Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.902exploits catalogados
34.597CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.624GitHub PoC 13.727VulnCheck XDB 8.410Nuclei 4.231Metasploit 3.467✓ só verificadosrecentespopularesrisco
13.727 exploits
GitHub PoC★ 1
MinIO Information Disclosure Vulnerability scanner by metasploit
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir ↗GitHub PoC★ 2
Perfom With Massive Authentication Bypass In PaperCut MF/NG
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir ↗GitHub PoC★ 2
Spring Cloud Gateway Actuator API SpEL表达式注入命令执行Exp
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir ↗GitHub PoC★ 1
PoC for login with password hash in STARFACE
RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the
41RISCO
abrir ↗GitHub PoC★ 140
GitLab CVE-2023-2825 PoC. This PoC leverages a path traversal vulnerability to retrieve the /etc/passwd file from a system running GitLab 16.0.0.
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RISCO
abrir ↗GitHub PoC★ 6
MStore API <= 3.9.2 - Authentication Bypass
MStore API <= 3.9.2 - Authentication Bypass
75RISCO
abrir ↗GitHub PoC
Exploit for CVE-2022-22963 remote command execution in Spring Cloud Function
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir ↗GitHub PoC★ 7
Camaleon CMS v2.7.0 contain a Server-Side Template Injection (SSTI) vulnerability
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats para
60RISCO
abrir ↗GitHub PoC
Vulnerable docker to test for: CVE-2023-32243
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISCO
abrir ↗GitHub PoC★ 30
PoC for CVE-2023-28771 based on Rapid7's excellent writeup
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware vers
100RISCO
abrir ↗GitHub PoC
manavvedawala2/CVE-2023-32243-POC
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISCO
abrir ↗GitHub PoC
manavvedawala2/CVE-2023-32243-proof-of-concept
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISCO
abrir ↗GitHub PoC
Dockerized POC for CVE-2022-42889 Text4Shell
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗GitHub PoC
This little script encrypts password to gpp cpassword. It useful to create vulnerable lab AD (CVE-2014-1812).
The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windo
98RISCO
abrir ↗GitHub PoC★ 286
CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling vulnerability.
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RISCO
abrir ↗GitHub PoC★ 1
vsftpd 2.0.5 - 'CWD' (Authenticated) Remote Memory Consumption
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 throug
28RISCO
abrir ↗GitHub PoC★ 1
Golang implementation of ThinVNC exploit CVE-2019-17662. For educational purposes only.
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RISCO
abrir ↗GitHub PoC
xiaosed/CVE-2023-29919
SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because t
75RISCO
abrir ↗GitHub PoC
Proof of Concept about a XSS Stored in SCM Manager 1.2 <= 1.60
A stored cross-site scripting (XSS) vulnerability in Cloudogu GmbH SCM Manager v1.2 to v1.60 allows attackers to execute
33RISCO
abrir ↗GitHub PoC★ 59
CVE-2023-21554 Windows MessageQueuing PoC,分析见 https://www.zoemurmure.top/posts/cve_2023_21554/
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
85RISCO
abrir ↗GitHub PoC★ 24
PoC for CVE-2023-20126
Cisco SPA112 2-Port Phone Adapters Remote Command Execution Vulnerability
60RISCO
abrir ↗GitHub PoC★ 4
A reflected Cross-Site Scripting (XSS) vulnerability exists in the Edit User functionality of the Microworld Technologies eScan Management Console (version 14.0.1400.2281).
Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allo
48RISCO
abrir ↗GitHub PoC
Exploit to cve-2023-1671. So there is a test and exploitation function. The test sends a ping request to the dnslog domain from the vulnerable site. If the ping passes, the vulnerability exists, if it doesn't, then cve-2023-1671 is missing. The exploit function, on the other hand, sends a request with your command to the server.
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISCO
abrir ↗GitHub PoC★ 2
CVE-2023-31702 is an authenticated SQL Injection vulnerability discovered in MicroWorld Technologies eScan Management Console version 14.0.1400.2281.
SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to d
41RISCO
abrir ↗GitHub PoC★ 51
Vulnerabilities Exploitation On Ubuntu 22.04
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir ↗GitHub PoC★ 11
POC for the CVE-2022-36944 vulnerability exploit
Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There i
48RISCO
abrir ↗GitHub PoC★ 1
Exploit script for CVE-2022-41544 - RCE in get-simple CMS
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file paramete
41RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.