Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
81.064exploits catalogados
37.667CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 24.044GitHub PoC 15.521VulnCheck XDB 9.080Nuclei 4.432Metasploit 3.505✓ só verificadosrecentespopularesrisco
15.521 exploits
GitHub PoC
mightysai1997/cve-2021-42013L
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗GitHub PoC
mightysai1997/cve-2021-42013
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗GitHub PoC★ 1
mightysai1997/CVE-2021-41773m
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗GitHub PoC
mightysai1997/CVE-2021-41773.git1
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗GitHub PoC
mightysai1997/CVE-2021-41773-i-
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗GitHub PoC★ 1
Free MP3 CD Ripper 2.6 版本中存在栈缓冲区溢出漏洞 (CVE-2019-9766),远程攻击者可借助特制的 .mp3 文件利用该漏洞执行任意代码。
Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to
23RISCO
abrir ↗GitHub PoC★ 2
bl4ck574r/CVE-2019-17662
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RISCO
abrir ↗GitHub PoC
ApacheSolrRCE(CVE-2019-0193)一键写shell,原理是通过代码执行的java文件流写的马。
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RISCO
abrir ↗GitHub PoC★ 5
CVE-2022-34715-POC pcap
Windows Network File System Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 7
Automation to validate the impact of the vulnerability CVE-2022-1292 on a specific system.
The c_rehash script allows command injection
70RISCO
abrir ↗GitHub PoC★ 8
POC exploit for CVE-2015-4133
Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 f
50RISCO
abrir ↗GitHub PoC★ 3
CVE-2022-27925 nuclei template
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISCO
abrir ↗GitHub PoC★ 323
A reliable exploit + write-up to elevate privileges to root. (Tested on Ubuntu 22.04)
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RISCO
abrir ↗GitHub PoC★ 1
M4fiaB0y/CVE-2022-30075
In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote
35RISCO
abrir ↗GitHub PoC★ 2
CVE-2022-0847(Dirty Pipe) vulnerability exploits.
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir ↗GitHub PoC★ 1
PhpMyAdmin 4.0.x—4.6.2 Remote Code Execution Vulnerability (CVE-2016-5734)
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to
60RISCO
abrir ↗GitHub PoC★ 4
CVE-2021-38163 - exploit for SAP Netveawer
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated
90RISCO
abrir ↗GitHub PoC★ 19
exploit for CVE-2017-1000486 vulnerability with SOCKS proxy support
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISCO
abrir ↗GitHub PoC
[CVE-2014-6271] Apache Shellshock Remote Command Injection tool for quick reverse shell and file browsing
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗GitHub PoC★ 5
CVE-2022-31188 - OpenCV CVAT (Computer Vision Annotation Tool) SSRF
Server-Side Request Forgery Vulnerability in Computer Vision Annotation Tool (CVAT)
53RISCO
abrir ↗GitHub PoC★ 3
CVE-2022-36446 - Webmin 1.996 Remote Code Execution
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
60RISCO
abrir ↗GitHub PoC★ 19
exploit for CVE-2017-1000486 vulnerability with SOCKS proxy support
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISCO
abrir ↗GitHub PoC
This powershell script is intended to be used by anyone looking to remediate the Log4j Vulnerability within their environment. It can target multiple machines and run remotely as a job on all or only affected devices.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC★ 35
A real exploit for BitBucket RCE CVE-2022-36804
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir ↗GitHub PoC
Remediation for CVE-2013-3900
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir ↗GitHub PoC★ 23
CVE-2021-34527 AddPrinterDriverEx() Privilege Escalation
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 1
Redis RCE through Lua Sandbox Escape vulnerability
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RISCO
abrir ↗GitHub PoC★ 22
CVE-2022-2586: Linux kernel nft_object UAF
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-a
68RISCO
abrir ↗GitHub PoC★ 1
0xrobiul/CVE-2018-15473
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir ↗GitHub PoC★ 2
Zabbix-SAML-Bypass: CVE-2022-23131
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.