Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
13.743 exploits
GitHub PoC1
Exploring CVE-2021-42013, using Suricata and OpenVAS to gather info
CVE-2021-42013CRITICALsob ataqueransomware20 jun 2023
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC
overgrowncarrot1/CVE-2021-22911
CVE-2021-2291119 jun 2023
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISCO
abrir
GitHub PoC69
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
CVE-2023-27372CRITICAL19 jun 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir
GitHub PoC57
Openfire Console Authentication Bypass Vulnerability with RCE plugin
CVE-2023-32315HIGHsob ataque18 jun 2023
Openfire administration console authentication bypass
100RISCO
abrir
GitHub PoC1
CVE-2023-24078 for FuguHub / BarracudaDrive
CVE-2023-24078HIGH17 jun 2023
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the c
53RISCO
abrir
GitHub PoC7
CVE-2023-24078 for FuguHub / BarracudaDrive
CVE-2023-24078HIGH17 jun 2023
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the c
53RISCO
abrir
GitHub PoC23
FortiOS 管理界面中的堆内存下溢导致远程代码执行
CVE-2023-25610CRITICAL17 jun 2023
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0
53RISCO
abrir
GitHub PoC4
Joomla未授权访问漏洞
CVE-2023-23752MEDIUMsob ataque16 jun 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
GitHub PoC6
Repository with everything I have tracking the impact of MOVEit CVE-2023-34362
CVE-2023-34362CRITICALsob ataqueransomware16 jun 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISCO
abrir
GitHub PoC27
POC FortiOS SSL-VPN buffer overflow vulnerability
CVE-2023-27997CRITICALsob ataqueransomware16 jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISCO
abrir
GitHub PoC134
Safely detect whether a FortiGate SSL VPN instance is vulnerable to CVE-2023-27997 based on response timing
CVE-2023-27997CRITICALsob ataqueransomware16 jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISCO
abrir
GitHub PoC
CVE-2023-34600
CVE-2023-34600CRITICAL16 jun 2023
Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection.
53RISCO
abrir
GitHub PoC15
SolarView Compact through 6.00 downloader.php commands injection (RCE) nuclei-templates
CVE-2023-23333CRITICAL16 jun 2023
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RISCO
abrir
GitHub PoC1
overgrowncarrot1/CVE-2023-0297
CVE-2023-0297CRITICAL15 jun 2023
Code Injection in pyload/pyload
85RISCO
abrir
GitHub PoC2
5rGJ5aCh5oCq5YW9/CVE-2023-32315exp
CVE-2023-32315HIGHsob ataque15 jun 2023
Openfire administration console authentication bypass
100RISCO
abrir
GitHub PoC
Exploit for CVE-2022-44136 for chcking security of your site
CVE-2022-44136CRITICAL15 jun 2023
Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).
48RISCO
abrir
GitHub PoC
Samba 3.0.20
CVE-2007-244715 jun 2023
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC
ohnonoyesyes/CVE-2023-32315
CVE-2023-32315HIGHsob ataque14 jun 2023
Openfire administration console authentication bypass
100RISCO
abrir
GitHub PoC1
y0d3n/CVE-2014-0094
CVE-2014-009414 jun 2023
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via t
60RISCO
abrir
GitHub PoC6
VMWare vRealize Network Insight Pre-Authenticated RCE (CVE-2023-20887)
CVE-2023-20887CRITICALsob ataque14 jun 2023
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware
100RISCO
abrir
GitHub PoC140
rce
CVE-2023-32315HIGHsob ataque14 jun 2023
Openfire administration console authentication bypass
100RISCO
abrir
GitHub PoC2
python program to exploit CVE-2023-21716
CVE-2023-21716CRITICAL13 jun 2023
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC229
VMWare vRealize Network Insight Pre-Authenticated RCE (CVE-2023-20887)
CVE-2023-20887CRITICALsob ataque13 jun 2023
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware
100RISCO
abrir
GitHub PoC
Python 2.7
CVE-2023-27350CRITICALsob ataqueransomware13 jun 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir
GitHub PoC
Sonatype Nexus 3.21.01 - Remote Code Execution (Authenticated - Updated)
CVE-2020-10199HIGHsob ataque13 jun 2023
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISCO
abrir
GitHub PoC
Proof of Concept for vulnerability CVE-2023-2986 in 'Abandoned Cart Lite for WooCommerce' Plugin in WordPress in Python Version
CVE-2023-2986CRITICAL13 jun 2023
Abandoned Cart Lite for WooCommerce <= 5.15.1 - Authentication Bypass
60RISCO
abrir
GitHub PoC3
A script, written in golang. POC for CVE-2023-25157
CVE-2023-25157CRITICAL12 jun 2023
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISCO
abrir
GitHub PoC64
CVE-2023-34362: MOVEit Transfer Unauthenticated RCE
CVE-2023-34362CRITICALsob ataqueransomware12 jun 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISCO
abrir
GitHub PoC77
CVE-2023-20963 PoC (Android WorkSource parcel/unparcel logic mismatch)
CVE-2023-20963HIGHsob ataque12 jun 2023
In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional
71RISCO
abrir
GitHub PoC3
omoknooni/CVE-2021-21311
CVE-2021-21311HIGHsob ataque12 jun 2023
SSRF in adminer
100RISCO
abrir
anteriorpágina 269 / 459próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.