Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.902exploits catalogados
34.597CVEs com exploração pública
24.695testados em laboratório
13.727 exploits
GitHub PoC
Anonimo501/ssh_enum_users_CVE-2018-15473
CVE-2018-15473MEDIUM21 abr 2023
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC2
「💥」CVE-2022-4944: KodExplorer <= 4.49 - CSRF to Arbitrary File Upload
CVE-2022-4944MEDIUM21 abr 2023
kalcaddle KodExplorer cross-site request forgery
33RISCO
abrir
GitHub PoC10
veritas501/CVE-2023-0386
CVE-2023-0386HIGHsob ataque20 abr 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir
GitHub PoC
A little demonstration of cve-2021-41773 on httpd docker containers
CVE-2021-41773HIGHsob ataqueransomware20 abr 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC14
CVE-2023-21823 PoC
CVE-2023-21823HIGHsob ataque20 abr 2023
Windows Graphics Component Remote Code Execution Vulnerability
71RISCO
abrir
GitHub PoC
Dima2021/cve-2022-42889-text4shell
CVE-2022-4288918 abr 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC4
Reproduce CVE-2023-2033
CVE-2023-2033HIGHsob ataque17 abr 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RISCO
abrir
GitHub PoC4
randallbanner/Spring-Cloud-Function-Vulnerability-CVE-2022-22963-RCE
CVE-2022-22963CRITICALsob ataque17 abr 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
GitHub PoC1
msd0pe-1/CVE-2023-31714
CVE-2023-3171416 abr 2023
Chitor-CMS before v1.1.2 was discovered to contain multiple SQL injection vulnerabilities.
23RISCO
abrir
GitHub PoC8
POC : CVE-2023-21716 Microsoft Word RTF Font Table Heap Corruption
CVE-2023-21716CRITICAL16 abr 2023
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC18
CVE-2023-21839 Python版本
CVE-2023-21839HIGHsob ataque15 abr 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISCO
abrir
GitHub PoC
💣💥💀 Proof of Concept: пример запуска fork-бомбы на удаленном сервере благодаря уязвимости CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware15 abr 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC4
houqe/EXP_CVE-2018-19518
CVE-2018-1951815 abr 2023
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh c
60RISCO
abrir
GitHub PoC7
CVE-2022-38181 POC for FireTV 2nd gen Cube (raven)
CVE-2022-38181HIGHsob ataque13 abr 2023
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishan
76RISCO
abrir
GitHub PoC3
CVE-2022-38181 POC for FireTV 3rd gen Cube (gazelle)
CVE-2022-38181HIGHsob ataque13 abr 2023
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishan
76RISCO
abrir
GitHub PoC
CHINA-china/MinIO_CVE-2023-28432_EXP
CVE-2023-28432HIGHsob ataque13 abr 2023
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir
GitHub PoC3
Fixed exploit for CVE-2022-46169 (originally from https://www.exploit-db.com/exploits/51166)
CVE-2022-46169CRITICALsob ataque13 abr 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC
hh-hunter/ml-CVE-2023-1177
CVE-2023-1177CRITICAL13 abr 2023
Path Traversal: '\..\filename' in mlflow/mlflow
75RISCO
abrir
GitHub PoC1
F5 BIG-IP Exploit Using CVE-2022-1388 and CVE-2022-41800
CVE-2022-1388CRITICALsob ataqueransomware12 abr 2023
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir
GitHub PoC
Unauthenticated Remote Code Execution through authentication bypass and command injection in Cacti < 1.2.23 and < 1.3.0
CVE-2022-46169CRITICALsob ataque11 abr 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC
nik0nz7/CVE-2020-14882
CVE-2020-14882CRITICALsob ataque11 abr 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC
FzBacon/CVE-2023-25234_Tenda_AC6_stack_overflow
CVE-2023-25234CRITICAL11 abr 2023
Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInte
53RISCO
abrir
GitHub PoC3
QloApp 1.5.2: Vulnerable to XSS on two Parameter (email_create and back)
CVE-2023-30256MEDIUM10 abr 2023
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive informat
48RISCO
abrir
GitHub PoC1
Rust-based exploit for the CVE-2022-22963 vulnerability
CVE-2022-22963CRITICALsob ataque10 abr 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
GitHub PoC
Test environments for CVE-2023-28432, information disclosure in MinIO clusters
CVE-2023-28432HIGHsob ataque09 abr 2023
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir
GitHub PoC33
Perform With Mass Exploiter In Joomla 4.2.8.
CVE-2023-23752MEDIUMsob ataque09 abr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
GitHub PoC
ReachabilityOrg/cve-2022-42889-text4shell-docker
CVE-2022-4288908 abr 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC
Ge-Per/Scanner-CVE-2023-23752
CVE-2023-23752MEDIUMsob ataque08 abr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
GitHub PoC2
POC,EXP,chatGPT for me
CVE-2022-45047CRITICAL07 abr 2023
Apache MINA SSHD: Java unsafe deserialization vulnerability
48RISCO
abrir
GitHub PoC
jedai47/CVE-2018-7273
CVE-2018-727307 abr 2023
In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables usi
23RISCO
abrir
anteriorpágina 275 / 458próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.