Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.902exploits catalogados
34.597CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.624GitHub PoC 13.727VulnCheck XDB 8.410Nuclei 4.231Metasploit 3.467✓ só verificadosrecentespopularesrisco
13.727 exploits
GitHub PoC★ 2
Tools for working with ImageMagick to handle arbitrary file read vulnerabilities. Generate, read, and apply profile information to PNG files using a command-line interface.
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISCO
abrir ↗GitHub PoC
pashayogi/CVE-2023-22809
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir ↗GitHub PoC★ 1
Based on the x.pl exploit/loader script for CVE-2009-1151
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RISCO
abrir ↗GitHub PoC★ 1
Windows Network File System Remote exploit (DoS) PoC
Windows Network File System Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC
puckiestyle/cve-2023-27997
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISCO
abrir ↗GitHub PoC★ 10
An exploit for CVE-2018-5955 GitStack 2.3.10 Unauthenticated RCE
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau
60RISCO
abrir ↗GitHub PoC★ 1
imbas007/CVE-2023-27997-Check
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISCO
abrir ↗GitHub PoC★ 34
An exploit for CVE-2022-42475, a pre-authentication heap overflow in Fortinet networking products
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISCO
abrir ↗GitHub PoC
sonpt-afk/CVE-2018-11776-FIS
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir ↗GitHub PoC★ 2
Analysis & Exploit
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir ↗GitHub PoC★ 1
Exploring CVE-2021-42013, using Suricata and OpenVAS to gather info
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗GitHub PoC★ 11
cfielding-r7/poc-cve-2023-2868
Remote Code injection in Barracuda Email Security Gateway
100RISCO
abrir ↗GitHub PoC★ 2
PoC and exploit for CVE-2022-22965 Spring4Shell
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir ↗GitHub PoC★ 19
Exploits for a heap overflow in MiniDLNA <=1.3.2 (CVE-2023-33476)
ReadyMedia (MiniDLNA) versions from 1.1.15 up to 1.3.2 is vulnerable to Buffer Overflow. The vulnerability is caused by
48RISCO
abrir ↗GitHub PoC★ 2
POC Exploit to add user to Sudo for CVE-2022-0847 Dirty Pipe Vulnerability
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir ↗GitHub PoC
overgrowncarrot1/CVE-2021-22911
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISCO
abrir ↗GitHub PoC★ 69
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir ↗GitHub PoC★ 57
Openfire Console Authentication Bypass Vulnerability with RCE plugin
Openfire administration console authentication bypass
100RISCO
abrir ↗GitHub PoC★ 7
CVE-2023-24078 for FuguHub / BarracudaDrive
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the c
53RISCO
abrir ↗GitHub PoC★ 1
CVE-2023-24078 for FuguHub / BarracudaDrive
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the c
53RISCO
abrir ↗GitHub PoC★ 23
FortiOS 管理界面中的堆内存下溢导致远程代码执行
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0
53RISCO
abrir ↗GitHub PoC★ 134
Safely detect whether a FortiGate SSL VPN instance is vulnerable to CVE-2023-27997 based on response timing
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISCO
abrir ↗GitHub PoC★ 6
Repository with everything I have tracking the impact of MOVEit CVE-2023-34362
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISCO
abrir ↗GitHub PoC★ 27
POC FortiOS SSL-VPN buffer overflow vulnerability
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISCO
abrir ↗GitHub PoC★ 4
Joomla未授权访问漏洞
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗GitHub PoC★ 15
SolarView Compact through 6.00 downloader.php commands injection (RCE) nuclei-templates
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RISCO
abrir ↗GitHub PoC
CVE-2023-34600
Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection.
53RISCO
abrir ↗GitHub PoC
Exploit for CVE-2022-44136 for chcking security of your site
Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).
48RISCO
abrir ↗GitHub PoC
Samba 3.0.20
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.