Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.542exploits catalogados
34.971CVEs com exploração pública
24.695testados em laboratório
13.947 exploits
GitHub PoC
WpDiscuz 7.0.4 Arbitrary File Upload Exploit
CVE-2020-24186CRITICAL13 ago 2021
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RISCO
abrir
GitHub PoC1
Sudo Heap Overflow Baron Samedit
CVE-2021-3156HIGHsob ataque13 ago 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC3
Exploit for CVE-2021-36934
CVE-2021-36934HIGHsob ataque12 ago 2021
Windows Elevation of Privilege Vulnerability
98RISCO
abrir
GitHub PoC5
Scanner for CVE-2021-34473, ProxyShell, A Microsoft Exchange On-premise Vulnerability
CVE-2021-34473CRITICALsob ataqueransomware11 ago 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
Jerry-zhuang/CVE-2017-1000117
CVE-2017-100011711 ago 2021
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RISCO
abrir
GitHub PoC
Zeek Package to detect cve-2017-2741
CVE-2017-274111 ago 2021
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmwa
60RISCO
abrir
GitHub PoC10
Windows Font Driver Type 1 VToHOrigin stack corruption
CVE-2020-1020HIGHsob ataque10 ago 2021
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly
83RISCO
abrir
GitHub PoC1
OlivierLaflamme/CVE-2021-36934-export-shadow-volume-POC
CVE-2021-36934HIGHsob ataque10 ago 2021
Windows Elevation of Privilege Vulnerability
98RISCO
abrir
GitHub PoC2
CVE-2019-11043
CVE-2019-11043HIGHsob ataqueransomware10 ago 2021
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC
ZeroShell命令执行漏洞批量扫描poc+exp
CVE-2019-1272510 ago 2021
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISCO
abrir
GitHub PoC46
nuclei scanner for proxyshell ( CVE-2021-34473 )
CVE-2021-34473CRITICALsob ataqueransomware10 ago 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
CVE-2021-2109 basic scanner
CVE-2021-2109HIGH09 ago 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
63RISCO
abrir
GitHub PoC9
BabyTeam1024/CVE-2021-2394
CVE-2021-2394CRITICAL08 ago 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
70RISCO
abrir
GitHub PoC
Very basic bash script to exploit the CVE-2019-6447.
CVE-2019-644708 ago 2021
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISCO
abrir
GitHub PoC
Modified version of CVE-2019-5736-PoC by Frichetten
CVE-2019-573607 ago 2021
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
GitHub PoC
CVE-2020-35847, CVE-2020-35848 : Account Takeover
CVE-2020-3584706 ago 2021
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
60RISCO
abrir
GitHub PoC1
this script is exploit for wordpress old plugin gwolle
CVE-2015-835106 ago 2021
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ
35RISCO
abrir
GitHub PoC4
Pastea/CVE-2017-1000486
CVE-2017-1000486CRITICALsob ataque05 ago 2021
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISCO
abrir
GitHub PoC1
An implementation of CVE-2017-5638
CVE-2017-5638CRITICALsob ataqueransomware04 ago 2021
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC4
s4dbrd/CVE-2020-9496
CVE-2020-949604 ago 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISCO
abrir
GitHub PoC
Windows Elevation of Privilege Vulnerability CVE-2021-36934
CVE-2021-36934HIGHsob ataque04 ago 2021
Windows Elevation of Privilege Vulnerability
98RISCO
abrir
GitHub PoC1
An implementation of CVE-2016-8740
CVE-2016-874003 ago 2021
The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2
45RISCO
abrir
GitHub PoC2
POC experiments with Volume Shadow copy Service (VSS)
CVE-2021-36934HIGHsob ataque02 ago 2021
Windows Elevation of Privilege Vulnerability
98RISCO
abrir
GitHub PoC20
POC of CVE-2021-2394
CVE-2021-2394CRITICAL02 ago 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
70RISCO
abrir
GitHub PoC40
POC of CVE-2021-2394
CVE-2021-2394CRITICAL02 ago 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
70RISCO
abrir
GitHub PoC3
PenTestical/CVE-2021-22204
CVE-2021-22204MEDIUMsob ataque02 ago 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISCO
abrir
GitHub PoC27
AssassinUKG/CVE-2021-22204
CVE-2021-22204MEDIUMsob ataque02 ago 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISCO
abrir
GitHub PoC
CVE-2018-20250
CVE-2018-20250HIGHsob ataqueransomware02 ago 2021
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
GitHub PoC5
My n-day exploit for CVE-2019-18634 (local privilege escalation)
CVE-2019-1863401 ago 2021
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISCO
abrir
GitHub PoC2
SeriousSAM Auto Exploiter
CVE-2021-36934HIGHsob ataque01 ago 2021
Windows Elevation of Privilege Vulnerability
98RISCO
abrir
anteriorpágina 363 / 465próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.