Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.003exploits catalogados
37.620CVEs com exploração pública
24.695testados em laboratório
15.501 exploits
GitHub PoC
CVE-2023-3460
CVE-2023-346011 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISCO
abrir
GitHub PoC1
asepsaepdin/CVE-2021-1732
CVE-2021-1732HIGHsob ataqueransomware11 jul 2023
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC2
CVE-2023-27372-SPIP-CMS-Bypass
CVE-2023-27372CRITICAL11 jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir
GitHub PoC6
asepsaepdin/CVE-2023-22809
CVE-2023-22809HIGH10 jul 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir
GitHub PoC
asepsaepdin/CVE-2021-4034
CVE-2021-4034HIGHsob ataqueransomware10 jul 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
asepsaepdin/CVE-2021-3560
CVE-2021-3560HIGHsob ataque10 jul 2023
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir
GitHub PoC4
A Directory Traversal attack (also known as path traversal) aims to access files and directories that are stored outside the intended folder.
CVE-2023-32235HIGH09 jul 2023
Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2
68RISCO
abrir
GitHub PoC
Mass CVE-2023-3460.
CVE-2023-346009 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISCO
abrir
GitHub PoC1
Using CVE-2022-0847, "Dirty Pipe Exploit", to pop a reverse bash shell for arbitrary code execution on a foreign machine.
CVE-2022-0847HIGHsob ataque09 jul 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC
bthnrml/guncel-cve-2019-9053.py
CVE-2019-905309 jul 2023
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC10
POC for CVE-2023-34362 affecting MOVEit Transfer
CVE-2023-34362CRITICALsob ataqueransomware09 jul 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISCO
abrir
GitHub PoC2
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted script to the mc parameter of the URL
CVE-2023-3616308 jul 2023
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code
23RISCO
abrir
GitHub PoC
An issue in MiniTool Partition Wizard ShadowMaker v.12.7 allows an attacker to execute arbitrary code and gain privileges via the SchedulerService.exe component.
CVE-2023-3616508 jul 2023
20RISCO
abrir
GitHub PoC
An issue in MiniTool Partition Wizard ShadowMaker v.12.7 allows an attacker to execute arbitrary code via the MTAgentService component
CVE-2023-3616408 jul 2023
20RISCO
abrir
GitHub PoC
Icinga Web 2 - Authenticated Remote Code Execution <2.8.6, <2.9.6, <2.10
CVE-2022-24715HIGH08 jul 2023
Arbitrary code execution for authenticated users in Icinga Web 2
46RISCO
abrir
GitHub PoC
Achat 0.150 beta7 - Remote Buffer Overflow Rewrite for python3 for the PNPT course.
CVE-2015-157807 jul 2023
Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web s
23RISCO
abrir
GitHub PoC5
CVE-2023-32315-Openfire-Bypass
CVE-2023-32315HIGHsob ataque07 jul 2023
Openfire administration console authentication bypass
100RISCO
abrir
GitHub PoC
LoaiEsam37/CVE-2023-2982
CVE-2023-2982CRITICAL07 jul 2023
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RISCO
abrir
GitHub PoC
rizqimaulanaa/CVE-2023-3460
CVE-2023-346007 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISCO
abrir
GitHub PoC
pitufo1721/CVE-2025-55182-GodzillaMemoryShell
CVE-2025-55182CRITICALsob ataqueransomware07 jul 2023
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC8
An eBPF program to detect attacks on CVE-2022-0847
CVE-2022-0847HIGHsob ataque06 jul 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC6
This is a PoC for CVE-2023-27372 which spawns a fully interactive shell.
CVE-2023-27372CRITICAL05 jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir
GitHub PoC35
Exploit for CVE-2023-3460. Unauthorized admin access for Ultimate Member plugin < v2.6.7
CVE-2023-346005 jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISCO
abrir
GitHub PoC
This is the Updated Python3 exploit for CVE-2019-9053
CVE-2019-905304 jul 2023
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC2
CVE-2017-7921 EXPLOIT
CVE-2017-7921CRITICALsob ataque04 jul 2023
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISCO
abrir
GitHub PoC
WARNING: This is a vulnerable application to test the exploit for the Cacti command injection (CVE-2023-39362). Run it at your own risk!
CVE-2023-39362HIGH03 jul 2023
Authenticated command injection in SNMP options of a Device
63RISCO
abrir
GitHub PoC3
Fix WinVerifyTrust Signature Validation Vulnerability, CVE-2013-3900, QID-378332
CVE-2013-3900MEDIUMsob ataque03 jul 2023
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir
GitHub PoC13
PoC of Imagemagick's Arbitrary File Read
CVE-2022-44268MEDIUM03 jul 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISCO
abrir
GitHub PoC4
Wordpress CVE-2023-32243
CVE-2023-32243CRITICAL03 jul 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISCO
abrir
GitHub PoC6
Perform With Massive Openfire Unauthenticated Users
CVE-2023-32315HIGHsob ataque02 jul 2023
Openfire administration console authentication bypass
100RISCO
abrir
anteriorpágina 319 / 517próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.