Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.401exploits catalogados
35.511CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.332GitHub PoC 14.209VulnCheck XDB 8.646Nuclei 4.289Metasploit 3.474✓ só verificadosrecentespopularesrisco
77.401 exploits
GitHub PoC★ 1
Full LPE Exploit for CVE-2019-5596 / FreeBSD-SA-19:02.fd
In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEAS
23RISCO
abrir ↗VulnCheck XDB
local
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir ↗Exploit-DB
Label Studio 1.5.0 - Authenticated Server Side Request Forgery (SSRF)
A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.
23RISCO
abrir ↗Exploit-DB
Tapo C310 RTSP server v1.3.0 - Unauthorised Video Stream Access
TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed via credentials of User --- and Password TPL07552646
41RISCO
abrir ↗Exploit-DB
ReQlogic v11.3 - Reflected Cross-Site Scripting (XSS)
Multiple cross-site scripting (XSS) vulnerabilities in ReQlogic v11.3 allow attackers to execute arbitrary web scripts o
48RISCO
abrir ↗Exploit-DB
ZKTeco ZEM/ZMM 8.88 - Missing Authentication
Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct r
41RISCO
abrir ↗Exploit-DB
OPSWAT Metadefender Core - Privilege Escalation
OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5
23RISCO
abrir ↗Exploit-DB
Pega Platform 8.1.0 - Remote Code Execution (RCE)
If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Inte
53RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BoxBilling<=4.22.1.5 - Remote Code Execution (RCE)
Unrestricted Upload of File with Dangerous Type in boxbilling/boxbilling
53RISCO
abrir ↗Exploit-DB
X-Skipper-Proxy v0.13.237 - Server Side Request Forgery (SSRF)
Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
53RISCO
abrir ↗GitHub PoC
cyberdesu/Remote-Buffer-overflow-CVE-2003-0172
Buffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes, allows remote at
28RISCO
abrir ↗VulnCheck XDB
initial-access
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8
85RISCO
abrir ↗GitHub PoC★ 2
通过vulhub的复现过程实现了,基本的批量检测。比较垃圾但是勉强能用
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir ↗VulnCheck XDB
initial-access
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Grafana <=6.2.4 - HTML Injection
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
CSRF key bypass using HTTP methods in zoneminder
41RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
Stored Cross-Site Scripting Vulnerability In File Parameter in zoneminder
41RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
Denial of service through logs in zoneminder
33RISCO
abrir ↗GitHub PoC
Bash Script for Checking Command Injection Vulnerability on CentOS Web Panel [CWP] (CVE-2022-44877)
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISCO
abrir ↗Exploit-DB
FortiOS_ FortiProxy_ FortiSwitchManager v7.2.1 - Authentication Bypass
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir ↗GitHub PoC★ 3
Arbitrary File Disclosure Vulnerability in Icinga Web 2 <2.8.6, <2.9.6, <2.10
Path traversal in Icinga Web 2
78RISCO
abrir ↗GitHub PoC
PoC for CVE-2022-39952 affecting Fortinet FortiNAC.
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8
85RISCO
abrir ↗GitHub PoC★ 319
EXP for CVE-2023-28434 MinIO unauthorized to RCE
MinIO is vulnerable to privilege escalation on Linux/MacOS
71RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
MinIO is vulnerable to privilege escalation on Linux/MacOS
71RISCO
abrir ↗GitHub PoC★ 5
0xNahim/CVE-2023-23752
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗GitHub PoC★ 3
Unauthenticated RCE in Open Web Analytics version <1.7.4
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.