Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.813exploits catalogados
35.788CVEs com exploração pública
24.695testados em laboratório
77.772 exploits
VulnCheck XDB
local
CVE-2016-5195HIGHsob ataque07 mar 2022
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC282
CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞,可覆盖重写任意可读文件中的数据,从而可将普通权限的用户提升到特权 root。 CVE-2022-0847 的漏洞原理类似于 CVE-2016-5195 脏牛漏洞(Dirty Cow),但它更容易被利用。漏洞作者将此漏洞命名为“Dirty Pipe”
CVE-2022-0847HIGHsob ataque07 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHsob ataque07 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
Metasploit600
TerraMaster TOS 4.2.29 or lower - Unauthenticated RCE chaining CVE-2022-24990 and CVE-2022-24989
CVE-2022-24990CRITICALsob ataqueransomware07 mar 2022
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agen
100RISCO
abrir
GitHub PoC9
CVE-2022-0847 exploit one liner
CVE-2022-0847HIGHsob ataque07 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
Metasploit600
TerraMaster TOS 4.2.29 or lower - Unauthenticated RCE chaining CVE-2022-24990 and CVE-2022-24989
CVE-2022-2498907 mar 2022
TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskst
30RISCO
abrir
VulnCheck XDB
local
CVE-2022-0492HIGHsob ataque06 mar 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RISCO
abrir
GitHub PoC113
Webmin <=1.984, CVE-2022-0824 Post-Auth Reverse Shell PoC
CVE-2022-0824HIGH06 mar 2022
Improper Access Control to Remote Code Execution in webmin/webmin
78RISCO
abrir
GitHub PoC11
A script to check if a container environment is vulnerable to container escapes via CVE-2022-0492
CVE-2022-0492HIGHsob ataque06 mar 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RISCO
abrir
GitHub PoC2
22ke/CVE-2022-22947
CVE-2022-22947CRITICALsob ataque05 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC
日常更新一些顺手写的gobypoc,包含高危害EXP
CVE-2022-22947CRITICALsob ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC2
Spring Cloud Gateway Actuator API 远程命令执行 CVE-2022-22947
CVE-2022-22947CRITICALsob ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC7
批量url检测Spring-Cloud-Gateway-CVE-2022-22947
CVE-2022-22947CRITICALsob ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC5
Greetdawn/CVE-2022-22947
CVE-2022-22947CRITICALsob ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHsob ataque04 mar 2022
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2019-11043HIGHsob ataqueransomware04 mar 2022
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC
Spring Cloud Gateway远程代码执行漏洞
CVE-2022-22947CRITICALsob ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC
Exp
CVE-2022-22947CRITICALsob ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC71
CVE-2022-22947批量
CVE-2022-22947CRITICALsob ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC9
cve-2022-22947 spring cloud gateway 批量扫描脚本
CVE-2022-22947CRITICALsob ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataqueransomware04 mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
CVE-2019-11043 LAB
CVE-2019-11043HIGHsob ataqueransomware04 mar 2022
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC8
9lyph/CVE-2022-29593
CVE-2022-29593MEDIUM04 mar 2022
relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post reques
38RISCO
abrir
VulnCheck XDB
local
CVE-2021-40449HIGHsob ataqueransomware04 mar 2022
Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
CVE-2022-22947批量检测脚本,回显命令没进行正则,大佬们先用着,后续再更
CVE-2022-22947CRITICALsob ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-0185HIGHsob ataque04 mar 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RISCO
abrir
GitHub PoC3
Spring-Cloud-Gateway-CVE-2022-22947
CVE-2022-22947CRITICALsob ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALsob ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALsob ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALsob ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
anteriorpágina 602 / 2.593próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.