Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.497GitHub PoC 13.627VulnCheck XDB 8.198Nuclei 4.217Metasploit 3.463✓ só verificadosrecentespopularesrisco
13.618 exploits
GitHub PoC
CVE-2024-54383, https://www.cve.org/CVERecord?id=CVE-2024-54383
WordPress WooCommerce - PDF Vouchers plugin < 4.9.9 - Broken Authentication vulnerability
48RISCO
abrir ↗GitHub PoC
Sornphut/CVE-2021-3156-Heap-Based-Buffer-Overflow-in-Sudo-Baron-Samedit-
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir ↗GitHub PoC★ 3
Ivanti Remote code execution
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISCO
abrir ↗GitHub PoC★ 15
Exploit for CVE-2024-0402 in Gitlab
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
48RISCO
abrir ↗GitHub PoC
Sp4ceDogy/NPE-CS-V-CVE-2021-1675
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 4
Unauthenticated remote command execution in Papercut service allows an attacker to execute commands due to improper access controls in the SetupCompleted Java class.
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir ↗GitHub PoC
sk00l/CVE-2023-30258
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir ↗GitHub PoC
progress moveit cve-2024-5806
MOVEit Transfer Authentication Bypass Vulnerability
85RISCO
abrir ↗GitHub PoC
cve-2017-5487 wp rest api 취약점
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RISCO
abrir ↗GitHub PoC
elphon/CVE-2007-2447-Exploit
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir ↗GitHub PoC
Zimbra CVE-2024-45519
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISCO
abrir ↗GitHub PoC
CVE-2023-40028 is a security vulnerability affecting Ghost CMS versions prior to 5.59.1.
Arbitrary file read via symlinks in Ghost
45RISCO
abrir ↗GitHub PoC
Simulation of the Zerologon (CVE-2020-1472) vulnerability attack in Active Directory on Windows Server 2016 and the use of the Trend Micro Deep Security solution to prevent such attacks.
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC★ 4
Python3 Rewrite of SmarterMail < Build 6985 Remote Code Execution found by 1F98D (CVE-2019-7214) POC
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co
60RISCO
abrir ↗GitHub PoC★ 1
A Critical Windows OLE Zero-Click Vulnerability. This is a proof-of-concept for CVE-2025-21298 - Windows OLE Remote Code Execution Vulnerability (CVSS 9.8). This is a memory corruption PoC
Windows OLE Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC
This repository contains a PoC for exploiting CVE-2024-32002, a vulnerability in Git that allows RCE during a git clone operation. By crafting repositories with submodules in a specific way, an attacker can exploit symlink handling on case-insensitive filesystems to write files into the .git/ directory, leading to the execution of malicious hooks.
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir ↗GitHub PoC
This repository contains a PoC for exploiting CVE-2024-32002, a vulnerability in Git that allows RCE during a git clone operation. By crafting repositories with submodules in a specific way, an attacker can exploit symlink handling on case-insensitive filesystems to write files into the .git/ directory, leading to the execution of malicious hooks.
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir ↗GitHub PoC
HFS 2.3m SERVER RCE Vulnerability exploit
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir ↗GitHub PoC★ 2
Arbitrary file read in Grafana allows an attacker to read server files by abusing a path traversal.
Grafana path traversal
100RISCO
abrir ↗GitHub PoC★ 2
Newscrunch <= 1.8.4 - Authenticated (Subscriber+) Arbitrary File Upload
Newscrunch <= 1.8.4 - Authenticated (Subscriber+) Arbitrary File Upload
48RISCO
abrir ↗GitHub PoC
This exploit targets an unauthenticated SQL injection vulnerability in CMS Made Simple <= 2.2.9 (CVE-2019-9053). It uses a time-based blind SQL injection to extract the username, email, and password hash from the database. Additionally, it supports password cracking using a wordlist.
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir ↗GitHub PoC
GazettEl/CVE-2020-24186
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RISCO
abrir ↗GitHub PoC
x3m1Sec/CVE-2019-0232_tomcat_cgi_exploit
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISCO
abrir ↗GitHub PoC
Sornphut/OverlayFS---CVE-2021-3493
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir ↗GitHub PoC
PoC exploit for CVE-2012-2982 (Webmin RCE), for educational purposes.
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISCO
abrir ↗GitHub PoC
Exploitation for CVE-2022-26923
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC★ 1
build-script for CVE-2024-46507 and CVE-2024-46508
A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti befor
56RISCO
abrir ↗GitHub PoC★ 2
Combining CVE-2024-8963 & CVE-2024-8190 - For Unauthenticated RCE on Ivanti CSA 4.6 and below
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remo
93RISCO
abrir ↗GitHub PoC★ 3
Python script to exploit CVE-2020-35391 on Tenda F3 V3/V4 routers, enabling unauthorized download of configuration, flash, and syslog files.
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RISCO
abrir ↗GitHub PoC
GazettEl/CVE-2020-17519
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.