Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.813exploits catalogados
35.788CVEs com exploração pública
24.695testados em laboratório
77.772 exploits
GitHub PoC77
Spring Cloud Gateway 远程代码执行漏洞Exp Spring_Cloud_Gateway_RCE_Exp-CVE-2022-22947
CVE-2022-22947CRITICALsob ataque03 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC10
Spring cloud gateway code injection : CVE-2022-22947
CVE-2022-22947CRITICALsob ataque03 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC
poc for cve-2022-22947
CVE-2022-22947CRITICALsob ataque03 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC1
Zero-day-scanning is a Domain Controller vulnerability scanner, that currently includes checks for Zero-day-scanning (CVE-2020-1472), MS-PAR/MS-RPRN and SMBv2 Signing.
CVE-2020-1472MEDIUMsob ataqueransomware03 mar 2022
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC28
SpringCloudGatewayRCE - CVE-2022-22947 / Code By:Tas9er
CVE-2022-22947CRITICALsob ataque03 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2020-1472MEDIUMsob ataqueransomware03 mar 2022
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC38
Spring Cloud Gateway < 3.0.7 & < 3.1.1 Code Injection (RCE)
CVE-2022-22947CRITICALsob ataque03 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataqueransomware03 mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataqueransomware03 mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataqueransomware03 mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALsob ataque03 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC
Test tool for CVE-2020-1472
CVE-2020-1472MEDIUMsob ataqueransomware03 mar 2022
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
Exploit-DB
Xerte 3.10.3 - Directory Traversal (Authenticated)
CVE-2021-44665webappsphp02 mar 2022
A Directory Traversal vulnerability exists in the Xerte Project Xerte through 3.10.3 when downloading a project file via
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALsob ataque02 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataqueransomware02 mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
takumak/cve-2019-5736-reproducer
CVE-2019-573602 mar 2022
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
Exploit-DB
Xerte 3.9 - Remote Code Execution (RCE) (Authenticated)
CVE-2021-44664webappsphp02 mar 2022
An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupl
28RISCO
abrir
GitHub PoC223
CVE-2022-22947
CVE-2022-22947CRITICALsob ataque02 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
Exploit-DB
Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site Scripting (XSS)
CVE-2021-46387webappsmultiple02 mar 2022
ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads t
43RISCO
abrir
GitHub PoC4
A "Creation of Temporary Files in Directory with Insecure Permissions" vulnerability in PrintixService.exe, in Printix's "Printix Secure Cloud Print Management", Version 1.3.1106.0 and below allows any logged in user to elevate any executable or file to the SYSTEM context. This is achieved by exploiting race conditions in the Installer.
CVE-2022-2509002 mar 2022
Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure
28RISCO
abrir
VulnCheck XDB
local
CVE-2018-100000101 mar 2022
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISCO
abrir
GitHub PoC
Tools for get offsets and adding patch for support i386
CVE-2018-100000101 mar 2022
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISCO
abrir
GitHub PoC
This script is intended to validate Apache Struts 2 vulnerability (CVE-2017-5638), AKA Struts-Shock.
CVE-2017-5638CRITICALsob ataqueransomware28 fev 2022
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHsob ataque28 fev 2022
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
GitHub PoC15
Zabbix - SAML SSO Authentication Bypass
CVE-2022-23131CRITICALsob ataque28 fev 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISCO
abrir
GitHub PoC1
Android Ransomware Development - AES256 encryption + CVE-2019-2215 (reverse root shell) + Data Exfiltration
CVE-2019-2215HIGHsob ataque28 fev 2022
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
GitHub PoC47
Test whether a container environment is vulnerable to container escapes via CVE-2022-0492
CVE-2022-0492HIGHsob ataque28 fev 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RISCO
abrir
Exploit-DB
Casdoor 1.13.0 - SQL Injection (Unauthenticated)
CVE-2022-24124webappsmultiple28 fev 2022
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as d
50RISCO
abrir
Metasploit300
Wordpress BookingPress bookingpress_front_get_category_services SQLi
CVE-2022-073928 fev 2022
BookingPress < 1.0.11 - Unauthenticated SQL Injection
30RISCO
abrir
GitHub PoC
CVE-2022-24086 RCE
CVE-2022-24086CRITICALsob ataque28 fev 2022
Adobe Commerce checkout improper input validation leads to remote code execution
100RISCO
abrir
anteriorpágina 603 / 2.593próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.