Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
81.859exploits catalogados
38.203CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.483Referência 24.469GitHub PoC 15.768VulnCheck XDB 9.182Nuclei 4.447Metasploit 3.510✓ só verificadosrecentespopularesrisco
81.859 exploits
GitHub PoC
MahdiOsman/CVE-2018-15473-SNMPv1-2-Community-String-Vulnerability-Testing
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir ↗VulnCheck XDB
initial-access
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir ↗Metasploit600
BYOB Unauthenticated RCE via Arbitrary File Write and Command Injection (CVE-2024-45256, CVE-2024-45257)
A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbi
36RISCO
abrir ↗GitHub PoC
1amthebest1/CVE-2023-27372
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir ↗Metasploit600
BYOB Unauthenticated RCE via Arbitrary File Write and Command Injection (CVE-2024-45256, CVE-2024-45257)
An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overw
43RISCO
abrir ↗VulnCheck XDB
initial-access
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISCO
abrir ↗GitHub PoC★ 3
This exploit was created to exploit an XXE (XML External Entity). Through it, I read the backend code of the web service and found an endpoint where I could use gopher to make internal requests on Zabbix vulnerable to RCE.
Time Based SQL Injection in Zabbix Server Audit Log
70RISCO
abrir ↗GitHub PoC★ 125
fortra/CVE-2024-30051
Windows DWM Core Library Elevation of Privilege Vulnerability
71RISCO
abrir ↗VulnCheck XDB
local
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
Time Based SQL Injection in Zabbix Server Audit Log
70RISCO
abrir ↗GitHub PoC
Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the vulnerability is found. This tool is particularly useful for security researchers and penetration testers.
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
Time Based SQL Injection in Zabbix Server Audit Log
70RISCO
abrir ↗GitHub PoC
jFriedli/CVE-2023-3897
Bypassing CAPTCHA & Enumerating Usernames via Password Reset Page
33RISCO
abrir ↗GitHub PoC★ 3
This is my exploit for CVE-2024-22120, which involves an SSRF vulnerability inside an XXE with a Gopher payload.
Time Based SQL Injection in Zabbix Server Audit Log
70RISCO
abrir ↗VulnCheck XDB
initial-access
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir ↗GitHub PoC★ 4
Adobe Commerce XXE exploit
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir ↗GitHub PoC★ 3
K7 Ultimate Security < v17.0.2019 "K7RKScan.sys" Null Pointer Dereference PoC
K7RKScan.sys in K7 Ultimate Security before 17.0.2019 allows local users to cause a denial of service (BSOD) because of
33RISCO
abrir ↗VulnCheck XDB
initial-access
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir ↗GitHub PoC
CVE-2024-37085 unauthenticated shell upload to full administrator on domain-joined esxi hypervisors.
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) per
68RISCO
abrir ↗GitHub PoC
This repository contains detailed documentation and code related to the exploitation, detection, and mitigation of two significant vulnerabilities: CVE-2020-0796 (SMBGhost) and Print Spooler.
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir ↗GitHub PoC
This script is a proof-of-concept exploit for pfBlockerNG <= 2.1.4_26 that allows for remote code execution. It takes a single target URL or a list of URLs, tries to upload a shell using multiple payloads, executes a command, and then deletes the shell.
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir ↗VulnCheck XDB
infoleak
SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated at
60RISCO
abrir ↗VulnCheck XDB
initial-access
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗GitHub PoC
CVE-2017-16921: In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manipulate form parameters (related to PGP) and execute arbitrary shell commands with the permissions of the OTRS or web server user.
In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.2
28RISCO
abrir ↗GitHub PoC
A bash automation that exploits the vulnerable endpoints for the Joomla! API 4.0 - 4.2.7
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗GitHub PoC★ 1
Wonder CMS RCE (XSS)
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir ↗GitHub PoC★ 2
A PoC Exploit for CVE-2024-3105 - The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress Remote Code Execution (RCE)
Woody code snippets – Insert Header Footer Code, AdSense Ads <= 2.5.0 -Authenticated (Contributor+) Remote Code Execution
48RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.