Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
13.743 exploits
GitHub PoC25
CVE-2023-22621: SSTI to RCE by Exploiting Email Templates affecting Strapi Versions <=4.5.5
CVE-2023-22621CRITICAL25 abr 2023
Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitra
85RISCO
abrir
GitHub PoC112
Basic PoC for CVE-2023-27524: Insecure Default Configuration in Apache Superset
CVE-2023-27524HIGHsob ataque25 abr 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISCO
abrir
GitHub PoC9
Exploit for Papercut CVE-2023-27350. [+] Reverse shell [+] Mass checking
CVE-2023-27350CRITICALsob ataqueransomware25 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir
GitHub PoC1
Fix URL containing SPACES after Apache upgrade CVE-2023-25690
CVE-2023-25690CRITICAL25 abr 2023
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RISCO
abrir
GitHub PoC9
Perform With Mass Exploits In WSO Management.
CVE-2022-29464CRITICALsob ataqueransomware25 abr 2023
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir
GitHub PoC16
CVE-2023-1671-POC, based on dnslog platform
CVE-2023-1671CRITICALsob ataque24 abr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISCO
abrir
GitHub PoC13
CVE-2023-22894
CVE-2023-22894CRITICAL24 abr 2023
Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting
48RISCO
abrir
GitHub PoC
andyhsu024/CVE-2021-29447
CVE-2021-29447HIGH24 abr 2023
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir
GitHub PoC1
RubXkuB/PoC-Metabase-CVE-2021-41277
CVE-2021-41277CRITICALsob ataque24 abr 2023
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RISCO
abrir
GitHub PoC
msd0pe-1/CVE-2023-31747
CVE-2023-31747HIGH24 abr 2023
Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the comp
41RISCO
abrir
GitHub PoC1
glen-pearson/ProxyLogon-CVE-2021-26855
CVE-2021-26855CRITICALsob ataqueransomware23 abr 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC3
Pre-Auth RCE in Sophos Web Appliance
CVE-2023-1671CRITICALsob ataque23 abr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISCO
abrir
GitHub PoC1
Exploit for CVE-2022-1609 WordPress Weblizar Backdoor.
CVE-2022-1609CRITICAL22 abr 2023
The School Management < 9.9.7 - Unauthenticated RCE via REST api
75RISCO
abrir
GitHub PoC55
Proof of Concept Exploit for PaperCut CVE-2023-27350
CVE-2023-27350CRITICALsob ataqueransomware22 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir
GitHub PoC2
「💥」CVE-2022-4944: KodExplorer <= 4.49 - CSRF to Arbitrary File Upload
CVE-2022-4944MEDIUM21 abr 2023
kalcaddle KodExplorer cross-site request forgery
33RISCO
abrir
GitHub PoC5
A simple python script to check if a service is vulnerable
CVE-2023-27350CRITICALsob ataqueransomware21 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir
GitHub PoC12
imancybersecurity/CVE-2023-27350-POC
CVE-2023-27350CRITICALsob ataqueransomware21 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir
GitHub PoC
Anonimo501/ssh_enum_users_CVE-2018-15473
CVE-2018-15473MEDIUM21 abr 2023
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC14
CVE-2023-21823 PoC
CVE-2023-21823HIGHsob ataque20 abr 2023
Windows Graphics Component Remote Code Execution Vulnerability
71RISCO
abrir
GitHub PoC
A little demonstration of cve-2021-41773 on httpd docker containers
CVE-2021-41773HIGHsob ataqueransomware20 abr 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC10
veritas501/CVE-2023-0386
CVE-2023-0386HIGHsob ataque20 abr 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir
GitHub PoC
Dima2021/cve-2022-42889-text4shell
CVE-2022-4288918 abr 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC4
Reproduce CVE-2023-2033
CVE-2023-2033HIGHsob ataque17 abr 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RISCO
abrir
GitHub PoC4
randallbanner/Spring-Cloud-Function-Vulnerability-CVE-2022-22963-RCE
CVE-2022-22963CRITICALsob ataque17 abr 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
GitHub PoC1
msd0pe-1/CVE-2023-31714
CVE-2023-3171416 abr 2023
Chitor-CMS before v1.1.2 was discovered to contain multiple SQL injection vulnerabilities.
23RISCO
abrir
GitHub PoC8
POC : CVE-2023-21716 Microsoft Word RTF Font Table Heap Corruption
CVE-2023-21716CRITICAL16 abr 2023
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC
💣💥💀 Proof of Concept: пример запуска fork-бомбы на удаленном сервере благодаря уязвимости CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware15 abr 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC18
CVE-2023-21839 Python版本
CVE-2023-21839HIGHsob ataque15 abr 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISCO
abrir
GitHub PoC4
houqe/EXP_CVE-2018-19518
CVE-2018-1951815 abr 2023
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh c
60RISCO
abrir
GitHub PoC7
CVE-2022-38181 POC for FireTV 2nd gen Cube (raven)
CVE-2022-38181HIGHsob ataque13 abr 2023
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishan
76RISCO
abrir
anteriorpágina 275 / 459próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.