phantomlancer123/CVE-2017-0199
CVE-2017-0199HIGHsob ataqueransomware20 abr 2022
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHsob ataque20 abr 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
Exploit-DB
PKP Open Journals System 3.3 - Cross-Site Scripting (XSS)
CVE-2022-24181webappsphp19 abr 2022
Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to
38RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-1635CRITICALsob ataque19 abr 2022
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-20198CRITICALsob ataque19 abr 2022
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir
Exploit-DB
Zyxel NWA-1100-NH - Command Injection
CVE-2021-4039CRITICALremotehardware19 abr 2022
A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to exec
70RISCO
abrir
anteriorpágina 586 / 2.593próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.