Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.589exploits catalogados
34.508CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.554GitHub PoC 13.689VulnCheck XDB 8.216Nuclei 4.223Metasploit 3.464✓ só verificadosrecentespopularesrisco
13.689 exploits
GitHub PoC★ 5
it's a CVE-2023-28229 (Patched), but feel free to use it for check any outdated software or reseach
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
71RISCO
abrir ↗GitHub PoC★ 10
Exploit Toolkit for Adobe ColdFusion CVE-2024-20767 Vulnerability
ColdFusion | Improper Access Control (CWE-284)
100RISCO
abrir ↗GitHub PoC
NMinhTrung/LIFERAY-CVE-2020-7961
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISCO
abrir ↗GitHub PoC★ 1
404fu/CVE-2022-26134-POC
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir ↗GitHub PoC★ 34
Exploit for CVE-2024-20767 - Adobe ColdFusion
ColdFusion | Improper Access Control (CWE-284)
100RISCO
abrir ↗GitHub PoC★ 1
Proof of Concept for CVE-2024-20767. Arbitrary file read from Adobe ColdFusion
ColdFusion | Improper Access Control (CWE-284)
100RISCO
abrir ↗GitHub PoC★ 3
Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using the Log4J vulnerability (CVE-2021-44228). I examined teh amount of endpoints communicating with the server and knowing jnidi as a common in the vulnerbilty found it in clear text
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC
Madan301/CVE-2024-2054
Artica Proxy Unauthenticated PHP Deserialization Vulnerability
85RISCO
abrir ↗GitHub PoC★ 9
evil-winrar,CVE-2023-38831漏洞利用和社会工程学攻击框架 (evil-winrar, CVE-2023-38831 Vulnerability Exploitation and Social Engineering Attack Framework)
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir ↗GitHub PoC★ 2
Part of my cybersecurity thesis consists in exploring and exploiting this vulnerability.
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir ↗GitHub PoC★ 1
exploit CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC★ 1
sxyrxyy/CVE-2024-1709-ConnectWise-ScreenConnect-Authentication-Bypass
Authentication bypass using an alternate path or channel
100RISCO
abrir ↗GitHub PoC
Nhom6KTLT/CVE-2010-3124
Untrusted search path vulnerability in bin/winvlc.c in VLC Media Player 1.1.3 and earlier allows local users, and possib
28RISCO
abrir ↗GitHub PoC★ 2
XenoM0rph97/CVE-2024-30896
InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows aut
48RISCO
abrir ↗GitHub PoC
Practice POC scripting in Tryhackme’s intro poc scripting room (For Linux)
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISCO
abrir ↗GitHub PoC★ 130
Windows Kernel Pool (clfs.sys) Corruption Privilege Escalation
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir ↗GitHub PoC
JolynNgSC/Zerologon_CVE-2020-1472
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC★ 8
POC code according to trendmicro's research
Internet Shortcut Files Security Feature Bypass Vulnerability
93RISCO
abrir ↗GitHub PoC★ 6
it's a CVE-2023-28252 (Patched), but feel free to use it for check any outdated software or reseach
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RISCO
abrir ↗GitHub PoC★ 1
Lilly-dox/Exploit-CVE-2023-22518
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz
100RISCO
abrir ↗GitHub PoC★ 1
Proof of Work of CVE-2023-23397 for vulnerable Microsoft Outlook client application.
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC★ 2.448
Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, including Debian, Ubuntu, and KernelCTF. The success rate is 99.4% in KernelCTF images.
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISCO
abrir ↗GitHub PoC★ 27
aiohttp LFI (CVE-2024-23334)
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir ↗GitHub PoC★ 1
A vuln about csapp.
Buffer Overflow vulnerability in CSAPP_Lab CSAPP Lab3 15-213 Fall 20xx allows a remote attacker to execute arbitrary cod
48RISCO
abrir ↗GitHub PoC★ 19
Unauthenticated Command Injection In Progress Kemp LoadMaster
LoadMaster Pre-Authenticated OS Command Injection
100RISCO
abrir ↗GitHub PoC★ 1
Matrexdz/CVE-2024-1071-Docker
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RISCO
abrir ↗GitHub PoC★ 1
CVE-2024-1071
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.