Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.302exploits catalogados
35.469CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.301GitHub PoC 14.141VulnCheck XDB 8.646Nuclei 4.289Metasploit 3.474✓ só verificadosrecentespopularesrisco
77.302 exploits
VulnCheck XDB
initial-access
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir ↗Exploit-DB
Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 64-bit - Remote Code Execution (RCE)
Microsoft Office Remote Code Execution Vulnerability
41RISCO
abrir ↗GitHub PoC★ 1
Expoit for CVE-2022-44268
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISCO
abrir ↗GitHub PoC★ 6
Perform With Massive Openfire Unauthenticated Users
Openfire administration console authentication bypass
100RISCO
abrir ↗Metasploit600
OpenNMS Horizon Authenticated RCE
ROLE_FILESYSTEM_EDITOR Can Be Used To Escalate To ROLE_ADMIN
28RISCO
abrir ↗Metasploit600
OpenTSDB 2.4.1 unauthenticated command injection
Remote Code Execution in OpenTSDB
68RISCO
abrir ↗Metasploit600
OpenNMS Horizon Authenticated RCE
ROLE_REST can be used to escalate to ROLE_ADMIN via /rest/users
36RISCO
abrir ↗Metasploit600
OpenTSDB 2.4.1 unauthenticated command injection
Remote Code Execution in OpenTSDB
75RISCO
abrir ↗GitHub PoC★ 5
Exploitation of "Shellshock" Vulnerability. Remote code execution in Apache with mod_cgi
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗VulnCheck XDB
initial-access
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir ↗GitHub PoC
spip
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir ↗GitHub PoC★ 9
WordPress社交登录和注册(Discord,Google,Twitter,LinkedIn)<=7.6.4-绕过身份验证
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RISCO
abrir ↗GitHub PoC★ 11
Decrypt reversible secrets encrypted using the default hardcoded key related to CVE-2020-9289 on FortiAnalyzer/FortiManager (the only difference with CVE-2019-6693 is the encryption routine).
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke
63RISCO
abrir ↗VulnCheck XDB
local
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writin
43RISCO
abrir ↗VulnCheck XDB
initial-access
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RISCO
abrir ↗VulnCheck XDB
initial-access
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RISCO
abrir ↗VulnCheck XDB
infoleak
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗VulnCheck XDB
initial-access
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC★ 82
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RISCO
abrir ↗GitHub PoC
yangshifan-git/CVE-2021-1732
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC★ 4
Using this tool, you can scan for remote command execution vulnerability CVE-2021-44228 on Apache Log4j at multiple addresses.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC★ 1
Hamesawian/CVE-2021-42013
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗VulnCheck XDB
local
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir ↗VulnCheck XDB
initial-access
Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashSe
50RISCO
abrir ↗VulnCheck XDB
local
Distros-[dirtyvma] privilege escalation via non-rcu-protected vma traversal
41RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
Formidable Forms < 6.3.1 - Subscriber+ Remote Code Execution
28RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.