Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
13.743 exploits
GitHub PoC
andyhsu024/CVE-2022-45025
CVE-2022-45025CRITICAL11 jun 2023
Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerabi
60RISCO
abrir
GitHub PoC14
GeoServer & GeoTools SQL Injection (CVE-2023-25157 & CVE-2023-25158)
CVE-2023-25157CRITICAL11 jun 2023
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISCO
abrir
GitHub PoC1
lukinneberg/CVE-2023-2636
CVE-2023-263611 jun 2023
AN_GradeBook <= 5.0.1 - Subscriber+ SQLi
23RISCO
abrir
GitHub PoC10
0x2458bughunt/CVE-2023-25157
CVE-2023-25157CRITICAL10 jun 2023
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISCO
abrir
GitHub PoC2
DreamD2v/CVE-2023-31541
CVE-2023-31541CRITICAL10 jun 2023
A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3
48RISCO
abrir
GitHub PoC
antisecc/CVE-2018-16763
CVE-2018-1676309 jun 2023
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
GitHub PoC1
Thruk Monitoring Web Interface <= 3.06 vulnerable to CVE-2023-34096 (Path Traversal).
CVE-2023-34096MEDIUM09 jun 2023
Thruk has Path Traversal Vulnerability in panorama.pm
45RISCO
abrir
GitHub PoC21
m-cetin/CVE-2023-29336
CVE-2023-29336HIGHsob ataque09 jun 2023
Win32k Elevation of Privilege Vulnerability
83RISCO
abrir
GitHub PoC138
MOVEit CVE-2023-34362
CVE-2023-34362CRITICALsob ataqueransomware09 jun 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISCO
abrir
GitHub PoC6
Proof of Concept for vulnerability CVE-2023-2986 in 'Abandoned Cart Lite for WooCommerce' Plugin in WordPress
CVE-2023-2986CRITICAL09 jun 2023
Abandoned Cart Lite for WooCommerce <= 5.15.1 - Authentication Bypass
60RISCO
abrir
GitHub PoC
axelbankole/CVE-2012-1495-Webcalendar-
CVE-2012-149508 jun 2023
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user
60RISCO
abrir
GitHub PoC1
This is a reproduction of PHP Laravel 8.70.1 - Cross Site Scripting (XSS) to Cross Site Request Forgery (CSRF) vulnerability
CVE-2021-4361708 jun 2023
Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Val
28RISCO
abrir
GitHub PoC1
CVE: 2021-42013 Tested on: 2.4.49 and 2.4.50 Description: Path Traversal or Remote Code Execution vulnerabilities in Apache 2.4.49 and 2.4.50
CVE-2021-42013CRITICALsob ataqueransomware08 jun 2023
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC56
Cloudpanel 0-day Exploit
CVE-2023-35885CRITICAL08 jun 2023
CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
85RISCO
abrir
GitHub PoC
hello4r1end/patch_CVE-2023-22809
CVE-2023-22809HIGH08 jun 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir
GitHub PoC3
SCM Manager XSS
CVE-2023-33829MEDIUM07 jun 2023
A stored cross-site scripting (XSS) vulnerability in Cloudogu GmbH SCM Manager v1.2 to v1.60 allows attackers to execute
33RISCO
abrir
GitHub PoC
Spring rce environment for CVE-2022-22965
CVE-2022-22965CRITICALsob ataque07 jun 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC1
Paid Memberships Pro v2.9.8 (WordPress Plugin) - Unauthenticated SQL Injection
CVE-2023-23488CRITICAL07 jun 2023
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit
85RISCO
abrir
GitHub PoC22
CVE-2022-39227 : Proof of Concept
CVE-2022-39227CRITICAL07 jun 2023
Python-jwt subject to Authentication Bypass by Spoofing
48RISCO
abrir
GitHub PoC170
CVE-2023-25157 - GeoServer SQL Injection - PoC
CVE-2023-25157CRITICAL06 jun 2023
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISCO
abrir
GitHub PoC
Python 2.7
CVE-2023-2732CRITICAL06 jun 2023
MStore API <= 3.9.2 - Authentication Bypass
75RISCO
abrir
GitHub PoC2
CVE-2023-34362-IOCs. More information on Deep Instinct's blog site.
CVE-2023-34362CRITICALsob ataqueransomware06 jun 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISCO
abrir
GitHub PoC
On May 23, 2023 GitLab released version 16.0.1 which fixed a critical vulnerability, CVE-2023-2825, affecting the Community Edition (CE) and Enterprise Edition (EE) version 16.0.0. The vulnerability allows unauthenticated users to read arbitrary files through a path traversal bug.
CVE-2023-2825CRITICAL05 jun 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RISCO
abrir
GitHub PoC
Proof of concept / CTF script for exploiting CVE-2022-46169 in Cacti, versions >=1.2.22
CVE-2022-46169CRITICALsob ataque05 jun 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC
MrDottt/CVE-2021-22911
CVE-2021-2291105 jun 2023
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISCO
abrir
GitHub PoC4
hoangprod/CVE-2021-31956-POC
CVE-2021-31956HIGHsob ataque05 jun 2023
Windows NTFS Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC
Base64-based encryption oracle exploit for CVE-2017-9248 (Telerik UI for ASP.NET AJAX dialog handler)
CVE-2017-9248CRITICALsob ataque05 jun 2023
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RISCO
abrir
GitHub PoC
hqdat809/CVE-2021-40444
CVE-2021-40444HIGHsob ataqueransomware05 jun 2023
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC3
Poc&Exp,支持批量扫描,反弹shell
CVE-2022-22965CRITICALsob ataque03 jun 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC
Exploit created in python3 to exploit known vulnerabilities in Apache web server (CVE-2021-41773, CVE-2021-42013)
CVE-2021-41773HIGHsob ataqueransomware03 jun 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
anteriorpágina 270 / 459próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.