Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.001exploits catalogados
34.636CVEs com exploração pública
24.695testados em laboratório
13.736 exploits
GitHub PoC1
WARNING: This is a vulnerable application to test the exploit for the Cacti command injection (CVE-2022-46169). Run it at your own risk!
CVE-2022-46169CRITICALsob ataque01 abr 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC
lionelmusonza/CVE-2023-26866
CVE-2023-26866CRITICAL01 abr 2023
GreenPacket OH736's WR-1200 Indoor Unit, OT-235 with firmware versions M-IDU-1.6.0.3_V1.1 and MH-46360-2.0.3-R5-GP respe
48RISCO
abrir
GitHub PoC8
BoxBilling<=4.22.1.5 - Remote Code Execution (RCE)
CVE-2022-3552HIGH01 abr 2023
Unrestricted Upload of File with Dangerous Type in boxbilling/boxbilling
53RISCO
abrir
GitHub PoC
webmin <=1.920 - RCE via command injection vulnerability
CVE-2019-15107CRITICALsob ataqueransomware31 mar 2023
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC3
CVE-2023-23397漏洞的简单PoC,有效载荷通过电子邮件发送。
CVE-2023-23397CRITICALsob ataque31 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC1
ZCBS/ZBBS/ZPBS v4.14k - Reflected XSS
CVE-2023-26692MEDIUM30 mar 2023
ZCBS Zijper Collectie Beheer Systeem (ZCBS), Zijper Publication Management System (ZPBS), and Zijper Image Bank Manageme
33RISCO
abrir
GitHub PoC
turnernator1/Node.js-CVE-2017-5941
CVE-2017-594130 mar 2023
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISCO
abrir
GitHub PoC1
Full LPE Exploit for CVE-2019-5596 / FreeBSD-SA-19:02.fd
CVE-2019-559629 mar 2023
In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEAS
23RISCO
abrir
GitHub PoC
0759104103/cd-CVE-2019-11932
CVE-2019-1193229 mar 2023
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISCO
abrir
GitHub PoC
jacquesquail/CVE-2023-23397
CVE-2023-23397CRITICALsob ataque29 mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC10
CVE-2023-28432 MinIO敏感信息泄露检测脚本
CVE-2023-28432HIGHsob ataque29 mar 2023
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir
GitHub PoC
cyberdesu/Remote-Buffer-overflow-CVE-2003-0172
CVE-2003-017228 mar 2023
Buffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes, allows remote at
28RISCO
abrir
GitHub PoC319
EXP for CVE-2023-28434 MinIO unauthorized to RCE
CVE-2023-28434HIGHsob ataque27 mar 2023
MinIO is vulnerable to privilege escalation on Linux/MacOS
71RISCO
abrir
GitHub PoC2
通过vulhub的复现过程实现了,基本的批量检测。比较垃圾但是勉强能用
CVE-2023-28432HIGHsob ataque27 mar 2023
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir
GitHub PoC
PoC for CVE-2022-39952 affecting Fortinet FortiNAC.
CVE-2022-39952CRITICAL27 mar 2023
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8
85RISCO
abrir
GitHub PoC
Bash Script for Checking Command Injection Vulnerability on CentOS Web Panel [CWP] (CVE-2022-44877)
CVE-2022-44877CRITICALsob ataque27 mar 2023
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISCO
abrir
GitHub PoC3
Arbitrary File Disclosure Vulnerability in Icinga Web 2 <2.8.6, <2.9.6, <2.10
CVE-2022-24716HIGH27 mar 2023
Path traversal in Icinga Web 2
78RISCO
abrir
GitHub PoC1
pfBlockerNG <= 2.1.4_26 Unauth RCE (CVE-2022-31814)
CVE-2022-31814CRITICAL26 mar 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir
GitHub PoC3
pfBlockerNG <= 2.1.4_26 Unauth RCE (CVE-2022-31814)
CVE-2022-31814CRITICAL26 mar 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir
GitHub PoC1
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information.
CVE-2019-1653HIGHsob ataque26 mar 2023
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISCO
abrir
GitHub PoC3
Unauthenticated RCE in Open Web Analytics version <1.7.4
CVE-2022-2463726 mar 2023
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISCO
abrir
GitHub PoC5
0xNahim/CVE-2023-23752
CVE-2023-23752MEDIUMsob ataque26 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
GitHub PoC
pumpkinpiteam/CVE-2022-24716
CVE-2022-24716HIGH26 mar 2023
Path traversal in Icinga Web 2
78RISCO
abrir
GitHub PoC1
a simple tool to detect the exploitation of BlueKeep vulnerability (CVE-2019-0708)
CVE-2019-0708CRITICALsob ataqueransomware25 mar 2023
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC
Authenticated Remote Code Execution in Icinga Web 2 <2.8.6, <2.9.6, <2.10
CVE-2022-24715HIGH25 mar 2023
Arbitrary code execution for authenticated users in Icinga Web 2
46RISCO
abrir
GitHub PoC4
Joomla Unauthorized Access Vulnerability (CVE-2023-23752) Dockerized
CVE-2023-23752MEDIUMsob ataque25 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
GitHub PoC
Brandaoo/CVE-2014-6271
CVE-2014-6271CRITICALsob ataque25 mar 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC37
MinIO敏感信息泄露漏洞批量扫描poc&exp
CVE-2023-28432HIGHsob ataque24 mar 2023
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir
GitHub PoC7
CVE-2023-28432,minio未授权访问检测工具
CVE-2023-28432HIGHsob ataque24 mar 2023
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir
GitHub PoC15
CVE-2023-28432 POC
CVE-2023-28432HIGHsob ataque24 mar 2023
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir
anteriorpágina 277 / 458próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.