Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.979exploits catalogados
37.614CVEs com exploração pública
24.695testados em laboratório
15.486 exploits
GitHub PoC5
WAGO Remote Exploit Tool for CVE-2023-1698
CVE-2023-1698CRITICAL15 set 2023
WAGO: WBM Command Injection in multiple products
85RISCO
abrir
GitHub PoC8
Automatic Mass Tool for checking vulnerability in CVE-2022-4060 - WordPress Plugin : User Post Gallery <= 2.19 - Unauthenticated RCE
CVE-2022-4060CRITICAL15 set 2023
User Post Gallery <= 2.19 - Unauthenticated RCE
75RISCO
abrir
GitHub PoC
Anthony1500/CVE-2022-40684
CVE-2022-40684CRITICALsob ataqueransomware14 set 2023
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir
GitHub PoC
CVE-2018-1000861 Exploit
CVE-2018-1000861CRITICALsob ataque13 set 2023
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea
100RISCO
abrir
GitHub PoC1
CVE-2023-43481
CVE-2023-43481CRITICAL13 set 2023
An issue in Shenzhen TCL Browser TV Web BrowseHere (aka com.tcl.browser) 6.65.022_dab24cc6_231221_gp allows a remote att
48RISCO
abrir
GitHub PoC9
CVE-2023-38831 WinRaR Exploit Generator
CVE-2023-38831HIGHsob ataqueransomware12 set 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC3
Proof of concept (PoC) exploit for WinRAR vulnerability (CVE-2023-38831) vulnerability
CVE-2023-38831HIGHsob ataqueransomware12 set 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC1
Python3 exploit for Fuel CMS 1.4.1 Remote Code Execution (CVE-2018-16763) with Reverse Shell.
CVE-2018-1676311 set 2023
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
GitHub PoC
Development of an exploit for privilege escalation in Windows systems ( NT / 2k / XP / 2K3 / VISTA / 2k8 / 7 ) using the vulnerability CVE-2010-0232
CVE-2010-0232HIGHsob ataque11 set 2023
The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Se
91RISCO
abrir
GitHub PoC2
Automatic Mass Tool for checking vulnerability in CVE-2023-0159 - Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated LFI
CVE-2023-015911 set 2023
Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE
50RISCO
abrir
GitHub PoC
ช่องโหว่ CVE-2023-35674 *สถานะ: ยังไม่เสร็จ*
CVE-2023-35674HIGHsob ataque11 set 2023
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the cod
71RISCO
abrir
GitHub PoC2
Automatic Mass Tool for checking vulnerability in CVE-2022-4063 - InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
CVE-2022-4063CRITICAL11 set 2023
InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
63RISCO
abrir
GitHub PoC
davidholiday/CVE-2007-4559
CVE-2007-4559CRITICAL10 set 2023
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows
53RISCO
abrir
GitHub PoC
0xZon/CVE-2022-46169-Exploit
CVE-2022-46169CRITICALsob ataque10 set 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC
caopengyan/CVE-2023-2825
CVE-2023-2825CRITICAL10 set 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RISCO
abrir
GitHub PoC
RCE PoC for Apache Commons Text vuln
CVE-2022-4288909 set 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC
simulation experiment of Curveball (CVE-2020-0601) attacks under ECQV implicit certificates with Windows-like verifiers
CVE-2020-0601HIGHsob ataque09 set 2023
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
GitHub PoC28
jakabakos/CVE-2023-27524-Apache-Superset-Auth-Bypass-and-RCE
CVE-2023-27524HIGHsob ataque08 set 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISCO
abrir
GitHub PoC
Hikikan/CVE-2021-22205
CVE-2021-22205CRITICALsob ataqueransomware08 set 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir
GitHub PoC9
A PoC exploit for CVE-2017-8225 - GoAhead System.ini Leak
CVE-2017-822508 set 2023
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An
43RISCO
abrir
GitHub PoC
Quick exploit builder for CVE-2023-38831, a vulnerability that affects WinRAR versions before 6.23.
CVE-2023-38831HIGHsob ataqueransomware07 set 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC2
SUPRAAA-1337/CVE-2021-20021
CVE-2021-20021CRITICALsob ataqueransomware07 set 2023
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account
100RISCO
abrir
GitHub PoC7
An exploit for OpenTSDB <= 2.4.1 cmd injection (CVE-2023-36812/CVE-2023-25826) written in Fortran
CVE-2023-36812CRITICAL07 set 2023
Remote Code Execution in OpenTSDB
68RISCO
abrir
GitHub PoC
This is a PoC for CVE-2023-27372 and spawns a fully interactive shell.
CVE-2023-27372CRITICAL07 set 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir
GitHub PoC
Text4Shell
CVE-2022-4288906 set 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC1
Script to exploit CVE-2023-38035
CVE-2023-38035CRITICALsob ataqueransomware05 set 2023
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an
100RISCO
abrir
GitHub PoC
Generate Seralize Payload for CVE-2019-0604 for Sharepoint 2010 SP2 .net 3.5
CVE-2019-0604CRITICALsob ataqueransomware05 set 2023
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RISCO
abrir
GitHub PoC
Ijinleife/CVE-2019-14287
CVE-2019-1428705 set 2023
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
GitHub PoC
asepsaepdin/CVE-2021-3156
CVE-2021-3156HIGHsob ataque05 set 2023
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC
A bash script for easyly exploiting ImageMagick Arbitrary File Read Vulnerability CVE-2022-44268
CVE-2022-44268MEDIUM05 set 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISCO
abrir
anteriorpágina 311 / 517próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.