Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
13.743 exploits
GitHub PoC1
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin
CVE-2022-044102 jun 2023
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
60RISCO
abrir
GitHub PoC3
CVE-2023-33246:Apache RocketMQ 远程命令执行漏洞检测工具
CVE-2023-33246CRITICALsob ataque02 jun 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISCO
abrir
GitHub PoC114
Apache RocketMQ 远程代码执行漏洞(CVE-2023-33246) Exploit
CVE-2023-33246CRITICALsob ataque01 jun 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISCO
abrir
GitHub PoC81
Apache RocketMQ 远程代码执行漏洞(CVE-2023-33246) Exploit
CVE-2023-33246CRITICALsob ataque01 jun 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISCO
abrir
GitHub PoC
[CVE-2021-33690] Server Side Request Forgery vulnerability in SAP NetWeaver Development Infrastructure
CVE-2021-33690CRITICAL01 jun 2023
Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Compo
75RISCO
abrir
GitHub PoC1
Exploit for CVE:2010-2075. This exploit allows remote command execution in UnrealIRCd 3.2.8.1.
CVE-2010-207531 mai 2023
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RISCO
abrir
GitHub PoC2
4mazing/CVE-2023-33246-Copy
CVE-2023-33246CRITICALsob ataque31 mai 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISCO
abrir
GitHub PoC2
A simple python script for a firewall rule that blocks incoming requests based on the Spring4Shell (CVE-2022-22965) vulnerability
CVE-2022-22965CRITICALsob ataque31 mai 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC1
eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's password in plain text.
CVE-2023-33730CRITICAL30 mai 2023
Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2
48RISCO
abrir
GitHub PoC62
I5N0rth/CVE-2023-33246
CVE-2023-33246CRITICALsob ataque30 mai 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISCO
abrir
GitHub PoC
the proof of concept written in Python for an unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups. This is a critical severity issue
CVE-2023-2825CRITICAL30 mai 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RISCO
abrir
GitHub PoC
kw3h4/CVE-2023-21839-metasploit-scanner
CVE-2023-21839HIGHsob ataque29 mai 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISCO
abrir
GitHub PoC6
WindowsProtocolTestSuites is to trigger BSoD, and full exploit poc.
CVE-2020-0796CRITICALsob ataqueransomware29 mai 2023
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC8
The exploit is edited to work with different text encodings and Python 3 and is compatible with CMSMS version 2.2.9 and below.
CVE-2019-905329 mai 2023
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC2
Identifies domains which run WordPress and tests against vulnerabilities (CVE-2023-32243) / #VU76395 / etc...
CVE-2023-32243CRITICAL29 mai 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISCO
abrir
GitHub PoC1
MinIO Information Disclosure Vulnerability scanner by metasploit
CVE-2023-28432HIGHsob ataque27 mai 2023
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir
GitHub PoC2
Exploit for Bad Binder
CVE-2019-2215HIGHsob ataque27 mai 2023
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
GitHub PoC2
Perfom With Massive Authentication Bypass In PaperCut MF/NG
CVE-2023-27350CRITICALsob ataqueransomware27 mai 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir
GitHub PoC1
PoC for login with password hash in STARFACE
CVE-2023-33243HIGH26 mai 2023
RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the
41RISCO
abrir
GitHub PoC2
Spring Cloud Gateway Actuator API SpEL表达式注入命令执行Exp
CVE-2022-22947CRITICALsob ataque26 mai 2023
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC6
MStore API <= 3.9.2 - Authentication Bypass
CVE-2023-2732CRITICAL25 mai 2023
MStore API <= 3.9.2 - Authentication Bypass
75RISCO
abrir
GitHub PoC
Exploit for CVE-2022-22963 remote command execution in Spring Cloud Function
CVE-2022-22963CRITICALsob ataque25 mai 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
GitHub PoC140
GitLab CVE-2023-2825 PoC. This PoC leverages a path traversal vulnerability to retrieve the /etc/passwd file from a system running GitLab 16.0.0.
CVE-2023-2825CRITICAL25 mai 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RISCO
abrir
GitHub PoC7
Camaleon CMS v2.7.0 contain a Server-Side Template Injection (SSTI) vulnerability
CVE-2023-30145CRITICAL25 mai 2023
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats para
60RISCO
abrir
GitHub PoC
Vulnerable docker to test for: CVE-2023-32243
CVE-2023-32243CRITICAL24 mai 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISCO
abrir
GitHub PoC
manavvedawala2/CVE-2023-32243-POC
CVE-2023-32243CRITICAL23 mai 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISCO
abrir
GitHub PoC
manavvedawala2/CVE-2023-32243-proof-of-concept
CVE-2023-32243CRITICAL23 mai 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISCO
abrir
GitHub PoC30
PoC for CVE-2023-28771 based on Rapid7's excellent writeup
CVE-2023-28771CRITICALsob ataque23 mai 2023
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware vers
100RISCO
abrir
GitHub PoC286
CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling vulnerability.
CVE-2023-25690CRITICAL22 mai 2023
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RISCO
abrir
GitHub PoC1
vsftpd 2.0.5 - 'CWD' (Authenticated) Remote Memory Consumption
CVE-2007-596222 mai 2023
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 throug
28RISCO
abrir
anteriorpágina 271 / 459próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.