Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.449exploits catalogados
35.552CVEs com exploração pública
24.695testados em laboratório
77.449 exploits
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALsob ataqueransomware14 mar 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Batch scanning site.
CVE-2020-3187CRITICAL14 mar 2023
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RISCO
abrir
GitHub PoC4
A Tool for scanning CVE-2017-9841 with multithread
CVE-2017-9841CRITICALsob ataque13 mar 2023
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALsob ataque13 mar 2023
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISCO
abrir
GitHub PoC1
Syd-SydneyJr/CVE-2021-45010
CVE-2021-4501013 mar 2023
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7
45RISCO
abrir
Metasploit600
PaperCut PaperCutNG Authentication Bypass
CVE-2023-27350CRITICALsob ataqueransomware13 mar 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir
Metasploit600
Lexmark Device Embedded Web Server RCE
CVE-2023-26068CRITICAL13 mar 2023
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).
68RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALsob ataque13 mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
GitHub PoC4
CVE-2022-22963 RCE PoC in python
CVE-2022-22963CRITICALsob ataque13 mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
GitHub PoC1
Demonstrable Proof of Concept Exploit for Spring4Shell Vulnerability (CVE-2022-22965)
CVE-2022-22965CRITICALsob ataque12 mar 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC26
CVE-2023-21839工具
CVE-2023-21839HIGHsob ataque11 mar 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISCO
abrir
GitHub PoC1
Laravel RCE CVE-2021-3129
CVE-2021-3129CRITICALsob ataqueransomware11 mar 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC15
This is poc of CVE-2022-46169 authentication bypass and remote code execution
CVE-2022-46169CRITICALsob ataque11 mar 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC
h1bAna/CVE-2017-5123
CVE-2017-512311 mar 2023
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALsob ataqueransomware11 mar 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC
python 2.7
CVE-2023-23752MEDIUMsob ataque11 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
GitHub PoC
ahiahai242/CVE-2017-5123
CVE-2017-512311 mar 2023
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALsob ataque11 mar 2023
Unauthenticated Command Injection
100RISCO
abrir
VulnCheck XDB
local
CVE-2022-21894MEDIUM11 mar 2023
Secure Boot Security Feature Bypass Vulnerability
33RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMsob ataque11 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
GitHub PoC
Microsoft Word 远程代码执行漏洞
CVE-2023-21716CRITICAL10 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC
FortiRecorder Denial of Service Exploit (CVE-2022-41333)
CVE-2022-41333MEDIUM10 mar 2023
An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below
33RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-12615HIGHsob ataqueransomware10 mar 2023
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir
GitHub PoC11
Tomcat PUT方法任意文件写入(CVE-2017-12615)exp
CVE-2017-12615HIGHsob ataqueransomware10 mar 2023
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir
VulnCheck XDB
local
CVE-2023-21768HIGH10 mar 2023
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISCO
abrir
GitHub PoC4
CVE-­2021­-1732 Microsoft Windows 10 本地提权漏 研究及Poc/Exploit开发
CVE-2021-1732HIGHsob ataqueransomware09 mar 2023
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC7
Bulk scanner + get config from CVE-2023-23752
CVE-2023-23752MEDIUMsob ataque09 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
VulnCheck XDB
local
CVE-2022-37969HIGHsob ataque09 mar 2023
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC2
开源,go多并发批量探测poc,准确率高
CVE-2023-23752MEDIUMsob ataque09 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
GitHub PoC2
CVE-2019-15107 图形化测试程序
CVE-2019-15107CRITICALsob ataqueransomware09 mar 2023
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
anteriorpágina 519 / 2.582próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.