Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.662GitHub PoC 13.743VulnCheck XDB 8.460Nuclei 4.233Metasploit 3.467✓ só verificadosrecentespopularesrisco
13.743 exploits
GitHub PoC★ 275
CVE-2022-44268 ImageMagick Arbitrary File Read - Payload Generator
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISCO
abrir ↗GitHub PoC
Trinadh465/linux-4.1.15_CVE-2017-1000371
The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1
23RISCO
abrir ↗GitHub PoC★ 3
Microsoft Exchange CVE-2021-26855&CVE-2021-27065
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC
imbas007/Atlassian-Bitbucket-CVE-2022-36804
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir ↗GitHub PoC
Unauthenticated SQL Injection - Paid Memberships Pro < 2.9.8 (WordPress Plugin)
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit
85RISCO
abrir ↗GitHub PoC★ 1
Control Web Panel 7 (CWP7) Remote Code Execution (RCE) (CVE-2022-44877) (Unauthenticated)
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISCO
abrir ↗GitHub PoC★ 18
Cisco SmartInstall Exploit [CVE-2018-0171]
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthentica
100RISCO
abrir ↗GitHub PoC★ 1
paulotrindadec/CVE-2019-9193
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir ↗GitHub PoC★ 9
CVE-2023-23924 (Dompdf - RCE) PoC
URI validation failure on SVG parsing in Dompdf
48RISCO
abrir ↗GitHub PoC★ 6
Vulnerability CVE-2021-44228 allows remote code execution without authentication for several versions of Apache Log4j2 (Log4Shell). Attackers can exploit vulnerable servers by connecting over any protocol, such as HTTPS, and sending a specially crafted string.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC★ 17
mistymntncop/CVE-2022-26485
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of at
76RISCO
abrir ↗GitHub PoC★ 1
Proof of concept for CVE-2022-41220
md2roff 1.9 has a stack-based buffer overflow via a Markdown file, a different vulnerability than CVE-2022-34913. NOTE:
48RISCO
abrir ↗GitHub PoC★ 282
Adobe Acrobat Reader - CVE-2023-21608 - Remote Code Execution Exploit
Adobe Acrobat Reader DC resetForm Use-After-Free Remote Code Execution Vulnerability
83RISCO
abrir ↗GitHub PoC
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a default credential if the Telnet protocol is enabled Perform c CVE project by @Sn0wAlice
Cisco Catalyst PON Series Switches Optical Network Terminal Vulnerabilities
48RISCO
abrir ↗GitHub PoC★ 7
The official exploit for Froxlor Remote Code Execution CVE-2023-0315
Command Injection in froxlor/froxlor
78RISCO
abrir ↗GitHub PoC
windows 10 SMB vulnerability
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir ↗GitHub PoC
This is a vulnerability in the Linux kernel that was discovered and disclosed in 2017.
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RISCO
abrir ↗GitHub PoC
Joomla JCK Editor 6.4.4 - 'parent' SQL Injection
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
60RISCO
abrir ↗GitHub PoC
Exploit for CVE-2022-40684 vulnerability
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir ↗GitHub PoC
This script implements a lab automation where I exploit CVE-2021-43798 to steal user secrets and then gain privileges on a Linux system.
Grafana path traversal
100RISCO
abrir ↗GitHub PoC★ 2
In Paradox Security System IPR512 web panel, an unauthenticated user can input JavaScript string, such as </script> that will overwrite configurations in the file "login.xml" and cause the login form to crash and make it unavailable.
An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and l
53RISCO
abrir ↗GitHub PoC
vulnerabilities, CVE-2022-41903, and CVE-2022-23521, that affect versions 2.39 and older. Git for Windows was also patched to address an additional, Windows-specific issue known as CVE-2022-41953.
Integer overflow in `git archive`, `git log --format` leading to RCE in git
60RISCO
abrir ↗GitHub PoC★ 1
Relativ3Pa1n/CVE-2014-2383-LFI-to-RCE-Escalation
dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroo
50RISCO
abrir ↗GitHub PoC★ 2
DDoS Tool which exploits vulnerability CVE-2004-2449 from vendor GameSpy (now known as OpenSpy). User is prompted for input IP address, and port. (NOTE: Please use this responsibly, I made this as a proof of concept of vulnerability exploitation ONLY. I do not endorse DOSing, DDoSing, or cheating in any way. Use this at your own risk.)
Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier allows remote attackers to cause a denial
23RISCO
abrir ↗GitHub PoC★ 2
Drity Pipe Linux Kernel 1-Day Exploit
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir ↗GitHub PoC★ 1
A pwnkit N-Day exploit
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗GitHub PoC★ 6
A proof of concept exploit for a wordpress 5.6 media library vulnerability
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir ↗GitHub PoC★ 2
Run on your ManageEngine server
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISCO
abrir ↗GitHub PoC★ 7
The manage engine mass loader for CVE-2022-47966
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.