Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.647exploits catalogados
34.986CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.899GitHub PoC 14.014VulnCheck XDB 8.571Nuclei 4.248Metasploit 3.472✓ só verificadosrecentespopularesrisco
14.014 exploits
GitHub PoC
CVE-2019-12840
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISCO
abrir ↗GitHub PoC★ 1
CVE-2021-3156漏洞修复Shell
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir ↗GitHub PoC★ 11
Public PoC Disclosure for CVE-2020-23839 - GetSimple CMS v3.3.16 suffers from a Reflected XSS on the Admin Login Portal
A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpa
28RISCO
abrir ↗GitHub PoC
dotslashed/CVE-2021-22986
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir ↗GitHub PoC★ 247
C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 13
Code By:Tas9er / F5 BIG-IP 远程命令执行漏洞
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir ↗GitHub PoC★ 21
Hancheng-Lei/Hacking-Vulnerability-CVE-2020-1938-Ghostcat
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir ↗GitHub PoC★ 1
Another implementation for linux privilege escalation exploit via snap(d) (CVE-2019-7304)
Local privilege escalation via snapd socket
53RISCO
abrir ↗GitHub PoC★ 38
CVE-2021-22192 靶场: 未授权用户 RCE 漏洞
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticat
53RISCO
abrir ↗GitHub PoC★ 8
F5 BIG-IP远程代码执行;cve-2021-22986,批量检测;命令执行利用
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir ↗GitHub PoC
siramk/CVE-2018-1335
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISCO
abrir ↗GitHub PoC★ 30
Vulnerability analysis and PoC for the Apache Tomcat - CGIServlet enableCmdLineArguments Remote Code Execution (RCE)
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISCO
abrir ↗GitHub PoC★ 1
Hack The CCTV | DVRs; Credentials Exposed | CVE-2018-9995
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir ↗GitHub PoC
Proof of concept for CVE-2020-11819 and CVE-2020-15946
In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve
28RISCO
abrir ↗GitHub PoC★ 10
Mybb associate CVE-2021-27890 & CVE-2021-27889 to RCE poc
SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.
28RISCO
abrir ↗GitHub PoC★ 52
Proof-of-concept exploit for CVE-2021-26855 and CVE-2021-27065. Unauthenticated RCE in Exchange.
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 10
CVE-2017-0100、MS17-012、Eop
A DCOM object in Helppane.exe in Microsoft Windows 7 SP1; Windows Server 2008 R2; Windows 8.1; Windows Server 2012 Gold
23RISCO
abrir ↗GitHub PoC
analytics ProxyLogo Mail exchange RCE
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 3
CVE-2021-22986 Checker Script in Python3
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir ↗GitHub PoC
Bypass bludit mitigation login form and upload malicious to call a rev shell
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISCO
abrir ↗GitHub PoC
kiri-48/CVE-2021-22986
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir ↗GitHub PoC★ 91
CVE-2021-22986 & F5 BIG-IP RCE
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir ↗GitHub PoC
F5 BIG-IP/BIG-IQ iControl Rest API SSRF to RCE
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir ↗GitHub PoC★ 18
EEsshq/CVE-2017-0144---EtneralBlue-MS17-010-Remote-Code-Execution
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir ↗GitHub PoC
Microsoft Exchange Proxylogon Exploit Chain EXP分析
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 4
CVE-2021-22986 F5 BIG-IP iControl 命令执行漏洞
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir ↗GitHub PoC
A vulnerability scanner that detects CVE-2021-22986 vulnerabilities.
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir ↗GitHub PoC★ 1
Exploiting CVE-2016-2555 enumerating and dumping the underlying Database.
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RISCO
abrir ↗GitHub PoC★ 3
Zoho ManageEngine ServiceDesk Plus MSP - Active Directory User Enumeration (CVE-2021-31159) - https://ricardojoserf.github.io/CVE-2021-31159/
Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-messag
28RISCO
abrir ↗GitHub PoC★ 4
Jquery File Tree 1.6.6 Path Traversal exploit (CVE-2017-1000170)
jqueryFileTree 2.1.5 and older Directory Traversal
50RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.