Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
13.727 exploits
GitHub PoC7
The official exploit for Froxlor Remote Code Execution CVE-2023-0315
CVE-2023-0315HIGH29 jan 2023
Command Injection in froxlor/froxlor
78RISCO
abrir
GitHub PoC
windows 10 SMB vulnerability
CVE-2020-0796CRITICALsob ataqueransomware29 jan 2023
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC
This is a vulnerability in the Linux kernel that was discovered and disclosed in 2017.
CVE-2017-548729 jan 2023
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RISCO
abrir
GitHub PoC
Exploit for CVE-2022-40684 vulnerability
CVE-2022-40684CRITICALsob ataqueransomware28 jan 2023
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir
GitHub PoC
This script implements a lab automation where I exploit CVE-2021-43798 to steal user secrets and then gain privileges on a Linux system.
CVE-2021-43798HIGHsob ataque28 jan 2023
Grafana path traversal
100RISCO
abrir
GitHub PoC2
In Paradox Security System IPR512 web panel, an unauthenticated user can input JavaScript string, such as </script> that will overwrite configurations in the file "login.xml" and cause the login form to crash and make it unavailable.
CVE-2023-24709HIGH26 jan 2023
An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and l
53RISCO
abrir
GitHub PoC1
Relativ3Pa1n/CVE-2014-2383-LFI-to-RCE-Escalation
CVE-2014-238326 jan 2023
dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroo
50RISCO
abrir
GitHub PoC
vulnerabilities, CVE-2022-41903, and CVE-2022-23521, that affect versions 2.39 and older. Git for Windows was also patched to address an additional, Windows-specific issue known as CVE-2022-41953.
CVE-2022-41903CRITICAL26 jan 2023
Integer overflow in `git archive`, `git log --format` leading to RCE in git
60RISCO
abrir
GitHub PoC2
DDoS Tool which exploits vulnerability CVE-2004-2449 from vendor GameSpy (now known as OpenSpy). User is prompted for input IP address, and port. (NOTE: Please use this responsibly, I made this as a proof of concept of vulnerability exploitation ONLY. I do not endorse DOSing, DDoSing, or cheating in any way. Use this at your own risk.)
CVE-2004-244925 jan 2023
Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier allows remote attackers to cause a denial
23RISCO
abrir
GitHub PoC6
A proof of concept exploit for a wordpress 5.6 media library vulnerability
CVE-2021-29447HIGH24 jan 2023
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir
GitHub PoC2
Drity Pipe Linux Kernel 1-Day Exploit
CVE-2022-0847HIGHsob ataque24 jan 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC1
A pwnkit N-Day exploit
CVE-2021-4034HIGHsob ataque24 jan 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
it is the official Fix of Wordpress CVE-2018-6389.
CVE-2018-638923 jan 2023
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISCO
abrir
GitHub PoC7
The manage engine mass loader for CVE-2022-47966
CVE-2022-47966CRITICALsob ataqueransomware23 jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISCO
abrir
GitHub PoC8
A critical command injection vulnerability was found in multiple API endpoints of the Atlassian Bit bucket Server and Data center. This vulnerability affects all versions of Bitbucket Server and Data Center released before versions <7.6.17, <7.17.10, <7.21.4, <8.0.3, <8.1.2, <8.2.2, and <8.3.1
CVE-2022-36804HIGHsob ataque23 jan 2023
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
GitHub PoC2
Run on your ManageEngine server
CVE-2022-47966CRITICALsob ataqueransomware23 jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISCO
abrir
GitHub PoC28
Python scanner for CVE-2022-47966. Supports ~10 of the 24 affected products.
CVE-2022-47966CRITICALsob ataqueransomware23 jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISCO
abrir
GitHub PoC6
Python exploit for RCE in Wordpress
CVE-2020-25213CRITICALsob ataque22 jan 2023
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISCO
abrir
GitHub PoC165
A script to automate privilege escalation with CVE-2023-22809 vulnerability
CVE-2023-22809HIGH21 jan 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir
GitHub PoC1
Demo webapp vulnerable to CVE-2022-44900
CVE-2022-44900CRITICAL21 jan 2023
A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and ea
48RISCO
abrir
GitHub PoC4
Remote Code Execution in Social Warfare Plugin before 3.5.3 for Wordpress.
CVE-2019-9978MEDIUMsob ataque20 jan 2023
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
GitHub PoC
PoC for cve-2022-47966
CVE-2022-47966CRITICALsob ataqueransomware19 jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISCO
abrir
GitHub PoC1
test for the ioc described for FG-IR-22-398
CVE-2022-42475CRITICALsob ataqueransomware17 jan 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISCO
abrir
GitHub PoC
Project for the Cyberspace Security class.
CVE-2017-891717 jan 2023
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISCO
abrir
GitHub PoC
notareaperbutDR34P3r/CVE-2022-40684-Rust
CVE-2022-40684CRITICALsob ataqueransomware17 jan 2023
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir
GitHub PoC129
POC for CVE-2022-47966 affecting multiple ManageEngine products
CVE-2022-47966CRITICALsob ataqueransomware17 jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISCO
abrir
GitHub PoC2
CVE-2014-5460
CVE-2014-546017 jan 2023
Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remot
60RISCO
abrir
GitHub PoC2
A POC on how to exploit CVE-2022-27518
CVE-2022-27518CRITICALsob ataque17 jan 2023
Unauthenticated remote arbitrary code execution
78RISCO
abrir
GitHub PoC
Exploit For OverlayFS
CVE-2021-3493HIGHsob ataque16 jan 2023
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir
GitHub PoC3
RCE POC for CVE-2022-46169
CVE-2022-46169CRITICALsob ataque16 jan 2023
Unauthenticated Command Injection
100RISCO
abrir
anteriorpágina 284 / 458próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.