Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.772exploits catalogados
35.760CVEs com exploração pública
24.695testados em laboratório
77.772 exploits
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALsob ataque15 abr 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-3180515 abr 2022
Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.
60RISCO
abrir
GitHub PoC4
CVE-2022-22954 VMware Workspace ONE Access free marker SSTI
CVE-2022-22954CRITICALsob ataqueransomware15 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir
Metasploit300
VMware vCenter Secrets Dump
CVE-2022-22948MEDIUMsob ataque15 abr 2022
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious act
83RISCO
abrir
GitHub PoC3
CVE-2022-0185 exploit
CVE-2022-0185HIGHsob ataque14 abr 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RISCO
abrir
GitHub PoC8
Spring Cloud Function SPEL表达式注入漏洞(CVE-2022-22963)
CVE-2022-22963CRITICALsob ataque14 abr 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
GitHub PoC
VVeakee/CVE-2017-12149
CVE-2017-12149CRITICALsob ataqueransomware14 abr 2022
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISCO
abrir
GitHub PoC7
auduongxuan/CVE-2022-26809
CVE-2022-26809CRITICAL14 abr 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC19
The poc for CVE-2022-26809 RCE via RPC will be updated here.
CVE-2022-26809CRITICAL14 abr 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC32
Detects attempts and successful exploitation of CVE-2022-26809
CVE-2022-26809CRITICAL14 abr 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC27
Remote Code Execution Exploit in the RPC Library
CVE-2022-26809CRITICAL14 abr 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-12149CRITICALsob ataqueransomware14 abr 2022
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISCO
abrir
VulnCheck XDB
local
CVE-2022-0185HIGHsob ataque14 abr 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RISCO
abrir
GitHub PoC1
Proof of Concept for exploiting VMware CVE-2022-22954
CVE-2022-22954CRITICALsob ataqueransomware14 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-1675HIGHsob ataqueransomware14 abr 2022
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC3
Easy!Appointments < 1.4.3 - Unauthenticated PII (events) disclosure
CVE-2022-0482CRITICAL13 abr 2022
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
75RISCO
abrir
GitHub PoC68
CVE-2022-22954 VMware Workspace ONE Access freemarker SSTI 漏洞 命令执行、批量检测脚本、文件写入
CVE-2022-22954CRITICALsob ataqueransomware13 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-22954CRITICALsob ataqueransomware13 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-22954CRITICALsob ataqueransomware13 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir
GitHub PoC
VMware Workspace ONE Access远程代码执行漏洞 / Code By:Jun_sheng
CVE-2022-22954CRITICALsob ataqueransomware13 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir
GitHub PoC16
VMware Workspace ONE Access and Identity Manager RCE via SSTI - Test script for shodan, file or manual.
CVE-2022-22954CRITICALsob ataqueransomware13 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALsob ataque13 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC3
A Zeek CVE-2022-24491 detector.
CVE-2022-24491CRITICAL13 abr 2022
Windows Network File System Remote Code Execution Vulnerability
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-26501CRITICALsob ataqueransomware13 abr 2022
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
78RISCO
abrir
GitHub PoC3
A Zeek detector for CVE-2022-24497.
CVE-2022-24497CRITICAL13 abr 2022
Windows Network File System Remote Code Execution Vulnerability
60RISCO
abrir
GitHub PoC
exploitation script tryhackme
CVE-2022-22965CRITICALsob ataque13 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC2
AkuCyberSec/CVE-2017-8917-Joomla-370-SQL-Injection
CVE-2017-891713 abr 2022
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISCO
abrir
GitHub PoC4
Greenwolf/CVE-2022-1162
CVE-2022-1162CRITICAL12 abr 2022
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE
85RISCO
abrir
GitHub PoC1
Greenwolf/CVE-2022-1175
CVE-2022-1175HIGH12 abr 2022
Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 befor
63RISCO
abrir
GitHub PoC3
TerraMaster TOS Unauthenticated Remote Command Execution(RCE) Vulnerability CVE-2022-24990
CVE-2022-24990CRITICALsob ataqueransomware12 abr 2022
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agen
100RISCO
abrir
anteriorpágina 588 / 2.593próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.