Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.949exploits catalogados
34.636CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.662GitHub PoC 13.734VulnCheck XDB 8.410Nuclei 4.233Metasploit 3.467✓ só verificadosrecentespopularesrisco
13.727 exploits
GitHub PoC
Checker help to verify created account or find it's mandat
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISCO
abrir ↗GitHub PoC★ 2
DarokNET/CVE-2023-27100
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22
48RISCO
abrir ↗GitHub PoC★ 1
POC,EXP,chatGPT for me,只能给一些思路,全部不可用
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
48RISCO
abrir ↗GitHub PoC★ 2
POC,EXP,chatGPT for me
Apache MINA SSHD: Java unsafe deserialization vulnerability
48RISCO
abrir ↗GitHub PoC
jedai47/CVE-2018-7273
In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables usi
23RISCO
abrir ↗GitHub PoC
jedai47/CVE-2017-16994
The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, w
23RISCO
abrir ↗GitHub PoC
qaisarafridi/cve-2021-3129
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗GitHub PoC★ 8
GoAnywhere MFT CVE-2023-0669 LicenseResponseServlet Deserialization Vulnerabilities Python RCE PoC(Proof of Concept)
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RISCO
abrir ↗GitHub PoC★ 6
CVE-2023-22809 Linux Sudo
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir ↗GitHub PoC
BaconCriCRi/PoC-CVE-2022-4939-
WCFM Membership <= 2.10.0 - Unauthenticated Privilege Escalation
48RISCO
abrir ↗GitHub PoC★ 1
CVE-2023-23752
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗GitHub PoC★ 1
LHXHL/Minio-CVE-2023-28432
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir ↗GitHub PoC★ 2
CVE-2014-6287
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir ↗GitHub PoC
docker for CVE-2022-42889
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗GitHub PoC★ 3
brosck/CVE-2006-3392
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RISCO
abrir ↗GitHub PoC★ 7
Poc for CVE-2023-23752
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗GitHub PoC★ 2
my python poc CVE-2023-24774 and CVE-2023-24775 this sqli cve funadmin
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member
53RISCO
abrir ↗GitHub PoC★ 1
A vulnerable Spring Boot application that uses log4j and is vulnerable to CVE-2021-44228, CVE-2021-44832, CVE-2021-45046 and CVE-2021-45105
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC
Struts2 S2-061 远程命令执行漏洞(CVE-2020-17530)
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISCO
abrir ↗GitHub PoC
exploit for CVE-2021-22911 in rust
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISCO
abrir ↗GitHub PoC★ 8
BoxBilling<=4.22.1.5 - Remote Code Execution (RCE)
Unrestricted Upload of File with Dangerous Type in boxbilling/boxbilling
53RISCO
abrir ↗GitHub PoC★ 1
WARNING: This is a vulnerable application to test the exploit for the Cacti command injection (CVE-2022-46169). Run it at your own risk!
Unauthenticated Command Injection
100RISCO
abrir ↗GitHub PoC
lionelmusonza/CVE-2023-26866
GreenPacket OH736's WR-1200 Indoor Unit, OT-235 with firmware versions M-IDU-1.6.0.3_V1.1 and MH-46360-2.0.3-R5-GP respe
48RISCO
abrir ↗GitHub PoC★ 3
CVE-2023-23397漏洞的简单PoC,有效载荷通过电子邮件发送。
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC
webmin <=1.920 - RCE via command injection vulnerability
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir ↗GitHub PoC★ 1
ZCBS/ZBBS/ZPBS v4.14k - Reflected XSS
ZCBS Zijper Collectie Beheer Systeem (ZCBS), Zijper Publication Management System (ZPBS), and Zijper Image Bank Manageme
33RISCO
abrir ↗GitHub PoC
turnernator1/Node.js-CVE-2017-5941
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISCO
abrir ↗GitHub PoC★ 10
CVE-2023-28432 MinIO敏感信息泄露检测脚本
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir ↗GitHub PoC★ 1
Full LPE Exploit for CVE-2019-5596 / FreeBSD-SA-19:02.fd
In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEAS
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.