Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.902exploits catalogados
34.597CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.624GitHub PoC 13.727VulnCheck XDB 8.410Nuclei 4.231Metasploit 3.467✓ só verificadosrecentespopularesrisco
13.727 exploits
GitHub PoC★ 22
Muhammad-Ali007/OutlookNTLM_CVE-2023-23397
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC
Pog-Frog/cve-2022-44268
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISCO
abrir ↗GitHub PoC★ 1
CVE-2023-33592批量漏洞利用程序
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lf
23RISCO
abrir ↗GitHub PoC★ 1
Recent Campaign abusing CVE-2023-36884
Windows Search Remote Code Execution Vulnerability
93RISCO
abrir ↗GitHub PoC
Proof of concept for LabVIEW Web Server HTTP Get Newline DoS vulnerability
LabVIEW Web Server 5.1.1 through 6.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET reques
28RISCO
abrir ↗GitHub PoC★ 106
Full Chain Analysis of CVE-2022-4262, a non-trivial feedback slot type confusion in V8.
Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corru
76RISCO
abrir ↗GitHub PoC★ 2
This is a Python3 script that demonstrates an exploit for a Blind SQL Injection vulnerability in WebERP version 4.15.
A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is d
23RISCO
abrir ↗GitHub PoC★ 26
The remediation script should set the reg entries described in https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36884 . The detection script checks if they exist. Provided AS-IS without any warrenty.
Windows Search Remote Code Execution Vulnerability
93RISCO
abrir ↗GitHub PoC
F5-BIG-IP Remote Code Execution Vulnerability CVE-2022-1388: A Case Study
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir ↗GitHub PoC★ 13
This project is a Python script that exploits the CVE-2023-24489 vulnerability in ShareFile. It allows remote command execution on the target server. The script supports both Windows and Linux (On testing) platforms, and it can be used to exploit individual targets or perform mass checking on a list of URLs.
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, coul
100RISCO
abrir ↗GitHub PoC★ 1
asepsaepdin/CVE-2021-1732
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC★ 1
Python script that generates pfs payloads to exploit CVE-2022-4510
Path Traversal in binwalk
46RISCO
abrir ↗GitHub PoC★ 2
Search vulnerable FortiOS devices via Shodan (CVE-2023-27997)
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISCO
abrir ↗GitHub PoC★ 2
CVE-2023-27372-SPIP-CMS-Bypass
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir ↗GitHub PoC★ 7
Exploit and scanner for CVE-2023-3460
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISCO
abrir ↗GitHub PoC
asepsaepdin/CVE-2021-3560
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir ↗GitHub PoC
asepsaepdin/CVE-2021-4034
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗GitHub PoC★ 6
asepsaepdin/CVE-2023-22809
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir ↗GitHub PoC
bthnrml/guncel-cve-2019-9053.py
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir ↗GitHub PoC★ 4
A Directory Traversal attack (also known as path traversal) aims to access files and directories that are stored outside the intended folder.
Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2
68RISCO
abrir ↗GitHub PoC★ 1
Using CVE-2022-0847, "Dirty Pipe Exploit", to pop a reverse bash shell for arbitrary code execution on a foreign machine.
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir ↗GitHub PoC
Mass CVE-2023-3460.
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISCO
abrir ↗GitHub PoC★ 10
POC for CVE-2023-34362 affecting MOVEit Transfer
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISCO
abrir ↗GitHub PoC
Icinga Web 2 - Authenticated Remote Code Execution <2.8.6, <2.9.6, <2.10
Arbitrary code execution for authenticated users in Icinga Web 2
46RISCO
abrir ↗GitHub PoC
An issue in MiniTool Partition Wizard ShadowMaker v.12.7 allows an attacker to execute arbitrary code and gain privileges via the SchedulerService.exe component.
20RISCO
abrir ↗GitHub PoC★ 2
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted script to the mc parameter of the URL
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code
23RISCO
abrir ↗GitHub PoC
An issue in MiniTool Partition Wizard ShadowMaker v.12.7 allows an attacker to execute arbitrary code via the MTAgentService component
20RISCO
abrir ↗GitHub PoC
Achat 0.150 beta7 - Remote Buffer Overflow Rewrite for python3 for the PNPT course.
Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web s
23RISCO
abrir ↗GitHub PoC
rizqimaulanaa/CVE-2023-3460
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.