Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
81.179exploits catalogados
37.765CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 24.138GitHub PoC 15.540VulnCheck XDB 9.080Nuclei 4.434Metasploit 3.505✓ só verificadosrecentespopularesrisco
15.540 exploits
GitHub PoC★ 1
cve-2022-29464 EXP
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir ↗GitHub PoC★ 28
This vulnerability may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only.
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir ↗GitHub PoC★ 16
may the poc with you
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISCO
abrir ↗GitHub PoC★ 6
WordPress Plugin MasterStudy LMS 2.7.5 - Unauthenticated Admin Account Creation
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
60RISCO
abrir ↗GitHub PoC
Satheesh575555/external_expat_AOSP10_r33_CVE-2022-25236
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace
60RISCO
abrir ↗GitHub PoC
CVE-2022-22954 analyst
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir ↗GitHub PoC★ 53
K23605346: BIG-IP iControl REST vulnerability CVE-2022-1388
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir ↗GitHub PoC★ 25
Simple script realizado en bash, para revisión de múltiples hosts para CVE-2022-1388 (F5)
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir ↗GitHub PoC★ 1
1
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir ↗GitHub PoC
CVE-2018-17553 PoC
An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs N
60RISCO
abrir ↗GitHub PoC★ 12
Exploit for CVE-2021-3560 (Polkit) - Local Privilege Escalation
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir ↗GitHub PoC
Willian-2-0-0-1/Log4j-Exploit-CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC★ 60
yuanLink/CVE-2022-26809
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 25
PolicyKit CVE-2021-3560 Exploitation (Authentication Agent)
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir ↗GitHub PoC★ 1
CVE-2021-44228 Log4j Summary
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC★ 2
CVE-2022-29464 POC exploit
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir ↗GitHub PoC
Enokiy/spring-RCE-CVE-2022-22965
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir ↗GitHub PoC★ 116
PolicyKit CVE-2021-3560 Exploit (Authentication Agent)
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir ↗GitHub PoC★ 8
This is an edited version of the CVE-2018-19422 exploit to fix an small but annoying issue I had.
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca
50RISCO
abrir ↗GitHub PoC★ 3
for kernel 3.18.x
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir ↗GitHub PoC★ 13
A tool for extracting, modifying, and crafting ASDM binary packages (CVE-2022-20829)
Cisco Adaptive Security Device Manager and Adaptive Security Appliance Software Client-side Arbitrary Code Execution Vulnerability
48RISCO
abrir ↗GitHub PoC
RedLeavesChilde/CVE-2021-40444
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 4
khidottrivi/CVE-2022-22965
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir ↗GitHub PoC★ 14
CVE-2021-41773&CVE-2021-42013图形化漏洞检测利用工具
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗GitHub PoC
OS X 10.11.6 LPE PoC for CVE-2016-4655 / CVE-2016-4656
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RISCO
abrir ↗GitHub PoC
CVE-2022-23046 phpIPAM 1.4.4
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su
28RISCO
abrir ↗GitHub PoC★ 1
CVE-2021-43857(gerapy命令执行)
Gerapy may contain remote code execution vulnerability
60RISCO
abrir ↗GitHub PoC
lowkey0808/cve-2022-29464
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir ↗GitHub PoC★ 1
Exploit for CVE-2021-3036, HTTP Smuggling + buffer overflow in PanOS 8.x
PAN-OS: Memory Corruption Vulnerability in GlobalProtect Portal and Gateway Interfaces
53RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.