Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.647exploits catalogados
34.986CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.899GitHub PoC 14.014VulnCheck XDB 8.571Nuclei 4.248Metasploit 3.472✓ só verificadosrecentespopularesrisco
14.014 exploits
GitHub PoC★ 2
CVE-2020–7961 Mass exploit for Script Kiddies
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISCO
abrir ↗GitHub PoC★ 2
CVE-2021-3317
KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of
35RISCO
abrir ↗GitHub PoC
Buffer Overflow in Seattle Lab Mail (SLmail) 5.5 - POP3
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RISCO
abrir ↗GitHub PoC
CVE-2016-2098 - POC of RCE Ruby on Rails: Improper Input Validation (CVE-2016-2098) in bash. Remote attackers can execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISCO
abrir ↗GitHub PoC
Exploit for CVE-2012-2982
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISCO
abrir ↗GitHub PoC
pwn3z/CVE-2019-19781-Citrix
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir ↗GitHub PoC★ 37
vRealize RCE + Privesc (CVE-2021-21975, CVE-2021-21983, CVE-0DAY-?????)
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir ↗GitHub PoC★ 1
Exploit Code for CVE-2020-1472 aka Zerologon
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC★ 6
[CVE-2021-21972] VMware vSphere Client Unauthorized File Upload to Remote Code Execution (RCE)
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir ↗GitHub PoC
capturingcats/CVE-2021-3156
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir ↗GitHub PoC★ 3
Exploiting CVE-2014-7205 by injecting arbitrary JavaScript resulting in Remote Code Execution.
Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for t
60RISCO
abrir ↗GitHub PoC
delina1/CVE-2018-8174_EXP
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir ↗GitHub PoC
delina1/CVE-2018-8174
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RISCO
abrir ↗GitHub PoC★ 1
CVE-2017-9805-Exploit
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir ↗GitHub PoC
piruprohacking/CVE-2020-25213
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISCO
abrir ↗GitHub PoC
CVE-2019-0708 Exploit
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir ↗GitHub PoC
shreesh1/CVE-2014-0226-poc
Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denia
45RISCO
abrir ↗GitHub PoC★ 3
linuxdy/CVE-2021-1732_exp
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC★ 4
[CVE-2021-21975] VMware vRealize Operations Manager API Server Side Request Forgery (SSRF)
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir ↗GitHub PoC★ 27
Nmap script to check vulnerability CVE-2021-21975
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir ↗GitHub PoC★ 1
Vulnmachines/apache-ofbiz-CVE-2020-9496
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISCO
abrir ↗GitHub PoC★ 3
CVE-2020-14882部署冰蝎内存马
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir ↗GitHub PoC★ 12
VMWare vRealize SSRF-CVE-2021-21975
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir ↗GitHub PoC★ 9
hev0x/CVE-2021-26828_ScadaBR_RCE
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and exe
83RISCO
abrir ↗GitHub PoC★ 13
CVE-2021-21975 vRealize Operations Manager SSRF
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir ↗GitHub PoC★ 2
dorkerdevil/CVE-2021-21975
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISCO
abrir ↗GitHub PoC★ 1
A collection of scripts and instructions to test CVE-2014-0160 (heartbleed). ❤️ 🩸
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir ↗GitHub PoC
CVE-2019-12840
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISCO
abrir ↗GitHub PoC★ 11
Public PoC Disclosure for CVE-2020-23839 - GetSimple CMS v3.3.16 suffers from a Reflected XSS on the Admin Login Portal
A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpa
28RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.