Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
13.727 exploits
GitHub PoC8
Local privilege escalation exploit for Android Binder bug CVE-2020-0041 (Pixel 3a)
CVE-2020-0041HIGHsob ataque14 ago 2023
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
71RISCO
abrir
GitHub PoC
This is a combination of the zerologon_tester.py code (https://raw.githubusercontent.com/SecuraBV/CVE-2020-1472/master/zerologon_tester.py) and the tool evil-winrm to get a shell.
CVE-2020-1472MEDIUMsob ataqueransomware14 ago 2023
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC2
CVE-2022-44268_By_Kyokito
CVE-2022-44268MEDIUM13 ago 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISCO
abrir
GitHub PoC1
A PoC exploit for CVE-2021-34621 - WordPress Privilege Escalation
CVE-2021-34621CRITICAL12 ago 2023
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RISCO
abrir
GitHub PoC1
CVE-2023-33246 POC
CVE-2023-33246CRITICALsob ataque11 ago 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISCO
abrir
GitHub PoC
CVE-2023-4174 PoC
CVE-2023-4174LOW11 ago 2023
mooSocial mooStore cross site scripting
43RISCO
abrir
GitHub PoC65
mandiant/citrix-ioc-scanner-cve-2023-3519
CVE-2023-3519CRITICALsob ataqueransomware10 ago 2023
Unauthenticated remote code execution
100RISCO
abrir
GitHub PoC
yosef0x01/CVE-2023-21752
CVE-2023-21752HIGH10 ago 2023
Windows Backup Service Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC3
Prestashop fix vulnerability CVE-2023-39526 & CVE-2023-39527
CVE-2023-39526CRITICAL10 ago 2023
PrestaShopSQL manager vulnerability (potential RCE)
48RISCO
abrir
GitHub PoC52
PoC for the recent critical vuln affecting OpenSSH versions < 9.3p2
CVE-2023-38408CRITICAL09 ago 2023
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISCO
abrir
GitHub PoC
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
CVE-2021-34621CRITICAL09 ago 2023
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RISCO
abrir
GitHub PoC
Original Exploit Source: https://www.exploit-db.com/exploits/46635
CVE-2019-905307 ago 2023
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC
Campcodes Online Matrimonial Website System 3.3 Cross Site Scripting
CVE-2023-3911507 ago 2023
install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG docum
23RISCO
abrir
GitHub PoC9
CVE exploitation for WebKit jsc CVE-2018-4416
CVE-2018-441607 ago 2023
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
35RISCO
abrir
GitHub PoC2
Running this exploit on a vulnerable system allows a local attacker to gain a root shell on the machine.
CVE-2023-22809HIGH06 ago 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir
GitHub PoC
MrE-Fog/jboss-_CVE-2017-12149
CVE-2017-12149CRITICALsob ataqueransomware06 ago 2023
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISCO
abrir
GitHub PoC1
rwincey/cve-2023-3519
CVE-2023-3519CRITICALsob ataqueransomware06 ago 2023
Unauthenticated remote code execution
100RISCO
abrir
GitHub PoC1
isacaya/CVE-2019-11358
CVE-2019-1135805 ago 2023
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RISCO
abrir
GitHub PoC1
passwa11/CVE-2023-3519
CVE-2023-3519CRITICALsob ataqueransomware05 ago 2023
Unauthenticated remote code execution
100RISCO
abrir
GitHub PoC3
This repo hosts TUKRU's Linux Privilege Escalation exploit (CVE-2021-22555). It demonstrates gaining root privileges via a vulnerability. Tested on Ubuntu 5.8.0-48-generic and COS 5.4.89+. Use responsibly and ethically.
CVE-2021-22555HIGHsob ataque05 ago 2023
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISCO
abrir
GitHub PoC2
Perform With Massive Authentication Bypass (Wordpress Mstore-API)
CVE-2023-2732CRITICAL05 ago 2023
MStore API <= 3.9.2 - Authentication Bypass
75RISCO
abrir
GitHub PoC1
Quick PoC checker for common configurations that might be available via directory traversal due to CVE-2013-3827
CVE-2013-382705 ago 2023
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2;
50RISCO
abrir
GitHub PoC2
Exim < 4.90.1 RCE Vulnerability remake for Python3 with arguments passed from CLI
CVE-2018-6789CRITICALsob ataqueransomware05 ago 2023
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISCO
abrir
GitHub PoC
Vulnerable environment of CVE-2013-2251 (S2-016) for testing
CVE-2013-2251CRITICALsob ataque04 ago 2023
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a
100RISCO
abrir
GitHub PoC2
CVE-2023-37979 PoC and Checker
CVE-2023-37979HIGH04 ago 2023
WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
61RISCO
abrir
GitHub PoC4
Remote Unauthenticated API Access Vulnerability in MobileIron Core 11.2 and older
CVE-2023-35082CRITICALsob ataqueransomware04 ago 2023
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted fu
100RISCO
abrir
GitHub PoC
Vulnerable environment of CVE-2020-17530 (S2-061) for testing
CVE-2020-17530CRITICALsob ataque04 ago 2023
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISCO
abrir
GitHub PoC
# Exploit Title: Pluck CMS 4.7.16 - Remote Code Execution (RCE) (Authenticated) # Date: 13.03.2022 # Exploit Author: Ashish Koli (Shikari) # Vendor Homepage: https://github.com/pluck-cms/pluck # Version: 4.7.16 # Tested on Ubuntu 20.04.3 LTS # CVE: CVE-2022-26965
CVE-2022-2696504 ago 2023
In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remot
35RISCO
abrir
GitHub PoC1
CVE-2020-0688 modified exploit for Exchange 2010
CVE-2020-0688HIGHsob ataqueransomware02 ago 2023
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC64
mistymntncop/CVE-2023-2033
CVE-2023-2033HIGHsob ataque02 ago 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RISCO
abrir
anteriorpágina 263 / 458próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.