Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
82.322exploits catalogados
38.524CVEs com exploração pública
24.695testados em laboratório
TodosReferência 24.711Exploit-DB 24.485GitHub PoC 15.927VulnCheck XDB 9.231Nuclei 4.455Metasploit 3.513✓ só verificadosrecentespopularesrisco
82.322 exploits
Metasploit600
Local Privilege Escalation via CVE-2023-0386
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir ↗Exploit-DB
Linksys AX3200 V1.1.00 - Command Injection
Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagn
46RISCO
abrir ↗GitHub PoC★ 1
Mustafa1986/cve-2022-42475-Fortinet
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISCO
abrir ↗GitHub PoC★ 14
Python script for sending e-mails with CVE-2023-23397 payload using SMTP
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC
Mustafa1986/CVE-2022-22963
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir ↗GitHub PoC★ 25
Proof of Concept for CVE-2023-23397 in Python
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗VulnCheck XDB
initial-access
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir ↗GitHub PoC
maldev866/ChExp_CVE-2021-30632
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap c
83RISCO
abrir ↗VulnCheck XDB
local
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISCO
abrir ↗GitHub PoC★ 6
Altenergy Power System Control Software set_timezone RCE Vulnerability (CVE-2023-28343)
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RISCO
abrir ↗GitHub PoC
SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.
SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent chang
48RISCO
abrir ↗VulnCheck XDB
client-side
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap c
83RISCO
abrir ↗Metasploit300
MinIO Bootstrap Verify Information Disclosure
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir ↗GitHub PoC
Arbitrary File Disclosure Vulnerability in Icinga Web 2 <2.8.6, <2.9.6, <2.10
Path traversal in Icinga Web 2
78RISCO
abrir ↗GitHub PoC
this web is vulnerable against CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC★ 130
Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC★ 1
Patch for MS Outlook Critical Vulnerability - CVSS 9.8
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗VulnCheck XDB
local
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir ↗GitHub PoC★ 1
Custom exploit written for enumerating usernames as per CVE-2016-6210
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISCO
abrir ↗GitHub PoC★ 2
ahmedkhlief/CVE-2023-23397-POC-Using-Interop-Outlook
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.