Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
81.003exploits catalogados
37.620CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 24.011GitHub PoC 15.501VulnCheck XDB 9.077Nuclei 4.427Metasploit 3.505✓ só verificadosrecentespopularesrisco
15.501 exploits
GitHub PoC★ 1
Pada bulan maret 2023, terdapat sample baru yang terindentifikasi sebagai malware. Malware tersebut berasal dari file berekstensi.xls dan .doc dan dikenal dengan nama “Bank Slip.xls”. Aktivitas malware tersebut memiliki hubungan dengan kerentanan yang dikenal dengan id CVE-2017-11882 dan CVE-2018-0802.
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir ↗GitHub PoC★ 2
CVE-2022-31814
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir ↗GitHub PoC★ 13
Laravel Debug mode RCE漏洞(CVE-2021-3129)poc / exp
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗GitHub PoC★ 6
This script is used for automating exploit for Oracle Ebussiness (EBS) for CVE 2022-21587 ( Unauthenticated File Upload For Remote Code Execution)
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
100RISCO
abrir ↗GitHub PoC
Checker and exploit for Bluekeep CVE-2019-0708 vulnerability
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir ↗GitHub PoC
🚀 Exploit for Spring core RCE in C [ wip ]
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir ↗GitHub PoC
An exploit for CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir ↗GitHub PoC
mritunjay-k/CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗GitHub PoC
A demonstration of CVE-2022-42889 (text4shell) remote code execution vulnerability
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗GitHub PoC★ 1
TheUnknownSoul/CVE-2022-31814
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir ↗GitHub PoC★ 13
Joomla 未授权访问漏洞 CVE-2023-23752
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗GitHub PoC★ 1
cve-2020-0796利用工具集
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir ↗GitHub PoC★ 2
Kubernetes Lab for CVE-2022-42889
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗GitHub PoC★ 10
BlackVue DR750 CVE CVE-2023-27746 CVE-2023-27747 CVE-2023-27748
BlackVue DR750-2CH LTE v.1.012_2022.10.26 was discovered to contain a weak default passphrase which can be easily cracke
48RISCO
abrir ↗GitHub PoC★ 5
一键枚举所有用户名以及写入SSH公钥
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir ↗GitHub PoC
sz-guanx/CVE-2021-32305
WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search paramet
60RISCO
abrir ↗GitHub PoC★ 2
Ozozuz/Magnolia-CMS-6.2.19-Stored-Cross-Site-Scripting-CVE-2022-33098
Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function.
35RISCO
abrir ↗GitHub PoC
hhhotdrink/CVE-2021-22205
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir ↗GitHub PoC★ 7
CVE analysis for CVE-2023-0669
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RISCO
abrir ↗GitHub PoC
orsuprasad/CVE-2022-0847-DirtyPipe-Exploits
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir ↗GitHub PoC★ 16
nmap detection scripts for CVE-2022-45477, CVE-2022-45479, CVE-2022-45482, CVE-2022-45481
Telepad allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any pre
48RISCO
abrir ↗GitHub PoC★ 3
PoC for CVE-2022-39952 affecting Fortinet FortiNAC.
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8
85RISCO
abrir ↗GitHub PoC★ 2
yilin1203/CVE-2022-40881
SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php
75RISCO
abrir ↗GitHub PoC
JonPichel/CVE-2017-7358
In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrar
23RISCO
abrir ↗GitHub PoC★ 115
Weblogic CVE-2023-21839 RCE (无需Java依赖一键RCE)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISCO
abrir ↗GitHub PoC★ 18
simple program for joomla CVE-2023-23752 scanner for pentesting and educational purpose
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗GitHub PoC★ 34
Joomla! Core 1.5.0 - 3.9.4 - Directory Traversal / Authenticated Arbitrary File Deletion in Python3
An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder param
28RISCO
abrir ↗GitHub PoC
3ndorph1n/CVE-2021-42756
Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 a
60RISCO
abrir ↗GitHub PoC★ 1
CVE-2023-23752 poc
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗GitHub PoC★ 3
未授权访问漏洞
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.