Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.813exploits catalogados
35.788CVEs com exploração pública
24.695testados em laboratório
77.813 exploits
GitHub PoC27
Oracle WebLogic Server 12.1.3.0.0 / 12.2.1.3.0 / 12.2.1.4.0 / 14.1.1.0.0 Local File Inclusion
CVE-2022-21371HIGH25 jan 2022
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
78RISCO
abrir
Exploit-DB
PHPIPAM 1.4.4 - SQLi (Authenticated)
CVE-2022-23046webappsphp25 jan 2022
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su
28RISCO
abrir
Metasploit600
Local Privilege Escalation in polkits pkexec
CVE-2021-4034HIGHsob ataqueransomware25 jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataqueransomware25 jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2019-573625 jan 2022
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
VulnCheck XDB
infoleak
CVE-2022-21371HIGH25 jan 2022
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
78RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataqueransomware25 jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
Exploit-WordPress Plugin The True Ranker 2.2.2 - Arbitrary File Read
CVE-2021-39312HIGH24 jan 2022
True Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read
78RISCO
abrir
VulnCheck XDB
info-leak
CVE-2021-39312HIGH24 jan 2022
True Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read
78RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2022-21907CRITICAL23 jan 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-1881823 jan 2022
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISCO
abrir
GitHub PoC2
Strapi CMS 3.0.0-beta.17.4 - Unauthenticated Remote Code Execution (CVE-2019-18818, CVE-2019-19609)
CVE-2019-1960923 jan 2022
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISCO
abrir
Metasploit300
Wordpress RegistrationMagic task_ids Authenticated SQLi
CVE-2021-2486223 jan 2022
RegistrationMagic < 5.0.1.6 - Admin+ SQL Injection
60RISCO
abrir
GitHub PoC28
CVE-2022-21907 Vulnerability PoC
CVE-2022-21907CRITICAL23 jan 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC1
jcarabantes/CVE-2022-23046
CVE-2022-2304622 jan 2022
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su
28RISCO
abrir
Metasploit600
Apache Couchdb Erlang RCE
CVE-2022-24706CRITICALsob ataque21 jan 2022
Remote Code Execution Vulnerability in Packaging
100RISCO
abrir
GitHub PoC5
test 反向辣鸡数据投放 CVE-2022-23305 工具 利用 教程 Exploit POC
CVE-2022-23305CRITICAL21 jan 2022
SQL injection in JDBC Appender in Apache Log4j V1
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-24489CRITICALsob ataque20 jan 2022
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, coul
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-7609CRITICALsob ataque19 jan 2022
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISCO
abrir
Metasploit600
Oracle Access Manager unauthenticated Remote Code Execution
CVE-2021-35587CRITICALsob ataque19 jan 2022
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported ver
100RISCO
abrir
GitHub PoC24
💀 Linux local root exploit for CVE-2018-18955
CVE-2018-1895519 jan 2022
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISCO
abrir
VulnCheck XDB
local
CVE-2022-0185HIGHsob ataque19 jan 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RISCO
abrir
GitHub PoC375
CVE-2022-0185
CVE-2022-0185HIGHsob ataque19 jan 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALsob ataqueransomware18 jan 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
Exploit-DB
Creston Web Interface 1.0.0.2159 - Credential Disclosure
CVE-2022-23178webappshardware18 jan 2022
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-6287CRITICALsob ataque18 jan 2022
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2020-1472MEDIUMsob ataqueransomware18 jan 2022
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-43798HIGHsob ataque18 jan 2022
Grafana path traversal
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2022-21661HIGH18 jan 2022
SQL injection in WordPress
78RISCO
abrir
GitHub PoC83
Proof of concept of CVE-2022-21907 Double Free in http.sys driver, triggering a kernel crash on IIS servers
CVE-2022-21907CRITICAL17 jan 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISCO
abrir
anteriorpágina 614 / 2.594próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.