Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
81.859exploits catalogados
38.203CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.483Referência 24.469GitHub PoC 15.768VulnCheck XDB 9.182Nuclei 4.447Metasploit 3.510✓ só verificadosrecentespopularesrisco
81.859 exploits
GitHub PoC★ 2
This Python script checks for the CVE-2024-6387 vulnerability in OpenSSH servers. It supports multiple IP addresses, URLs, CIDR ranges, and ports. The script can also read addresses from a file.
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir ↗GitHub PoC
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
100RISCO
abrir ↗GitHub PoC
Apache: a Mainstream Web Service Turned a Vector of Attack for Remote Code Execution
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗VulnCheck XDB
local
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir ↗GitHub PoC★ 2
D0rDa4aN919/CVE-2023-22809-Exploiter
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir ↗GitHub PoC★ 6
This exploit will attempt to execute system commands on SPIP targets.
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISCO
abrir ↗GitHub PoC★ 7
potential memory corruption vulnerabilities in IPv6 networks.
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 4
Windows TCP/IP IPv6(CVE-2024-38063)
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 3
Apache OFBiz CVE-2024-38856
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISCO
abrir ↗GitHub PoC★ 1
【Teedy 1.11】Account Takeover via XSS
Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.
41RISCO
abrir ↗GitHub PoC★ 2
Remotely Exploiting The Kernel Via IPv6
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 3
CVE-2023-41425 - Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component.
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir ↗GitHub PoC★ 20
patchpoint/CVE-2024-38063
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 1
Nuclei template to scan for Apache Ofbiz affecting versions before 18.12.15
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISCO
abrir ↗GitHub PoC★ 10
CVE-2024-25641 - RCE Automated Exploit - Cacti 1.2.26
Cacti RCE vulnerability when importing packages
85RISCO
abrir ↗VulnCheck XDB
initial-access
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISCO
abrir ↗VulnCheck XDB
initial-access
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISCO
abrir ↗Metasploit600
Moodle Remote Code Execution (CVE-2024-43425)
Moodle: remote code execution via calculated question types
78RISCO
abrir ↗GitHub PoC★ 2
PoC for CVE-2024-25641 Authenticated RCE on Cacti v1.2.26
Cacti RCE vulnerability when importing packages
85RISCO
abrir ↗GitHub PoC★ 4
Mass scanner for CVE-2024-36401
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir ↗VulnCheck XDB
initial-access
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISCO
abrir ↗VulnCheck XDB
initial-access
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir ↗GitHub PoC★ 4
Jelly Template Injection Vulnerability in ServiceNow | POC CVE-2024-4879
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISCO
abrir ↗GitHub PoC★ 7
PoC for the CVE-2024 Litespeed Cache Privilege Escalation
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISCO
abrir ↗GitHub PoC
CVE-2023-4220 Chamilo Exploit
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir ↗GitHub PoC
zxybfq/CVE-2021-4034
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗GitHub PoC
Sudo Privilege Escalation: CVE-2023-22809 Simulation This project simulates the Sudo privilege escalation vulnerability (CVE-2023-22809) to demonstrate how unauthorized root access can be gained. It involves identifying and exploiting this vulnerability in a controlled environment using Parrot OS, the Sudo command, and Bash scripting.
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir ↗GitHub PoC
sanan2004/CVE-2023-20198
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir ↗VulnCheck XDB
initial-access
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.