Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.449exploits catalogados
35.552CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.367GitHub PoC 14.225VulnCheck XDB 8.649Nuclei 4.283Metasploit 3.474✓ só verificadosrecentespopularesrisco
77.449 exploits
VulnCheck XDB
client-side
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap c
83RISCO
abrir ↗GitHub PoC
SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.
SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent chang
48RISCO
abrir ↗GitHub PoC★ 130
Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC
Arbitrary File Disclosure Vulnerability in Icinga Web 2 <2.8.6, <2.9.6, <2.10
Path traversal in Icinga Web 2
78RISCO
abrir ↗GitHub PoC★ 1
Patch for MS Outlook Critical Vulnerability - CVSS 9.8
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗Metasploit300
MinIO Bootstrap Verify Information Disclosure
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir ↗GitHub PoC
this web is vulnerable against CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC★ 1
Custom exploit written for enumerating usernames as per CVE-2016-6210
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISCO
abrir ↗VulnCheck XDB
local
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir ↗GitHub PoC★ 2
ahmedkhlief/CVE-2023-23397-POC-Using-Interop-Outlook
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗VulnCheck XDB
initial-access
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir ↗GitHub PoC★ 73
POC for Veeam Backup and Replication CVE-2023-27532
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database
93RISCO
abrir ↗Metasploit600
pfSense Restore RRD Data Command Injection
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attac
60RISCO
abrir ↗VulnCheck XDB
infoleak
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database
93RISCO
abrir ↗GitHub PoC★ 1
This script exploits a vulnerability (CVE-2021-25094) in the TypeHub WordPress plugin.
Tatsu < 3.3.12 - Unauthenticated RCE
60RISCO
abrir ↗GitHub PoC★ 1
CVE-2023-23397 C# PoC
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC★ 24
CVE-2022-22963 is a vulnerability in the Spring Cloud Function Framework for Java that allows remote code execution. This python script will verify if the vulnerability exists, and if it does, will give you a reverse shell.
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir ↗GitHub PoC★ 9
djackreuter/CVE-2023-23397-PoC
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗VulnCheck XDB
info-leak
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The
60RISCO
abrir ↗GitHub PoC★ 6
Exploit POC for CVE-2023-23397
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC★ 7
Generates meeting requests taking advantage of CVE-2023-23397. This requires the outlook thick client to send.
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.