Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
81.689exploits catalogados
38.075CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 24.381GitHub PoC 15.712VulnCheck XDB 9.162Nuclei 4.445Metasploit 3.507✓ só verificadosrecentespopularesrisco
81.689 exploits
GitHub PoC★ 96
synacktiv/CVE-2024-43468
Microsoft Configuration Manager Remote Code Execution Vulnerability
100RISCO
abrir ↗VulnCheck XDB
local
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
76RISCO
abrir ↗GitHub PoC★ 3
WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.43.2 is vulnerable to Unauthenticated Arbitrary Plugin Installation
Spam protection, Anti-Spam, FireWall by CleanTalk <= 6.43.2 - Authorization Bypass via Reverse DNS Spoofing to Unauthenticated Arbitrary Plugin Installation
53RISCO
abrir ↗VulnCheck XDB
initial-access
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISCO
abrir ↗GitHub PoC★ 1
Proof Of Concept for the CVE-2012-1831 (Kingview Touchview 6.53). This is a Industrial Control Systems Vulnerability
Heap-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted p
28RISCO
abrir ↗VulnCheck XDB
infoleak
WordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data Exposure
60RISCO
abrir ↗VulnCheck XDB
initial-access
Microsoft Configuration Manager Remote Code Execution Vulnerability
100RISCO
abrir ↗VulnCheck XDB
denial-of-service
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir ↗VulnCheck XDB
infoleak
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISCO
abrir ↗VulnCheck XDB
initial-access
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RISCO
abrir ↗GitHub PoC★ 3
Identify hikvision ip and probe for cve-s (CVE-2017-7921, CVE-2022-28171, CVE-2021-36260)
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir ↗VulnCheck XDB
initial-access
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISCO
abrir ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RISCO
abrir ↗GitHub PoC★ 1
Projet de présentation d'une CVE (ShellShock) avec pdf, démonstration technique et reproductible
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗VulnCheck XDB
local
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RISCO
abrir ↗VulnCheck XDB
infoleak
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RISCO
abrir ↗VulnCheck XDB
initial-access
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RISCO
abrir ↗GitHub PoC★ 3
Identify hikvision ip and probe for cve-s (CVE-2017-7921, CVE-2022-28171, CVE-2021-36260)
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISCO
abrir ↗GitHub PoC
Picsmize <= 1.0.0 - Unauthenticated Arbitrary File Upload
WordPress Picsmize plugin <= 1.0.0 - Arbitrary File Upload vulnerability
48RISCO
abrir ↗VulnCheck XDB
local
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir ↗GitHub PoC
Magento 2 patch for CVE-2022-24086, CVE-2022-24087. Fix the RCE vulnerability and related bugs by performing deep template variable escaping. If you cannot upgrade Magento or cannot apply the official patches, try this one.
Adobe Commerce checkout improper input validation leads to remote code execution
100RISCO
abrir ↗GitHub PoC
Lis Video Gallery <= 0.2.1 - Unauthenticated PHP Object Injection
WordPress Lis Video Gallery plugin <= 0.2.1 - PHP Object Injection vulnerability
48RISCO
abrir ↗GitHub PoC
Working Dirty Pipe (CVE-2022-0847) exploit tool with root access and file overwrites.
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir ↗VulnCheck XDB
initial-access
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISCO
abrir ↗GitHub PoC
WolffCorentin/CVE-2019-1663-Binary-Analysis
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RISCO
abrir ↗GitHub PoC★ 1
Xss injection, WonderCMS 3.2.0 -3.4.2
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir ↗GitHub PoC★ 1
Remote Command Execution into shell from a vulnerable exim service.
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISCO
abrir ↗GitHub PoC
francescobrina/hfs-cve-2014-6287-exploit
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.