Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.284exploits catalogados
35.465CVEs com exploração pública
24.695testados em laboratório
77.231 exploits
GitHub PoC8
Automatic Mass Tool for checking vulnerability in CVE-2022-4060 - WordPress Plugin : User Post Gallery <= 2.19 - Unauthenticated RCE
CVE-2022-4060CRITICAL15 set 2023
User Post Gallery <= 2.19 - Unauthenticated RCE
75RISCO
abrir
GitHub PoC
Anthony1500/CVE-2022-40684
CVE-2022-40684CRITICALsob ataqueransomware14 set 2023
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-40684CRITICALsob ataqueransomware14 set 2023
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-1000861CRITICALsob ataque13 set 2023
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea
100RISCO
abrir
Metasploit600
Themebleed- Windows 11 Themes Arbitrary Code Execution CVE-2023-38146
CVE-2023-38146HIGH13 set 2023
Windows Themes Remote Code Execution Vulnerability
48RISCO
abrir
Metasploit600
Craft CMS unauthenticated Remote Code Execution (RCE)
CVE-2023-41892CRITICAL13 set 2023
Craft CMS Remote Code Execution vulnerability
85RISCO
abrir
GitHub PoC
CVE-2018-1000861 Exploit
CVE-2018-1000861CRITICALsob ataque13 set 2023
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea
100RISCO
abrir
GitHub PoC1
CVE-2023-43481
CVE-2023-43481CRITICAL13 set 2023
An issue in Shenzhen TCL Browser TV Web BrowseHere (aka com.tcl.browser) 6.65.022_dab24cc6_231221_gp allows a remote att
48RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-38831HIGHsob ataqueransomware12 set 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-38831HIGHsob ataqueransomware12 set 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC9
CVE-2023-38831 WinRaR Exploit Generator
CVE-2023-38831HIGHsob ataqueransomware12 set 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC3
Proof of concept (PoC) exploit for WinRAR vulnerability (CVE-2023-38831) vulnerability
CVE-2023-38831HIGHsob ataqueransomware12 set 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC2
Automatic Mass Tool for checking vulnerability in CVE-2022-4063 - InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
CVE-2022-4063CRITICAL11 set 2023
InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-1676311 set 2023
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
GitHub PoC
Development of an exploit for privilege escalation in Windows systems ( NT / 2k / XP / 2K3 / VISTA / 2k8 / 7 ) using the vulnerability CVE-2010-0232
CVE-2010-0232HIGHsob ataque11 set 2023
The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Se
91RISCO
abrir
GitHub PoC2
Automatic Mass Tool for checking vulnerability in CVE-2023-0159 - Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated LFI
CVE-2023-015911 set 2023
Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE
50RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-4063CRITICAL11 set 2023
InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-015911 set 2023
Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE
50RISCO
abrir
GitHub PoC
ช่องโหว่ CVE-2023-35674 *สถานะ: ยังไม่เสร็จ*
CVE-2023-35674HIGHsob ataque11 set 2023
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the cod
71RISCO
abrir
VulnCheck XDB
local
CVE-2010-0232HIGHsob ataque11 set 2023
The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Se
91RISCO
abrir
GitHub PoC1
Python3 exploit for Fuel CMS 1.4.1 Remote Code Execution (CVE-2018-16763) with Reverse Shell.
CVE-2018-1676311 set 2023
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALsob ataque10 set 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC
davidholiday/CVE-2007-4559
CVE-2007-4559CRITICAL10 set 2023
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows
53RISCO
abrir
GitHub PoC
0xZon/CVE-2022-46169-Exploit
CVE-2022-46169CRITICALsob ataque10 set 2023
Unauthenticated Command Injection
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-2825CRITICAL10 set 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALsob ataque10 set 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC
caopengyan/CVE-2023-2825
CVE-2023-2825CRITICAL10 set 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RISCO
abrir
GitHub PoC
simulation experiment of Curveball (CVE-2020-0601) attacks under ECQV implicit certificates with Windows-like verifiers
CVE-2020-0601HIGHsob ataque09 set 2023
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
GitHub PoC
RCE PoC for Apache Commons Text vuln
CVE-2022-4288909 set 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-1389HIGHsob ataque09 set 2023
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability i
100RISCO
abrir
anteriorpágina 465 / 2.575próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.