Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
81.192exploits catalogados
37.765CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 24.138GitHub PoC 15.542VulnCheck XDB 9.091Nuclei 4.434Metasploit 3.505✓ só verificadosrecentespopularesrisco
15.542 exploits
GitHub PoC
ms15-034 or CVE-2015-1635 批量扫描
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISCO
abrir ↗GitHub PoC
CVE-2021-42013 - Apache 2.4.50
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗GitHub PoC
CVE-2019-15107
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir ↗GitHub PoC★ 2
Watchguard RCE POC CVE-2022-26318
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulner
100RISCO
abrir ↗GitHub PoC★ 1
GitLab 13.10.2 - Remote Code Execution (RCE) (Unauthenticated) cve-2021-22205
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir ↗GitHub PoC★ 1
CVE-2015-1635-POC,指定IP与端口验证HTTP.sys漏洞是否存在
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISCO
abrir ↗GitHub PoC★ 1
A Log4j vulnerability scanner is used to identify the CVE-2021-44228 and CVE_2021_45046
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC★ 9
Scripted Linux Privilege Escalation for the CVE-2022-0847 "Dirty Pipe" vulnerability
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir ↗GitHub PoC
mhurts/CVE-2022-22954-POC
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir ↗GitHub PoC★ 156
Laravel RCE Exploit PoC - CVE-2021-3129 (user-friendly with automatic log path detection)
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗GitHub PoC★ 2
Repository containing nse script for vulnerability CVE-2022-21907. It is a component (IIS) vulnerability on Windows. It allows remote code execution. The vulnerability affects the kernel module http. sys, which handles most basic IIS operations.
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 2
CVE-2021-44529 Ivanti EPM 云服务设备 (CSA) 中的代码注入漏洞允许未经身份验证的用户以有限的权限(nobody)执行任意代码。
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execut
100RISCO
abrir ↗GitHub PoC★ 55
Exploit for CVE-2021-22204 (ExifTool) - Arbitrary Code Execution
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISCO
abrir ↗GitHub PoC★ 2
tufanturhan/CVE-2022-21971-Windows-Runtime-RCE
Windows Runtime Remote Code Execution Vulnerability
83RISCO
abrir ↗GitHub PoC★ 4
CVE-2022-22954 VMware Workspace ONE Access free marker SSTI
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir ↗GitHub PoC★ 11
Spring Cloud Gateway Actuator API SpEL Code Injection (CVE-2022-22947)
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir ↗GitHub PoC
tufanturhan/CVE-2022-0847-L-nux-PrivEsc
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir ↗GitHub PoC★ 32
Detects attempts and successful exploitation of CVE-2022-26809
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 19
The poc for CVE-2022-26809 RCE via RPC will be updated here.
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 27
Remote Code Execution Exploit in the RPC Library
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 7
auduongxuan/CVE-2022-26809
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 3
CVE-2022-0185 exploit
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RISCO
abrir ↗GitHub PoC
VVeakee/CVE-2017-12149
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISCO
abrir ↗GitHub PoC★ 8
Spring Cloud Function SPEL表达式注入漏洞(CVE-2022-22963)
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir ↗GitHub PoC★ 1
Proof of Concept for exploiting VMware CVE-2022-22954
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir ↗GitHub PoC★ 3
A Zeek detector for CVE-2022-24497.
Windows Network File System Remote Code Execution Vulnerability
60RISCO
abrir ↗GitHub PoC
VMware Workspace ONE Access远程代码执行漏洞 / Code By:Jun_sheng
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir ↗GitHub PoC★ 16
VMware Workspace ONE Access and Identity Manager RCE via SSTI - Test script for shodan, file or manual.
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir ↗GitHub PoC★ 68
CVE-2022-22954 VMware Workspace ONE Access freemarker SSTI 漏洞 命令执行、批量检测脚本、文件写入
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir ↗GitHub PoC★ 3
A Zeek CVE-2022-24491 detector.
Windows Network File System Remote Code Execution Vulnerability
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.