Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
82.252exploits catalogados
38.481CVEs com exploração pública
24.695testados em laboratório
TodosReferência 24.678Exploit-DB 24.485GitHub PoC 15.900VulnCheck XDB 9.221Nuclei 4.455Metasploit 3.513✓ só verificadosrecentespopularesrisco
82.252 exploits
Exploit-DB
Apache Superset 2.0.0 - Authentication Bypass
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISCO
abrir ↗Metasploit600
Apache RocketMQ update config RCE
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISCO
abrir ↗Exploit-DB
PaperCut NG/MG 22.0.4 - Remote Code Execution (RCE)
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir ↗Metasploit600
Barracuda ESG TAR Filename Command Injection
Remote Code injection in Barracuda Email Security Gateway
100RISCO
abrir ↗Exploit-DB
Webkul Qloapps 1.5.2 - Cross-Site Scripting (XSS)
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive informat
48RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GetSimple CMS v3.3.16 - Remote Code Execution (RCE)
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file paramete
46RISCO
abrir ↗Exploit-DB
CiviCRM 5.59.alpha1 - Stored XSS (Cross-Site Scripting)
Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to exe
33RISCO
abrir ↗Exploit-DB
FusionInvoice 2023-1.0 - Stored XSS (Cross-Site Scripting)
Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitr
33RISCO
abrir ↗Exploit-DB
PnPSCADA v2.x - Unauthenticated PostgreSQL Injection
The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL
48RISCO
abrir ↗VulnCheck XDB
initial-access
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
43RISCO
abrir ↗VulnCheck XDB
initial-access
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
43RISCO
abrir ↗VulnCheck XDB
initial-access
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
43RISCO
abrir ↗VulnCheck XDB
initial-access
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RISCO
abrir ↗VulnCheck XDB
initial-access
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗GitHub PoC★ 286
CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling vulnerability.
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RISCO
abrir ↗GitHub PoC
This little script encrypts password to gpp cpassword. It useful to create vulnerable lab AD (CVE-2014-1812).
The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windo
98RISCO
abrir ↗GitHub PoC★ 1
vsftpd 2.0.5 - 'CWD' (Authenticated) Remote Memory Consumption
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 throug
28RISCO
abrir ↗GitHub PoC
Dockerized POC for CVE-2022-42889 Text4Shell
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗VulnCheck XDB
local
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RISCO
abrir ↗VulnCheck XDB
local
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir ↗VulnCheck XDB
local
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir ↗VulnCheck XDB
local
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RISCO
abrir ↗VulnCheck XDB
infoleak
SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because t
75RISCO
abrir ↗GitHub PoC
Proof of Concept about a XSS Stored in SCM Manager 1.2 <= 1.60
A stored cross-site scripting (XSS) vulnerability in Cloudogu GmbH SCM Manager v1.2 to v1.60 allows attackers to execute
33RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.