Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
82.451exploits catalogados
38.590CVEs com exploração pública
24.695testados em laboratório
TodosReferência 24.767Exploit-DB 24.485GitHub PoC 15.955VulnCheck XDB 9.270Nuclei 4.456Metasploit 3.518✓ só verificadosrecentespopularesrisco
82.451 exploits
VulnCheck XDB
initial-access
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗GitHub PoC
[CVE-2014-6271] Apache Shellshock Remote Command Injection tool for quick reverse shell and file browsing
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗GitHub PoC★ 5
CVE-2022-31188 - OpenCV CVAT (Computer Vision Annotation Tool) SSRF
Server-Side Request Forgery Vulnerability in Computer Vision Annotation Tool (CVAT)
53RISCO
abrir ↗VulnCheck XDB
initial-access
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISCO
abrir ↗GitHub PoC★ 19
exploit for CVE-2017-1000486 vulnerability with SOCKS proxy support
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISCO
abrir ↗GitHub PoC★ 19
exploit for CVE-2017-1000486 vulnerability with SOCKS proxy support
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISCO
abrir ↗GitHub PoC★ 3
CVE-2022-36446 - Webmin 1.996 Remote Code Execution
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
60RISCO
abrir ↗GitHub PoC
This powershell script is intended to be used by anyone looking to remediate the Log4j Vulnerability within their environment. It can target multiple machines and run remotely as a job on all or only affected devices.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC★ 35
A real exploit for BitBucket RCE CVE-2022-36804
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir ↗VulnCheck XDB
initial-access
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir ↗Metasploit600
Syncovery For Linux Web-GUI Authenticated Remote Command Execution
Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote c
30RISCO
abrir ↗GitHub PoC
Remediation for CVE-2013-3900
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir ↗Metasploit300
Syncovery For Linux Web-GUI Session Token Brute-Forcer
An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and be
18RISCO
abrir ↗Metasploit500
pfSense plugin pfBlockerNG unauthenticated RCE as root
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir ↗GitHub PoC★ 1
Redis RCE through Lua Sandbox Escape vulnerability
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RISCO
abrir ↗GitHub PoC★ 23
CVE-2021-34527 AddPrinterDriverEx() Privilege Escalation
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 1
0xrobiul/CVE-2018-15473
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir ↗VulnCheck XDB
initial-access
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗VulnCheck XDB
local
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-a
68RISCO
abrir ↗GitHub PoC★ 22
CVE-2022-2586: Linux kernel nft_object UAF
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-a
68RISCO
abrir ↗GitHub PoC★ 5
Win10 20H2 LPE for CVE-2021-31956
Windows NTFS Elevation of Privilege Vulnerability
76RISCO
abrir ↗GitHub PoC★ 2
Zabbix-SAML-Bypass: CVE-2022-23131
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISCO
abrir ↗GitHub PoC★ 4
Powertek PDU身份绕过
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypas
68RISCO
abrir ↗GitHub PoC
75ACOL/CVE-2022-22963
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir ↗VulnCheck XDB
initial-access
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RISCO
abrir ↗GitHub PoC
shavchen/CVE-2022-26138
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in th
100RISCO
abrir ↗VulnCheck XDB
local
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.