Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
82.646exploits catalogados
38.712CVEs com exploração pública
24.695testados em laboratório
TodosReferência 24.884Exploit-DB 24.485GitHub PoC 15.969VulnCheck XDB 9.333Nuclei 4.457Metasploit 3.518✓ só verificadosrecentespopularesrisco
82.647 exploits
GitHub PoC★ 15
Confluence Hardcoded Password POC
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in th
100RISCO
abrir ↗GitHub PoC★ 25
「💥」CVE-2022-33891 - Apache Spark Command Injection
Apache Spark shell command injection vulnerability via Spark UI
100RISCO
abrir ↗GitHub PoC★ 2
Script to exploit CVE-2018-1042 in order to do internal port scans.
Moodle 3.x has Server Side Request Forgery in the filepicker.
28RISCO
abrir ↗VulnCheck XDB
initial-access
Apache Spark shell command injection vulnerability via Spark UI
100RISCO
abrir ↗VulnCheck XDB
initial-access
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in th
100RISCO
abrir ↗Exploit-DB
rpc.py 0.6.0 - Remote Code Execution (RCE)
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header i
35RISCO
abrir ↗VulnCheck XDB
initial-access
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RISCO
abrir ↗GitHub PoC
xpgdgit/CVE-2015-1427
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RISCO
abrir ↗GitHub PoC★ 78
wo ee cve-2022-2185 gitlab authenticated rce
A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to
85RISCO
abrir ↗Exploit-DB
Dingtian-DT-R002 3.1.276A - Authentication Bypass
relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post reques
38RISCO
abrir ↗GitHub PoC★ 3
Atlassian Confluence Server and Data Center: CVE-2022-26138
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in th
100RISCO
abrir ↗GitHub PoC
Reports on post-exploitation on honeypot exploiting vulnerable wu-ftpd (CVE-2001-0550)
wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which i
45RISCO
abrir ↗GitHub PoC★ 1
libSSH-Authentication-Bypass
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir ↗GitHub PoC★ 408
警惕 一种针对红队的新型溯源手段!
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC
weblogic-cve-2018-2628-exp
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISCO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISCO
abrir ↗Metasploit600
Softing Secure Integration Server v1.22 Remote Code Execution
Softing Secure Integration Server Relative Path Traversal
41RISCO
abrir ↗Metasploit600
Softing Secure Integration Server v1.22 Remote Code Execution
Softing Secure Integration Server Uncontrolled Search Path Element
41RISCO
abrir ↗GitHub PoC★ 14
QNAP N-Day (Probably not CVE-2020-2509)
Command Injection Vulnerability in QTS and QuTS hero
90RISCO
abrir ↗GitHub PoC★ 7
Zimbra unrar vulnerability. Now there are already POC available, it is safe to release our POC.
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) o
100RISCO
abrir ↗VulnCheck XDB
initial-access
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir ↗GitHub PoC★ 1
WebMin Versions <= 1.920 [CVE-2019-15107] RCE PoC
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir ↗GitHub PoC
A demo for cve-2019-12735
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via th
28RISCO
abrir ↗Metasploit600
Webmin Package Updates RCE
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
60RISCO
abrir ↗GitHub PoC
Module for PrestaShop 1.6.1.X/1.7.X to fix CVE-2022-31181 / CVE-2022-36408 vulnerability (Chain SQL Injection)
Remote code execution in prestashop
63RISCO
abrir ↗VulnCheck XDB
initial-access
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.