Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.753exploits catalogados
37.445CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 23.871GitHub PoC 15.407VulnCheck XDB 9.065Nuclei 4.426Metasploit 3.502✓ só verificadosrecentespopularesrisco
15.407 exploits
GitHub PoC
Modified RCE with a remote shell and logging
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISCO
abrir ↗GitHub PoC
scirusvulgaris/CVE-2017-12617
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISCO
abrir ↗GitHub PoC★ 1
CocoaPods RCE Vulnerability CVE-2024-38366
CoacoaPods trunk RCE in email verification system rfc-822
53RISCO
abrir ↗GitHub PoC
CVE-2024-4040 PoC
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir ↗GitHub PoC★ 8
🆘New Windows Kernel Priviledge Escalation Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
83RISCO
abrir ↗GitHub PoC★ 95
A Pwn2Own 2024 SpiderMonkey JIT Bug: From Integer Range Inconsistency to Bound Check Elimination then RCE
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds chec
53RISCO
abrir ↗GitHub PoC
ArturArz1/TestCVE-2024-34102
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir ↗GitHub PoC★ 14
CVE-2024-34102: Unauthenticated Magento XXE
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir ↗GitHub PoC★ 31
POC for CVE-2024-34102. A pre-authentication XML entity injection issue in Magento / Adobe Commerce.
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir ↗GitHub PoC
This is a simple proof of concept for CVE-2023-49103.
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies
100RISCO
abrir ↗GitHub PoC★ 1
Exploit for CVE-2024-28995 affecting SolarWinds Serv-U 15.4.2 HF 1 and previous versions
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISCO
abrir ↗GitHub PoC★ 1
Exploit for CVE-2024-28995 affecting SolarWinds Serv-U 15.4.2 HF 1 and previous versions
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISCO
abrir ↗GitHub PoC★ 1
The script has been remastered by Teymur Novruzov to ensure compatibility with Python 3. This tool is intended for educational purposes only. Unauthorized use of this tool on any system or network without permission is illegal. The author is not responsible for any misuse of this tool.
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir ↗GitHub PoC
CVE-2024-6028 Quiz Maker <= 6.5.8.3 - Unauthenticated SQL Injection via 'ays_questions' Parameter
Quiz Maker <= 6.5.8.3 - Unauthenticated SQL Injection via 'ays_questions' Parameter
68RISCO
abrir ↗GitHub PoC
zerobytesecure/CVE-2019-19781
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir ↗GitHub PoC
Hirusha-N/CVE-2021-34527-CVE-2023-38831-and-CVE-2023-32784
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir ↗GitHub PoC
Hirusha-N/CVE-2021-34527-CVE-2023-38831-and-CVE-2023-32784
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 290
tykawaii98/CVE-2024-30088
Windows Kernel Elevation of Privilege Vulnerability
83RISCO
abrir ↗GitHub PoC★ 1
Proof of concept of CVE-2024-29868 affecting Apache StreamPipes from 0.69.0 through 0.93.0
Apache StreamPipes, Apache StreamPipes: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Recovery Token Generation
63RISCO
abrir ↗GitHub PoC
CVE-2018-9995
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir ↗GitHub PoC★ 45
Exploit for the CVE-2024-5806
MOVEit Transfer Authentication Bypass Vulnerability
85RISCO
abrir ↗GitHub PoC★ 1
This is an Incident Response Walkthrough: Mitigating a Zero-Day Attack (CVE-2024-4577)
Argument Injection in PHP-CGI
100RISCO
abrir ↗GitHub PoC★ 40
tykawaii98/CVE-2024-21338_PoC
Windows Kernel Elevation of Privilege Vulnerability
83RISCO
abrir ↗GitHub PoC
PoC and analysis for Kibana Prototype Pollution RCE (CVE-2019-7609).
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISCO
abrir ↗GitHub PoC★ 2
☣️ This repository contains the description and a proof of concept for CVE-2024-34313
An issue in VPL Jail System up to v4.0.2 allows attackers to execute a directory traversal via a crafted request to a pu
48RISCO
abrir ↗GitHub PoC
CVE-2023-23397: Remote Code Execution Vulnerability in Microsoft Outlook
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.