Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.000exploits catalogados
37.620CVEs com exploração pública
24.695testados em laboratório
15.498 exploits
GitHub PoC
sohamsharma966/Spring4Shell-CVE-2022-22965
CVE-2022-22965CRITICALsob ataque02 set 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC2
test-yaml
CVE-2021-34523CRITICALsob ataqueransomware02 set 2023
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
TheCyberWatchers/CVE-2017-0199-v5.0
CVE-2017-0199HIGHsob ataqueransomware02 set 2023
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir
GitHub PoC
samh4cks/CVE-2016-6210-OpenSSH-User-Enumeration
CVE-2016-6210MEDIUM01 set 2023
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISCO
abrir
GitHub PoC3
CVE-2023-38831 winrar exploit builder
CVE-2023-38831HIGHsob ataqueransomware01 set 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC97
VMWare Aria Operations for Networks (vRealize Network Insight) Static SSH key RCE (CVE-2023-34039)
CVE-2023-34039CRITICAL01 set 2023
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key g
75RISCO
abrir
GitHub PoC
niceeeeeeee/CVE-2021-22145-poc
CVE-2021-2214531 ago 2023
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the abil
60RISCO
abrir
GitHub PoC
Script for checking CVE-2023-3519 for Backdoors
CVE-2023-3519CRITICALsob ataqueransomware31 ago 2023
Unauthenticated remote code execution
100RISCO
abrir
GitHub PoC2
an exploit of POC for CVE-2023-34362 affecting MOVEit Transfer
CVE-2023-34362CRITICALsob ataqueransomware31 ago 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISCO
abrir
GitHub PoC2
PoC of CVE-2023-36281
CVE-2023-36281CRITICAL31 ago 2023
An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt. This
48RISCO
abrir
GitHub PoC3
Tool for CVE-2023-32315 exploitation
CVE-2023-32315HIGHsob ataque31 ago 2023
Openfire administration console authentication bypass
100RISCO
abrir
GitHub PoC24
PoC Script for CVE-2023-4596, unauthenticated Remote Command Execution through arbitrary file uploads.
CVE-2023-4596CRITICAL30 ago 2023
Forminator <= 1.24.6 - Unauthenticated Arbitrary File Upload
68RISCO
abrir
GitHub PoC
CVE-2022-46169
CVE-2022-46169CRITICALsob ataque30 ago 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC13
This is a POC for the CVE-2023-3883 exploit targeting WinRAR up to 6.22. Modified some existing internet-sourced POCs by introducing greater dynamism and incorporated additional try-except blocks within the code.
CVE-2023-38831HIGHsob ataqueransomware30 ago 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC1
Ben1B3astt/CVE-2023-38831_ReverseShell_Winrar
CVE-2023-38831HIGHsob ataqueransomware30 ago 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC
winrar exploit 6.22 <=
CVE-2023-38831HIGHsob ataqueransomware30 ago 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC
CVE-2023-27524
CVE-2023-27524HIGHsob ataque30 ago 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISCO
abrir
GitHub PoC6
Proof-of-Concept for CVE-2023-38831 Zero-Day vulnerability in WinRAR
CVE-2023-38831HIGHsob ataqueransomware30 ago 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC
winrar exploit 6.22 <=
CVE-2023-38831HIGHsob ataqueransomware30 ago 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC5
A Nuclei template to detect ZeroQlik (CVE-2023-41265 and CVE-2023-41266)
CVE-2023-41265CRITICALsob ataqueransomware30 ago 2023
An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and ear
100RISCO
abrir
GitHub PoC
Ivanti Endpoint Manager Mobile (EPMM) POC
CVE-2023-35078CRITICALsob ataqueransomware30 ago 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RISCO
abrir
GitHub PoC5
Remote Code Execution on Junos OS CVE-2023-36846
CVE-2023-36846MEDIUMsob ataque29 ago 2023
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
85RISCO
abrir
GitHub PoC13
Adapted CVE-2020-0041 root exploit for Pixel 3
CVE-2020-0041HIGHsob ataque29 ago 2023
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
71RISCO
abrir
GitHub PoC
This repository has both an attack detection tool and a Proof-of-Concept (PoC) Python script for the WinRAR CVE-2023-38831 vulnerability.
CVE-2023-38831HIGHsob ataqueransomware29 ago 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC
hanmin0512/CVE-2014-6271_pwnable
CVE-2014-6271CRITICALsob ataque29 ago 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC1
Proof of Concept (POC) for CVE-2023-38831 WinRAR
CVE-2023-38831HIGHsob ataqueransomware29 ago 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC11
CVE-2023-38831 winrar exploit generator and get reverse shell
CVE-2023-38831HIGHsob ataqueransomware28 ago 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC3
CVE-2023-38831 WinRAR
CVE-2023-38831HIGHsob ataqueransomware28 ago 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC6
CloudPanel 2 Remote Code Execution Exploit
CVE-2023-35885CRITICAL28 ago 2023
CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
85RISCO
abrir
GitHub PoC4
KQL Hunting for WinRAR CVE-2023-38831
CVE-2023-38831HIGHsob ataqueransomware28 ago 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
anteriorpágina 313 / 517próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.