Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
13.743 exploits
GitHub PoC
This little script encrypts password to gpp cpassword. It useful to create vulnerable lab AD (CVE-2014-1812).
CVE-2014-1812HIGHsob ataqueransomware22 mai 2023
The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windo
98RISCO
abrir
GitHub PoC1
vsftpd 2.0.5 - 'CWD' (Authenticated) Remote Memory Consumption
CVE-2007-596222 mai 2023
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 throug
28RISCO
abrir
GitHub PoC
RCE Unauth in PyLoad <0.5.0b3.dev31
CVE-2023-0297CRITICAL21 mai 2023
Code Injection in pyload/pyload
85RISCO
abrir
GitHub PoC
antisecc/CVE-2022-46169
CVE-2022-46169CRITICALsob ataque21 mai 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC
antisecc/CVE-2022-24716
CVE-2022-24716HIGH20 mai 2023
Path traversal in Icinga Web 2
78RISCO
abrir
GitHub PoC
Proof of Concept about a XSS Stored in SCM Manager 1.2 <= 1.60
CVE-2023-33829MEDIUM19 mai 2023
A stored cross-site scripting (XSS) vulnerability in Cloudogu GmbH SCM Manager v1.2 to v1.60 allows attackers to execute
33RISCO
abrir
GitHub PoC1
Golang implementation of ThinVNC exploit CVE-2019-17662. For educational purposes only.
CVE-2019-1766219 mai 2023
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RISCO
abrir
GitHub PoC
xiaosed/CVE-2023-29919
CVE-2023-29919CRITICAL19 mai 2023
SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because t
75RISCO
abrir
GitHub PoC59
CVE-2023-21554 Windows MessageQueuing PoC,分析见 https://www.zoemurmure.top/posts/cve_2023_21554/
CVE-2023-21554CRITICAL18 mai 2023
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
85RISCO
abrir
GitHub PoC24
PoC for CVE-2023-20126
CVE-2023-20126CRITICAL17 mai 2023
Cisco SPA112 2-Port Phone Adapters Remote Command Execution Vulnerability
60RISCO
abrir
GitHub PoC
Exploit to cve-2023-1671. So there is a test and exploitation function. The test sends a ping request to the dnslog domain from the vulnerable site. If the ping passes, the vulnerability exists, if it doesn't, then cve-2023-1671 is missing. The exploit function, on the other hand, sends a request with your command to the server.
CVE-2023-1671CRITICALsob ataque17 mai 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISCO
abrir
GitHub PoC4
A reflected Cross-Site Scripting (XSS) vulnerability exists in the Edit User functionality of the Microworld Technologies eScan Management Console (version 14.0.1400.2281).
CVE-2023-31703CRITICAL17 mai 2023
Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allo
48RISCO
abrir
GitHub PoC2
CVE-2023-31702 is an authenticated SQL Injection vulnerability discovered in MicroWorld Technologies eScan Management Console version 14.0.1400.2281.
CVE-2023-31702HIGH17 mai 2023
SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to d
41RISCO
abrir
GitHub PoC51
Vulnerabilities Exploitation On Ubuntu 22.04
CVE-2023-0386HIGHsob ataque16 mai 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir
GitHub PoC11
POC for the CVE-2022-36944 vulnerability exploit
CVE-2022-36944CRITICAL16 mai 2023
Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There i
48RISCO
abrir
GitHub PoC8
Abusing CVE-2023-28206 to make something useful
CVE-2023-28206HIGHsob ataque15 mai 2023
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5,
76RISCO
abrir
GitHub PoC84
CVE-2023-32243 - Essential Addons for Elementor 5.4.0-5.7.1 - Unauthenticated Privilege Escalation
CVE-2023-32243CRITICAL15 mai 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISCO
abrir
GitHub PoC
school project
CVE-2019-15107CRITICALsob ataqueransomware15 mai 2023
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC1
Exploit script for CVE-2022-41544 - RCE in get-simple CMS
CVE-2022-41544HIGH15 mai 2023
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file paramete
41RISCO
abrir
GitHub PoC3
Exploit for CVE-2023-32243 - Unauthorized Account Takeover.
CVE-2023-32243CRITICAL14 mai 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISCO
abrir
GitHub PoC12
Follina (CVE-2022-30190) is a Microsoft Office zero-day vulnerability that has recently been discovered. It’s a high-severity vulnerability that hackers can leverage for remote code execution (RCE) attacks.
CVE-2022-30190HIGHsob ataqueransomware14 mai 2023
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC4
Akash7350/CVE-2021-22204
CVE-2021-22204MEDIUMsob ataque14 mai 2023
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISCO
abrir
GitHub PoC6
Exploits for Tenda Ac8v4 stack-based overflow to Remote-Code Execution via Mipsel Ropping (CVE-2023-33669 - CVE-2023-33675)
CVE-2023-33669CRITICAL13 mai 2023
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the timeZone parameter in the sub_44db3c funct
48RISCO
abrir
GitHub PoC
raiden757/CVE-2020-17087
CVE-2020-17087HIGHsob ataque13 mai 2023
Windows Kernel Local Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC7
Exploit for Ubuntu 20.04 using CVE-2021-3156 enhanced with post-exploitation scripts
CVE-2021-3156HIGHsob ataque13 mai 2023
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC1
poc
CVE-2023-32243CRITICAL13 mai 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISCO
abrir
GitHub PoC
A simple PoC for CVE-2022-46169 a.k.a Cacti Unauthenticated Command Injection, a vulnerability allows an unauthenticated user to execute arbitrary code on a server running Cacti prior from version 1.2.17 to 1.2.22
CVE-2022-46169CRITICALsob ataque12 mai 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC1
Exploit for grafana CVE-2021-43798
CVE-2021-43798HIGHsob ataque12 mai 2023
Grafana path traversal
100RISCO
abrir
GitHub PoC3
R0rt1z2/CVE-2022-38181
CVE-2022-38181HIGHsob ataque12 mai 2023
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishan
76RISCO
abrir
GitHub PoC
Baron SameEdit Heap Overflow LPE 1-Day Exploit
CVE-2021-3156HIGHsob ataque11 mai 2023
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
anteriorpágina 272 / 459próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.