Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.107exploits catalogados
34.679CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.692GitHub PoC 13.812VulnCheck XDB 8.460Nuclei 4.233Metasploit 3.467✓ só verificadosrecentespopularesrisco
13.812 exploits
GitHub PoC
CVE-2022-26809-RCE
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 5
mariomamo/CVE-2022-22965
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir ↗GitHub PoC
A python script/generator, for generating and exploiting Microsoft vulnerability
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir ↗GitHub PoC
This repository contains a PoC for remote code execution CVE-2022-26809
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 1
0xAgun/CVE-2022-29464
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir ↗GitHub PoC★ 5
cve-2022-29464 批量脚本
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir ↗GitHub PoC★ 5
WSO2 RCE (CVE-2022-29464)
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir ↗GitHub PoC★ 3
Repository containing nse script for vulnerability CVE-2022-29464 known as WSO2 RCE.
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir ↗GitHub PoC★ 2
Pre-auth RCE bug CVE-2022-29464
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir ↗GitHub PoC★ 2
tufanturhan/wso2-rce-cve-2022-29464
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir ↗GitHub PoC★ 1
c4mx/CVE-2022-22965_PoC
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir ↗GitHub PoC★ 1
Phantomlancer123/CVE-2017-0199
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir ↗GitHub PoC
MS CVE 2019-0708 Python Exploit
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir ↗GitHub PoC
CVE-2021-4034 PoC
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗GitHub PoC★ 377
WSO2 RCE (CVE-2022-29464) exploit and writeup.
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir ↗GitHub PoC
CVE-2017-9841批量扫描及利用脚本。PHPUnit是其中的一个基于PHP的测试框架。 PHPUnit 4.8.28之前的版本和5.6.3之前的5.x版本中的Util/PHP/eval-stdin.php文件存在安全漏洞。远程攻击者可通过发送以‘<?php’字符串开头的HTTP POST数据利用该漏洞执行任意PHP代码。
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISCO
abrir ↗GitHub PoC
ms15-034 or CVE-2015-1635 批量扫描
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISCO
abrir ↗GitHub PoC
CVE-2019-15107
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir ↗GitHub PoC
CVE-2021-42013 - Apache 2.4.50
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗GitHub PoC★ 2
Watchguard RCE POC CVE-2022-26318
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulner
100RISCO
abrir ↗GitHub PoC★ 9
Scripted Linux Privilege Escalation for the CVE-2022-0847 "Dirty Pipe" vulnerability
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir ↗GitHub PoC★ 1
CVE-2015-1635-POC,指定IP与端口验证HTTP.sys漏洞是否存在
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISCO
abrir ↗GitHub PoC
mhurts/CVE-2022-22954-POC
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir ↗GitHub PoC★ 2
Repository containing nse script for vulnerability CVE-2022-21907. It is a component (IIS) vulnerability on Windows. It allows remote code execution. The vulnerability affects the kernel module http. sys, which handles most basic IIS operations.
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 53
Exploit for CVE-2021-22204 (ExifTool) - Arbitrary Code Execution
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISCO
abrir ↗GitHub PoC★ 148
Laravel RCE Exploit PoC - CVE-2021-3129 (user-friendly with automatic log path detection)
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗GitHub PoC★ 2
tufanturhan/CVE-2022-21971-Windows-Runtime-RCE
Windows Runtime Remote Code Execution Vulnerability
83RISCO
abrir ↗GitHub PoC★ 4
CVE-2022-22954 VMware Workspace ONE Access free marker SSTI
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir ↗GitHub PoC
tufanturhan/CVE-2022-0847-L-nux-PrivEsc
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir ↗GitHub PoC★ 11
Spring Cloud Gateway Actuator API SpEL Code Injection (CVE-2022-22947)
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.