Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.753exploits catalogados
37.445CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 23.871GitHub PoC 15.407VulnCheck XDB 9.065Nuclei 4.426Metasploit 3.502✓ só verificadosrecentespopularesrisco
15.407 exploits
GitHub PoC★ 1
Powershell script that checks for cert padding in the Windows Registry and adds it if it does not exist. Meant to resolve the WinTrustVerify Vulnerability.
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir ↗GitHub PoC
CVE Exploitation Reports: CVE-2007-3280, CVE-2017-0144, CVE-2019-0708
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir ↗GitHub PoC★ 2
Spring Cloud Remote Code Execution
CVE-2024-37084: Remote code execution in Spring Cloud Data Flow
60RISCO
abrir ↗GitHub PoC
CVE Exploitation Reports: CVE-2007-3280, CVE-2017-0144, CVE-2019-0708
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir ↗GitHub PoC
My proof of concept for CVE-2019 Microsoft-Edge
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISCO
abrir ↗GitHub PoC★ 1
KaoXx/CVE-2022-37706
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RISCO
abrir ↗GitHub PoC★ 1
CVE-2024-38063 - Remotely Exploiting The Kernel Via IPv6
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC
Python3 toolkit update
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir ↗GitHub PoC★ 1
Artemisxxx37/OverlayFS-PrivEsc-CVE-2022-0944
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISCO
abrir ↗GitHub PoC★ 9
0xRoqeeb/sqlpad-rce-exploit-CVE-2022-0944
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISCO
abrir ↗GitHub PoC★ 3
JSON API User <= 3.9.3 - Unauthenticated Privilege Escalation
JSON API User <= 3.9.3 - Unauthenticated Privilege Escalation
48RISCO
abrir ↗GitHub PoC★ 3
Analysis , Demo exploit and poc about CVE-2024-37084
CVE-2024-37084: Remote code execution in Spring Cloud Data Flow
60RISCO
abrir ↗GitHub PoC★ 1
Scanning CVE-2024-4577 vulnerability with a url list.
Argument Injection in PHP-CGI
100RISCO
abrir ↗GitHub PoC
carradolly/CVE-2015-8660
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RISCO
abrir ↗GitHub PoC★ 5
CVE-2024-28000 Exploit for litespeed-cache =<6.3 allows Privilege Escalation with creation of administrator account
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISCO
abrir ↗GitHub PoC
CVE-2024-23897 분석
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗GitHub PoC★ 5
SQLPad - Template injection (POC exploit for SQLPad RCE [CVE-2022-0944])
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISCO
abrir ↗GitHub PoC★ 1
CVE-2024-28000 LiteSpeed Cache Privilege Escalation Scan&Exp
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISCO
abrir ↗GitHub PoC
PoC code written for CVE-2022-0944 to make exploitation easier. Based on information found here: https://huntr.com/bounties/46630727-d923-4444-a421-537ecd63e7fb
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISCO
abrir ↗GitHub PoC★ 4
CVE-2018-0834 full code exec
Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remot
35RISCO
abrir ↗GitHub PoC★ 7
A proof of concept exploit for SQLPad RCE (CVE-2022-0944).
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISCO
abrir ↗GitHub PoC★ 4
A proof of concept of the LFI vulnerability on aiohttp 3.9.1
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir ↗GitHub PoC
quick powershell script to fix cve-2024-38063
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 5
🔥 CVE-2024-44849 Exploit
Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.
75RISCO
abrir ↗GitHub PoC★ 16
CVE-2024-44000 is a vulnerability in the LiteSpeed Cache plugin, a popular WordPress plugin. This vulnerability affects session management in LiteSpeed Cache, allowing attackers to gain unauthorized access to sensitive data.
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RISCO
abrir ↗GitHub PoC★ 2
XSS to RCE in RenderTune v1.1.4 exploit
Cross-site scripting (XSS) vulnerability in RenderTune v1.1.4 allows attackers to execute arbitrary web scripts or HTML
48RISCO
abrir ↗GitHub PoC
test POC for CVE-2019-10149
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISCO
abrir ↗GitHub PoC
deskfiler 1.2.3 Open Redirect exploit
Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin.
48RISCO
abrir ↗GitHub PoC
LiteSpeed Unauthorized Account Takeover
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.