Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
13.743 exploits
GitHub PoC1
Patch for MS Outlook Critical Vulnerability - CVSS 9.8
CVE-2023-23397CRITICALsob ataque20 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC2
ahmedkhlief/CVE-2023-23397-POC-Using-Interop-Outlook
CVE-2023-23397CRITICALsob ataque19 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC1
Custom exploit written for enumerating usernames as per CVE-2016-6210
CVE-2016-6210MEDIUM19 mar 2023
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISCO
abrir
GitHub PoC73
POC for Veeam Backup and Replication CVE-2023-27532
CVE-2023-27532HIGHsob ataqueransomware18 mar 2023
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database
93RISCO
abrir
GitHub PoC24
CVE-2022-22963 is a vulnerability in the Spring Cloud Function Framework for Java that allows remote code execution. This python script will verify if the vulnerability exists, and if it does, will give you a reverse shell.
CVE-2022-22963CRITICALsob ataque18 mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
GitHub PoC1
This script exploits a vulnerability (CVE-2021-25094) in the TypeHub WordPress plugin.
CVE-2021-2509418 mar 2023
Tatsu < 3.3.12 - Unauthenticated RCE
60RISCO
abrir
GitHub PoC1
CVE-2023-23397 C# PoC
CVE-2023-23397CRITICALsob ataque18 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC9
djackreuter/CVE-2023-23397-PoC
CVE-2023-23397CRITICALsob ataque18 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC7
Generates meeting requests taking advantage of CVE-2023-23397. This requires the outlook thick client to send.
CVE-2023-23397CRITICALsob ataque17 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
h3x0v3rl0rd/CVE-2016-1531
CVE-2016-153117 mar 2023
Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.
38RISCO
abrir
GitHub PoC
CVE-2023-23397 Remediation Script (Powershell)
CVE-2023-23397CRITICALsob ataque17 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC6
Exploit POC for CVE-2023-23397
CVE-2023-23397CRITICALsob ataque17 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC3
CVE-2023-23397 - Microsoft Outlook Vulnerability
CVE-2023-23397CRITICALsob ataque16 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC4
Python script to create a message with the vulenrability properties set
CVE-2023-23397CRITICALsob ataque16 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC39
Simple PoC in PowerShell for CVE-2023-23397
CVE-2023-23397CRITICALsob ataque16 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC346
api0cradle/CVE-2023-23397-POC-Powershell
CVE-2023-23397CRITICALsob ataque16 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC7
FortiOS buffer overflow vulnerability
CVE-2022-42475CRITICALsob ataqueransomware16 mar 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISCO
abrir
GitHub PoC1
j0eyv/CVE-2023-23397
CVE-2023-23397CRITICALsob ataque16 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
Automate JWT Exploit (CVE-2018-0114)
CVE-2018-011416 mar 2023
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISCO
abrir
GitHub PoC2
Proof of concept exploit code for CVE-2020-7388, an unauthenticated RCE as SYSTEM on Sage X3's AdxDSrv Service
CVE-2020-7388CRITICAL15 mar 2023
Sage X3 AdxAdmin Unauthenticated Command Execution Bypass by Spoofing
85RISCO
abrir
GitHub PoC15
Windows Network File System Remote exploit for CVE-2022-30136
CVE-2022-30136CRITICAL15 mar 2023
Windows Network File System Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC159
Exploit for the CVE-2023-23397
CVE-2023-23397CRITICALsob ataque15 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
Batch scanning site.
CVE-2020-3187CRITICAL14 mar 2023
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RISCO
abrir
GitHub PoC3
An educational Proof of Concept for the Log4j Vulnerability (CVE-2021-44228) in Minecraft
CVE-2021-44228CRITICALsob ataqueransomware14 mar 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
Implementation of FOLLINA-CVE-2022-30190
CVE-2022-30190HIGHsob ataqueransomware14 mar 2023
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
Syd-SydneyJr/CVE-2021-45010
CVE-2021-4501013 mar 2023
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7
45RISCO
abrir
GitHub PoC4
CVE-2022-22963 RCE PoC in python
CVE-2022-22963CRITICALsob ataque13 mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
GitHub PoC4
A Tool for scanning CVE-2017-9841 with multithread
CVE-2017-9841CRITICALsob ataque13 mar 2023
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISCO
abrir
GitHub PoC1
Demonstrable Proof of Concept Exploit for Spring4Shell Vulnerability (CVE-2022-22965)
CVE-2022-22965CRITICALsob ataque12 mar 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC
python 2.7
CVE-2023-23752MEDIUMsob ataque11 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
anteriorpágina 279 / 459próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.