Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.302exploits catalogados
35.469CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.301GitHub PoC 14.141VulnCheck XDB 8.646Nuclei 4.289Metasploit 3.474✓ só verificadosrecentespopularesrisco
77.302 exploits
GitHub PoC★ 1
isacaya/CVE-2019-11358
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RISCO
abrir ↗VulnCheck XDB
client-side
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISCO
abrir ↗VulnCheck XDB
infoleak
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2;
50RISCO
abrir ↗GitHub PoC★ 3
This repo hosts TUKRU's Linux Privilege Escalation exploit (CVE-2021-22555). It demonstrates gaining root privileges via a vulnerability. Tested on Ubuntu 5.8.0-48-generic and COS 5.4.89+. Use responsibly and ethically.
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISCO
abrir ↗Exploit-DB
PHPJabbers Taxi Booking 2.0 - Reflected XSS
PHP Jabbers Taxi Booking index.php cross site scripting
48RISCO
abrir ↗GitHub PoC★ 2
CVE-2023-37979 PoC and Checker
WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
56RISCO
abrir ↗Exploit-DB
PHPJabbers Rental Property Booking 2.0 - Reflected XSS
PHP Jabbers Rental Property Booking index.php cross site scripting
33RISCO
abrir ↗GitHub PoC
# Exploit Title: Pluck CMS 4.7.16 - Remote Code Execution (RCE) (Authenticated) # Date: 13.03.2022 # Exploit Author: Ashish Koli (Shikari) # Vendor Homepage: https://github.com/pluck-cms/pluck # Version: 4.7.16 # Tested on Ubuntu 20.04.3 LTS # CVE: CVE-2022-26965
In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remot
35RISCO
abrir ↗Exploit-DB
Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Event Access
EventON < 2.1.2 - Unauthenticated Event Access
50RISCO
abrir ↗Exploit-DB
PHPJabbers Night Club Booking 1.0 - Reflected XSS
PHP Jabbers Night Club Booking Software index.php cross site scripting
48RISCO
abrir ↗Exploit-DB
Shelly PRO 4PM v0.11.0 - Authentication Bypass
Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition t
23RISCO
abrir ↗GitHub PoC
Vulnerable environment of CVE-2020-17530 (S2-061) for testing
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISCO
abrir ↗Exploit-DB
PHPJabbers Shuttle Booking Software 1.0 - Reflected XSS
PHP Jabbers Shuttle Booking Software index.php cross site scripting
48RISCO
abrir ↗Exploit-DB
PHPJabbers Cleaning Business 1.0 - Reflected XSS
PHP Jabbers Cleaning Business index.php cross site scripting
48RISCO
abrir ↗Exploit-DB
PHPJabbers Service Booking Script 1.0 - Reflected XSS
PHP Jabbers Service Booking Script index.php cross site scripting
48RISCO
abrir ↗Exploit-DB
Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Post Access via IDOR
EventON < 2.1.2 - Unauthenticated Post Access via IDOR
38RISCO
abrir ↗Exploit-DB
WordPress Plugin Ninja Forms 3.6.25 - Reflected XSS
WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
56RISCO
abrir ↗GitHub PoC★ 4
Remote Unauthenticated API Access Vulnerability in MobileIron Core 11.2 and older
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted fu
100RISCO
abrir ↗VulnCheck XDB
initial-access
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted fu
100RISCO
abrir ↗GitHub PoC
Vulnerable environment of CVE-2013-2251 (S2-016) for testing
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a
100RISCO
abrir ↗Metasploit600
LG Simple Editor Command Injection (CVE-2023-40504)
LG Simple Editor readVideoInfo Command Injection Remote Code Execution Vulnerability
65RISCO
abrir ↗VulnCheck XDB
initial-access
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISCO
abrir ↗GitHub PoC
726232111/CVE-2023-28252
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RISCO
abrir ↗GitHub PoC
overgrowncarrot1/DejaVu-CVE-2021-22205
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir ↗VulnCheck XDB
initial-access
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir ↗GitHub PoC★ 3
Python Interactive Exploit for WP File Manager Vulnerability. The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension.
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISCO
abrir ↗VulnCheck XDB
initial-access
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.