Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.902exploits catalogados
34.597CVEs com exploração pública
24.695testados em laboratório
13.727 exploits
GitHub PoC
CVE-2022-21907漏洞RCE PoC
CVE-2022-21907CRITICAL06 mai 2023
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC
c7w1n/CVE-2023-30185
CVE-2023-30185CRITICAL05 mai 2023
CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\System
48RISCO
abrir
GitHub PoC2
simple Python exploit using CVE-2018-7449 on embOS/IP FTP Server v3.22
CVE-2018-744905 mai 2023
SEGGER FTP Server for Windows before 3.22a allows remote attackers to cause a denial of service (daemon crash) via an in
23RISCO
abrir
GitHub PoC
User enumeration for CVE-2018-15473
CVE-2018-15473MEDIUM05 mai 2023
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC420
CVE-2023-0386在ubuntu22.04上的提权
CVE-2023-0386HIGHsob ataque05 mai 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir
GitHub PoC1
mclbn/docker-cve-2018-15473
CVE-2018-15473MEDIUM05 mai 2023
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC
threatcode/CVE-2008-6806
CVE-2008-680604 mai 2023
Unrestricted file upload vulnerability in includes/imageupload.php in 7Shop 1.1 and earlier allows remote attackers to e
23RISCO
abrir
GitHub PoC4
Satheesh575555/linux-4.19.72_CVE-2023-0386
CVE-2023-0386HIGHsob ataque04 mai 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir
GitHub PoC3
Perform With Apache-SuperSet Leaked Token [CSRF]
CVE-2023-27524HIGHsob ataque04 mai 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISCO
abrir
GitHub PoC
A POC for the all new CVE-2023-27524 which allows for authentication bypass and gaining access to the admin dashboard.
CVE-2023-27524HIGHsob ataque04 mai 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISCO
abrir
GitHub PoC
🐍 Python Exploit for CVE-2022-46169
CVE-2022-46169CRITICALsob ataque04 mai 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC
This is a exploit of CVE-2019-16278 for Nostromo 1.9.6 RCE. This exploit allows RCE on the victim machine.
CVE-2019-16278CRITICALsob ataque04 mai 2023
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISCO
abrir
GitHub PoC6
0xhav0c/CVE-2013-5211
CVE-2013-521103 mai 2023
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISCO
abrir
GitHub PoC
Binaries for CVE-2022-22963
CVE-2022-22963CRITICALsob ataque03 mai 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
GitHub PoC1
Improved PoC for Unauthenticated RCE on Cacti <= 1.2.22 - CVE-2022-46169
CVE-2022-46169CRITICALsob ataque02 mai 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC
Este es un código del exploit CVE-2022-46169, que recree utilizando Python3! Si por ahí estás haciendo una máquina de HTB, esto te puede ser útil... 🤞✨
CVE-2022-46169CRITICALsob ataque02 mai 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC1
An exploitation of CVE-2022-30190 (Follina)
CVE-2022-30190HIGHsob ataqueransomware02 mai 2023
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
tuankiethkt020/Phat-hien-CVE-2017-8464
CVE-2017-8464HIGHsob ataque01 mai 2023
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RISCO
abrir
GitHub PoC3
Exploit for cacti version 1.2.22
CVE-2022-46169CRITICALsob ataque01 mai 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC
Zoo1sondv/CVE-2021-3129
CVE-2021-3129CRITICALsob ataqueransomware01 mai 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC42
This is a exploit of CVE-2022-46169 to cacti 1.2.22. This exploit allows through an RCE to obtain a reverse shell on your computer.
CVE-2022-46169CRITICALsob ataque01 mai 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC2
Akash7350/CVE-2020-1472
CVE-2020-1472MEDIUMsob ataqueransomware30 abr 2023
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC1
zPrototype/CVE-2023-29809
CVE-2023-29809CRITICAL30 abr 2023
SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbit
53RISCO
abrir
GitHub PoC
check cve-2022-0847
CVE-2022-0847HIGHsob ataque30 abr 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC
Cisco r042 research
CVE-2023-20025CRITICAL30 abr 2023
A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 Routers co
48RISCO
abrir
GitHub PoC
MrE-Fog/CVE-2014-0160-Chrome-Plugin
CVE-2014-0160HIGHsob ataque30 abr 2023
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
CVE-2022-46169
CVE-2022-46169CRITICALsob ataque30 abr 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC
gretchenfrage/CVE-2023-2033-analysis
CVE-2023-2033HIGHsob ataque30 abr 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RISCO
abrir
GitHub PoC
PoC for CVE-2022-46169 that affects Cacti 1.2.22 version
CVE-2022-46169CRITICALsob ataque29 abr 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC
zPrototype/CVE-2023-29983
CVE-2023-29983MEDIUM29 abr 2023
Cross Site Scripting vulnerability found in Maximilian Vogt cmaps v.8.0 allows a remote attacker to execute arbitrary co
33RISCO
abrir
anteriorpágina 273 / 458próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.