Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.003exploits catalogados
37.620CVEs com exploração pública
24.695testados em laboratório
15.501 exploits
GitHub PoC2
CVE-2014-6287
CVE-2014-6287CRITICALsob ataque04 abr 2023
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir
GitHub PoC8
Poc for CVE-2023-23752
CVE-2023-23752MEDIUMsob ataque04 abr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
GitHub PoC
docker for CVE-2022-42889
CVE-2022-4288904 abr 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC3
brosck/CVE-2006-3392
CVE-2006-339204 abr 2023
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RISCO
abrir
GitHub PoC2
my python poc CVE-2023-24774 and CVE-2023-24775 this sqli cve funadmin
CVE-2023-24775CRITICAL03 abr 2023
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member
53RISCO
abrir
GitHub PoC
Struts2 S2-061 远程命令执行漏洞(CVE-2020-17530)
CVE-2020-17530CRITICALsob ataque02 abr 2023
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISCO
abrir
GitHub PoC1
A vulnerable Spring Boot application that uses log4j and is vulnerable to CVE-2021-44228, CVE-2021-44832, CVE-2021-45046 and CVE-2021-45105
CVE-2021-44228CRITICALsob ataqueransomware02 abr 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
devAL3X/CVE-2022-46169_poc
CVE-2022-46169CRITICALsob ataque01 abr 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC1
WARNING: This is a vulnerable application to test the exploit for the Cacti command injection (CVE-2022-46169). Run it at your own risk!
CVE-2022-46169CRITICALsob ataque01 abr 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC8
BoxBilling<=4.22.1.5 - Remote Code Execution (RCE)
CVE-2022-3552HIGH01 abr 2023
Unrestricted Upload of File with Dangerous Type in boxbilling/boxbilling
53RISCO
abrir
GitHub PoC
exploit for CVE-2021-22911 in rust
CVE-2021-2291101 abr 2023
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISCO
abrir
GitHub PoC
lionelmusonza/CVE-2023-26866
CVE-2023-26866CRITICAL01 abr 2023
GreenPacket OH736's WR-1200 Indoor Unit, OT-235 with firmware versions M-IDU-1.6.0.3_V1.1 and MH-46360-2.0.3-R5-GP respe
48RISCO
abrir
GitHub PoC
webmin <=1.920 - RCE via command injection vulnerability
CVE-2019-15107CRITICALsob ataqueransomware31 mar 2023
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC3
CVE-2023-23397漏洞的简单PoC,有效载荷通过电子邮件发送。
CVE-2023-23397CRITICALsob ataque31 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC1
ZCBS/ZBBS/ZPBS v4.14k - Reflected XSS
CVE-2023-26692MEDIUM30 mar 2023
ZCBS Zijper Collectie Beheer Systeem (ZCBS), Zijper Publication Management System (ZPBS), and Zijper Image Bank Manageme
33RISCO
abrir
GitHub PoC
turnernator1/Node.js-CVE-2017-5941
CVE-2017-594130 mar 2023
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISCO
abrir
GitHub PoC10
CVE-2023-28432 MinIO敏感信息泄露检测脚本
CVE-2023-28432HIGHsob ataque29 mar 2023
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir
GitHub PoC
jacquesquail/CVE-2023-23397
CVE-2023-23397CRITICALsob ataque29 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
0759104103/cd-CVE-2019-11932
CVE-2019-1193229 mar 2023
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
GitHub PoC1
Full LPE Exploit for CVE-2019-5596 / FreeBSD-SA-19:02.fd
CVE-2019-559629 mar 2023
In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEAS
23RISCO
abrir
GitHub PoC
cyberdesu/Remote-Buffer-overflow-CVE-2003-0172
CVE-2003-017228 mar 2023
Buffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes, allows remote at
28RISCO
abrir
GitHub PoC
Bash Script for Checking Command Injection Vulnerability on CentOS Web Panel [CWP] (CVE-2022-44877)
CVE-2022-44877CRITICALsob ataque27 mar 2023
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISCO
abrir
GitHub PoC
PoC for CVE-2022-39952 affecting Fortinet FortiNAC.
CVE-2022-39952CRITICAL27 mar 2023
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8
85RISCO
abrir
GitHub PoC2
通过vulhub的复现过程实现了,基本的批量检测。比较垃圾但是勉强能用
CVE-2023-28432HIGHsob ataque27 mar 2023
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir
GitHub PoC319
EXP for CVE-2023-28434 MinIO unauthorized to RCE
CVE-2023-28434HIGHsob ataque27 mar 2023
MinIO is vulnerable to privilege escalation on Linux/MacOS
71RISCO
abrir
GitHub PoC3
Arbitrary File Disclosure Vulnerability in Icinga Web 2 <2.8.6, <2.9.6, <2.10
CVE-2022-24716HIGH27 mar 2023
Path traversal in Icinga Web 2
78RISCO
abrir
GitHub PoC1
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information.
CVE-2019-1653HIGHsob ataque26 mar 2023
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISCO
abrir
GitHub PoC1
pfBlockerNG <= 2.1.4_26 Unauth RCE (CVE-2022-31814)
CVE-2022-31814CRITICAL26 mar 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir
GitHub PoC6
0xNahim/CVE-2023-23752
CVE-2023-23752MEDIUMsob ataque26 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
GitHub PoC
pumpkinpiteam/CVE-2022-24716
CVE-2022-24716HIGH26 mar 2023
Path traversal in Icinga Web 2
78RISCO
abrir
anteriorpágina 329 / 517próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.