Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
13.743 exploits
GitHub PoC
spip
CVE-2023-27372CRITICAL01 jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir
GitHub PoC5
Exploitation of "Shellshock" Vulnerability. Remote code execution in Apache with mod_cgi
CVE-2014-6271CRITICALsob ataque01 jul 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC11
Decrypt reversible secrets encrypted using the default hardcoded key related to CVE-2020-9289 on FortiAnalyzer/FortiManager (the only difference with CVE-2019-6693 is the encryption routine).
CVE-2019-6693MEDIUMsob ataqueransomware30 jun 2023
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke
63RISCO
abrir
GitHub PoC9
WordPress社交登录和注册(Discord,Google,Twitter,LinkedIn)<=7.6.4-绕过身份验证
CVE-2023-2982CRITICAL30 jun 2023
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RISCO
abrir
GitHub PoC82
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
CVE-2023-2982CRITICAL29 jun 2023
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RISCO
abrir
GitHub PoC4
Using this tool, you can scan for remote command execution vulnerability CVE-2021-44228 on Apache Log4j at multiple addresses.
CVE-2021-44228CRITICALsob ataqueransomware29 jun 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
yangshifan-git/CVE-2021-1732
CVE-2021-1732HIGHsob ataqueransomware29 jun 2023
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC1
Hamesawian/CVE-2021-42013
CVE-2021-42013CRITICALsob ataqueransomware29 jun 2023
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC21
非常简单的CVE-2023-0386's exp and analysis.Use c and sh.
CVE-2023-0386HIGHsob ataque28 jun 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir
GitHub PoC179
fortra/CVE-2023-28252
CVE-2023-28252HIGHsob ataqueransomware27 jun 2023
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RISCO
abrir
GitHub PoC14
A Python script for generating exploits targeting CVE-2022-4510 RCE Binwalk. It supports SSH, command execution, and reverse shell options. Exploits are saved in PNG format. Ideal for testing and demonstrations.
CVE-2022-4510HIGH27 jun 2023
Path Traversal in binwalk
46RISCO
abrir
GitHub PoC13
This repository contains a Python script to automate the process of testing for a vulnerability known as Text4Shell, referenced under the CVE id: CVE-2022-42889.
CVE-2022-4288927 jun 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC
ps-interactive/lab_cve-2021-4034-polkit-emulation-and-detection
CVE-2021-4034HIGHsob ataque27 jun 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
An exploit for the Nibbles manager version 4.0.3. This exploit allows RCE to be performed.
CVE-2015-696726 jun 2023
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RISCO
abrir
GitHub PoC
manavvedawala/CVE-2023-32243-proof-of-concept
CVE-2023-32243CRITICAL26 jun 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISCO
abrir
GitHub PoC
pashayogi/CVE-2023-22809
CVE-2023-22809HIGH25 jun 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir
GitHub PoC2
Tools for working with ImageMagick to handle arbitrary file read vulnerabilities. Generate, read, and apply profile information to PNG files using a command-line interface.
CVE-2022-44268MEDIUM25 jun 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISCO
abrir
GitHub PoC8
SPIP Vulnerability Scanner - CVE-2023-27372 Detector
CVE-2023-27372CRITICAL25 jun 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir
GitHub PoC1
Based on the x.pl exploit/loader script for CVE-2009-1151
CVE-2009-1151CRITICALsob ataque24 jun 2023
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RISCO
abrir
GitHub PoC10
An exploit for CVE-2018-5955 GitStack 2.3.10 Unauthenticated RCE
CVE-2018-595523 jun 2023
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau
60RISCO
abrir
GitHub PoC
puckiestyle/cve-2023-27997
CVE-2023-27997CRITICALsob ataqueransomware23 jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISCO
abrir
GitHub PoC1
Windows Network File System Remote exploit (DoS) PoC
CVE-2022-30136CRITICAL23 jun 2023
Windows Network File System Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC1
imbas007/CVE-2023-27997-Check
CVE-2023-27997CRITICALsob ataqueransomware22 jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISCO
abrir
GitHub PoC34
An exploit for CVE-2022-42475, a pre-authentication heap overflow in Fortinet networking products
CVE-2022-42475CRITICALsob ataqueransomware21 jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISCO
abrir
GitHub PoC
sonpt-afk/CVE-2018-11776-FIS
CVE-2018-11776HIGHsob ataque21 jun 2023
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
GitHub PoC2
PoC and exploit for CVE-2022-22965 Spring4Shell
CVE-2022-22965CRITICALsob ataque20 jun 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC1
Exploring CVE-2021-42013, using Suricata and OpenVAS to gather info
CVE-2021-42013CRITICALsob ataqueransomware20 jun 2023
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC11
cfielding-r7/poc-cve-2023-2868
CVE-2023-2868CRITICALsob ataque20 jun 2023
Remote Code injection in Barracuda Email Security Gateway
100RISCO
abrir
GitHub PoC2
POC Exploit to add user to Sudo for CVE-2022-0847 Dirty Pipe Vulnerability
CVE-2022-0847HIGHsob ataque20 jun 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC19
Exploits for a heap overflow in MiniDLNA <=1.3.2 (CVE-2023-33476)
CVE-2023-33476CRITICAL20 jun 2023
ReadyMedia (MiniDLNA) versions from 1.1.15 up to 1.3.2 is vulnerable to Buffer Overflow. The vulnerability is caused by
48RISCO
abrir
anteriorpágina 268 / 459próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.