Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.534GitHub PoC 13.654VulnCheck XDB 8.213Nuclei 4.218Metasploit 3.464✓ só verificadosrecentespopularesrisco
13.654 exploits
GitHub PoC★ 3
is a PoC tool that targets a vulnerability in the TeamCity server (CVE-2024-27198)
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir ↗GitHub PoC★ 1
Proof of Concept for the Log4Shell vulnerability (CVE-2021-44228), developed as part of the coursework for the curricular unit TPAS in the Master's degree in Information Security at FCUP.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC
wargame, CVE-2024-4367
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir ↗GitHub PoC
Apache CouchDB 3.2.1 - Remote Code Execution (RCE) Checker
Remote Code Execution Vulnerability in Packaging
100RISCO
abrir ↗GitHub PoC
TeamCity server scanner to detect CVE-2023-42793
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir ↗GitHub PoC
bka/magento-cve-2024-34102-exploit-cosmicstring
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir ↗GitHub PoC★ 1
Performs an IPv6 vulnerability scan and packet flood attack on specified targets. The script simulates a SYN flood and ICMP flood attack and optionally sends exploit packets.
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 1
Agilevatester/FlaskCache_CVE-2021-33026_POC
The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code e
48RISCO
abrir ↗GitHub PoC
The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attac
Booking Calendar <= 9.9 - Unauthenticated SQL Injection
48RISCO
abrir ↗GitHub PoC★ 83
Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit
The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selector
53RISCO
abrir ↗GitHub PoC★ 1
Automated Exploit for CVE-2020-6287
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISCO
abrir ↗GitHub PoC★ 1
CVE-2023-22527 | RCE using SSTI in Confluence
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISCO
abrir ↗GitHub PoC★ 4
is a PoC tool demonstrating an exploit for a known vulnerability in the WebDAV component of IIS6
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir ↗GitHub PoC★ 4
is a PoC tool designed to exploit an authenticated Remote Code Execution (RCE) vulnerability in specific versions of PostgreSQL (9.3 - 11.7)
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir ↗GitHub PoC★ 3
Python implementation of a tool for decrypting and encrypting sensitive data in Grafana, specifically addressing the vulnerabilities associated with CVE-2021-43798. Grafana encrypts all data source passwords using the AES algorithm with the secret_key found in the defaults.ini configuration file.
Grafana path traversal
100RISCO
abrir ↗GitHub PoC★ 4
A simple Python script to test an off-by-one vulnerability in the OPIE library (CVE-2010-1938). This vulnerability affects certain FTP servers and may allow for Denial of Service (DoS) or arbitrary code execution.
Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeB
28RISCO
abrir ↗GitHub PoC★ 139
Zimbra - Remote Command Execution (CVE-2024-45519)
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISCO
abrir ↗GitHub PoC★ 6
CVE-2024-26304 is a critical vulnerability (CVSS score of 9.8) affecting ArubaOS
There is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated r
60RISCO
abrir ↗GitHub PoC★ 5
The CVE-2019-16172 Scanner is designed to check LimeSurvey instances for the stored XSS vulnerability.
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, Su
23RISCO
abrir ↗GitHub PoC★ 1
Woo Inquiry <= 0.1 - Unauthenticated SQL Injection
Woo Inquiry <= 0.1 - Unauthenticated SQL Injection
63RISCO
abrir ↗GitHub PoC★ 2
Simple hash cracker for Apache Shiro hashes written in Golang. Useful for exploiting CVE-2024-4956.
Nexus Repository 3 - Path Traversal
61RISCO
abrir ↗GitHub PoC★ 3
A Bash script designed to scan multiple domains for the CVE-2024-4577 vulnerability in PHP-CGI.
Argument Injection in PHP-CGI
100RISCO
abrir ↗GitHub PoC
EuJin03/CVE-2021-4034-PoC
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗GitHub PoC
Exploit of CVE-2021-23639 for the vulnerable library 'md-to-pdf' in JS
Remote Code Execution (RCE)
48RISCO
abrir ↗GitHub PoC★ 2
Nortek Linear eMerge E3 Pre-Auth RCE PoC (CVE-2024-9441)
Linear eMerge e3-Series Forgot Password Command Injection
60RISCO
abrir ↗GitHub PoC★ 3
CVE-2023-41425 (Wonder CMS XSS to RCE) exploit which serves required scripts locally. Good if you're lost at sea and have found a problem with your bike.
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir ↗GitHub PoC★ 5
This Python script helps to detect the Etherleak (CVE-2003-0001) vulnerability on a target host by analyzing the padding data in network packets. The script uses Scapy to send various types of requests (ICMP, ARP, or TCP) and checks if the responses contain any padding data that could potentially leak sensitive memory contents.
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote att
45RISCO
abrir ↗GitHub PoC★ 1
Wechat Social login <= 1.3.0 - Authentication Bypass
Wechat Social login <= 1.3.0 - Authentication Bypass
48RISCO
abrir ↗GitHub PoC★ 12
GiveWP PHP Object Injection exploit
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
68RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.