Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
13.743 exploits
GitHub PoC1
An exploitation of CVE-2022-30190 (Follina)
CVE-2022-30190HIGHsob ataqueransomware02 mai 2023
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
Este es un código del exploit CVE-2022-46169, que recree utilizando Python3! Si por ahí estás haciendo una máquina de HTB, esto te puede ser útil... 🤞✨
CVE-2022-46169CRITICALsob ataque02 mai 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC1
Improved PoC for Unauthenticated RCE on Cacti <= 1.2.22 - CVE-2022-46169
CVE-2022-46169CRITICALsob ataque02 mai 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC
Zoo1sondv/CVE-2021-3129
CVE-2021-3129CRITICALsob ataqueransomware01 mai 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC42
This is a exploit of CVE-2022-46169 to cacti 1.2.22. This exploit allows through an RCE to obtain a reverse shell on your computer.
CVE-2022-46169CRITICALsob ataque01 mai 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC3
Exploit for cacti version 1.2.22
CVE-2022-46169CRITICALsob ataque01 mai 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC
tuankiethkt020/Phat-hien-CVE-2017-8464
CVE-2017-8464HIGHsob ataque01 mai 2023
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RISCO
abrir
GitHub PoC1
zPrototype/CVE-2023-29809
CVE-2023-29809CRITICAL30 abr 2023
SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbit
53RISCO
abrir
GitHub PoC
gretchenfrage/CVE-2023-2033-analysis
CVE-2023-2033HIGHsob ataque30 abr 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RISCO
abrir
GitHub PoC2
Akash7350/CVE-2020-1472
CVE-2020-1472MEDIUMsob ataqueransomware30 abr 2023
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
Cisco r042 research
CVE-2023-20025CRITICAL30 abr 2023
A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 Routers co
48RISCO
abrir
GitHub PoC
CVE-2022-46169
CVE-2022-46169CRITICALsob ataque30 abr 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC
check cve-2022-0847
CVE-2022-0847HIGHsob ataque30 abr 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC
MrE-Fog/CVE-2014-0160-Chrome-Plugin
CVE-2014-0160HIGHsob ataque30 abr 2023
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
zPrototype/CVE-2023-29983
CVE-2023-29983MEDIUM29 abr 2023
Cross Site Scripting vulnerability found in Maximilian Vogt cmaps v.8.0 allows a remote attacker to execute arbitrary co
33RISCO
abrir
GitHub PoC
PoC for CVE-2022-46169 that affects Cacti 1.2.22 version
CVE-2022-46169CRITICALsob ataque29 abr 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC37
Cobalt Strike 4.4 猪猪版 去暗桩 去流量特征 beacon仿造真实API服务 修补CVE-2022-39197补丁
CVE-2022-39197MEDIUMsob ataque28 abr 2023
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISCO
abrir
GitHub PoC
This repository contains a python script that will handle the majority of the dompdf cached font exploit (CVE-2022-28368), all you need to do is create the request
CVE-2022-2836828 abr 2023
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (
60RISCO
abrir
GitHub PoC
CVE-2020-14882 rewritten in PowerShell
CVE-2020-14882CRITICALsob ataque28 abr 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC6
A Python PoC of CVE-2022-21661, inspired from z92g's Go PoC
CVE-2022-21661HIGH27 abr 2023
SQL injection in WordPress
78RISCO
abrir
GitHub PoC11
Apahce-Superset身份认证绕过漏洞(CVE-2023-27524)检测工具
CVE-2023-27524HIGHsob ataque27 abr 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISCO
abrir
GitHub PoC
PrestaShop <1.7.8.9 Fix for CVE-2023-30839 and CVE-2023-30545
CVE-2023-30839CRITICAL27 abr 2023
PrestaShop vulnerable to SQL filter bypass leading to arbitrary write requests using "SQL Manager"
48RISCO
abrir
GitHub PoC3
Apache Superset Auth Bypass Vulnerability CVE-2023-27524.
CVE-2023-27524HIGHsob ataque27 abr 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISCO
abrir
GitHub PoC
natceil/cve-2022-42475
CVE-2022-42475CRITICALsob ataqueransomware27 abr 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISCO
abrir
GitHub PoC19
A collection of resources and information about CVE-2023-2033
CVE-2023-2033HIGHsob ataque26 abr 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RISCO
abrir
GitHub PoC2
A simple exploit that uses dirtypipe to inject shellcode into runC entrypoint to implement container escapes.
CVE-2022-0847HIGHsob ataque26 abr 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC
ShyTangerine/cve-2021-26855
CVE-2021-26855CRITICALsob ataqueransomware25 abr 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
Check for CVE-2014-0160
CVE-2014-0160HIGHsob ataque25 abr 2023
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC9
Exploit for Papercut CVE-2023-27350. [+] Reverse shell [+] Mass checking
CVE-2023-27350CRITICALsob ataqueransomware25 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir
GitHub PoC
UnrealIRCd 3.2.8.1 backdoor command execution exploit in Python 3 (CVE-2010-2075).
CVE-2010-207525 abr 2023
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RISCO
abrir
anteriorpágina 274 / 459próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.