Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.003exploits catalogados
37.620CVEs com exploração pública
24.695testados em laboratório
15.501 exploits
GitHub PoC1
lakshit1212/CVE-2021-23017-PoC
CVE-2021-2301720 jul 2023
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RISCO
abrir
GitHub PoC2
A PoC exploit for CVE-2015-2166 - Directory Traversal Vulnerability in Ericsson Drutt Mobile Service Delivery Platform (MSDP)
CVE-2015-216620 jul 2023
Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5
43RISCO
abrir
GitHub PoC
passwa11/CVE-2023-29017-reverse-shell
CVE-2023-29017CRITICAL20 jul 2023
vm2 Sandbox Escape vulnerability
60RISCO
abrir
GitHub PoC
PowerShell Script for initial mitigation of vulnerability
CVE-2023-36884HIGHsob ataqueransomware20 jul 2023
Windows Search Remote Code Execution Vulnerability
93RISCO
abrir
GitHub PoC
Muhammad-Ali007/Log4j_CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware19 jul 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
CVE-2023-36884 临时补丁
CVE-2023-36884HIGHsob ataqueransomware18 jul 2023
Windows Search Remote Code Execution Vulnerability
93RISCO
abrir
GitHub PoC1
This shellscript given the OrgKey 0 will parse the header of the base64 artifacts found in MOVEit Logs and decrypt the Serialized object used a payload
CVE-2023-34362CRITICALsob ataqueransomware18 jul 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISCO
abrir
GitHub PoC15
Script to check for CVE-2023-36884 hardening
CVE-2023-36884HIGHsob ataqueransomware17 jul 2023
Windows Search Remote Code Execution Vulnerability
93RISCO
abrir
GitHub PoC1
Muhammad-Ali007/Follina_MSDT_CVE-2022-30190
CVE-2022-30190HIGHsob ataqueransomware17 jul 2023
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
d0x-awrqxavc/CVE-2019-7609-KibanaRCE
CVE-2019-7609CRITICALsob ataque17 jul 2023
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISCO
abrir
GitHub PoC2
This script allows for remote code execution (RCE) on Oracle WebLogic Server
CVE-2020-14882CRITICALsob ataque17 jul 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC6
Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints
CVE-2023-32117CRITICAL17 jul 2023
WordPress Integrate Google Drive plugin <= 1.1.99 - Unauthenticated Broken Access Control vulnerability
63RISCO
abrir
GitHub PoC2
Automating Exploitation of CVE-2022-44268 ImageMagick Arbitrary File Read
CVE-2022-44268MEDIUM17 jul 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISCO
abrir
GitHub PoC4
NyaMeeEain/CVE-2022-28171-POC
CVE-2022-28171HIGH16 jul 2023
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to t
53RISCO
abrir
GitHub PoC
Fuel CMS 1.4.1 - Remote Code Execution - Python 3.x
CVE-2018-1676316 jul 2023
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
GitHub PoC2
This is an emergency solution while Microsoft addresses the vulnerability.
CVE-2023-36884HIGHsob ataqueransomware15 jul 2023
Windows Search Remote Code Execution Vulnerability
93RISCO
abrir
GitHub PoC46
Apache RocketMQ Arbitrary File Write Vulnerability Exploit
CVE-2023-37582CRITICAL14 jul 2023
Apache RocketMQ: Possible remote code execution when using the update configuration function
85RISCO
abrir
GitHub PoC
Pog-Frog/cve-2022-44268
CVE-2022-44268MEDIUM14 jul 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISCO
abrir
GitHub PoC22
Muhammad-Ali007/OutlookNTLM_CVE-2023-23397
CVE-2023-23397CRITICALsob ataque14 jul 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC1
CVE-2023-33592批量漏洞利用程序
CVE-2023-3359214 jul 2023
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lf
23RISCO
abrir
GitHub PoC1
Recent Campaign abusing CVE-2023-36884
CVE-2023-36884HIGHsob ataqueransomware13 jul 2023
Windows Search Remote Code Execution Vulnerability
93RISCO
abrir
GitHub PoC106
Full Chain Analysis of CVE-2022-4262, a non-trivial feedback slot type confusion in V8.
CVE-2022-4262HIGHsob ataque13 jul 2023
Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corru
76RISCO
abrir
GitHub PoC
Proof of concept for LabVIEW Web Server HTTP Get Newline DoS vulnerability
CVE-2002-074813 jul 2023
LabVIEW Web Server 5.1.1 through 6.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET reques
28RISCO
abrir
GitHub PoC2
This is a Python3 script that demonstrates an exploit for a Blind SQL Injection vulnerability in WebERP version 4.15.
CVE-2019-1329213 jul 2023
A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is d
23RISCO
abrir
GitHub PoC
F5-BIG-IP Remote Code Execution Vulnerability CVE-2022-1388: A Case Study
CVE-2022-1388CRITICALsob ataqueransomware12 jul 2023
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir
GitHub PoC13
This project is a Python script that exploits the CVE-2023-24489 vulnerability in ShareFile. It allows remote command execution on the target server. The script supports both Windows and Linux (On testing) platforms, and it can be used to exploit individual targets or perform mass checking on a list of URLs.
CVE-2023-24489CRITICALsob ataque12 jul 2023
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, coul
100RISCO
abrir
GitHub PoC26
The remediation script should set the reg entries described in https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36884 . The detection script checks if they exist. Provided AS-IS without any warrenty.
CVE-2023-36884HIGHsob ataqueransomware12 jul 2023
Windows Search Remote Code Execution Vulnerability
93RISCO
abrir
GitHub PoC2
CVE-2023-27372-SPIP-CMS-Bypass
CVE-2023-27372CRITICAL11 jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir
GitHub PoC1
asepsaepdin/CVE-2021-1732
CVE-2021-1732HIGHsob ataqueransomware11 jul 2023
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC7
Exploit and scanner for CVE-2023-3460
CVE-2023-346011 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISCO
abrir
anteriorpágina 318 / 517próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.