Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.449exploits catalogados
35.552CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.367GitHub PoC 14.225VulnCheck XDB 8.649Nuclei 4.283Metasploit 3.474✓ só verificadosrecentespopularesrisco
77.449 exploits
VulnCheck XDB
infoleak
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗VulnCheck XDB
infoleak
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗VulnCheck XDB
local
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir ↗GitHub PoC★ 4
CVE-2021-1732 Microsoft Windows 10 本地提权漏 研究及Poc/Exploit开发
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC★ 7
Mass Auto Exploit CVE-2022-4395 Unauthenticated Arbitrary File Upload
Membership For WooCommerce < 2.1.7 - Unauthenticated Arbitrary File Upload
53RISCO
abrir ↗GitHub PoC★ 135
Windows LPE exploit for CVE-2022-37969
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir ↗GitHub PoC★ 4
Open Web Analytics 1.7.3 - Remote Code Execution
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISCO
abrir ↗GitHub PoC★ 2
Tenda f3 Malformed HTTP Request Header Processing Vulnerability.
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RISCO
abrir ↗GitHub PoC★ 4
SSH User Enumerator in Python3, CVE-2018-15473, I updated the code of this exploit (https://www.exploit-db.com/exploits/45939) to work with python3 instead of python2.
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir ↗GitHub PoC
sei-fish/CVE-2021-22205
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir ↗VulnCheck XDB
infoleak
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RISCO
abrir ↗VulnCheck XDB
client-side
Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a
83RISCO
abrir ↗GitHub PoC
Results of retrohunt for files matching YARA rules from https://github.com/AmgdGocha/Detection-Rules/blob/main/CVE-2023-21716.yar
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 59
A vulnerability within Microsoft Office's wwlib allows attackers to achieve remote code execution with the privileges of the victim that opens a malicious RTF document. The attacker could deliver this file as an email attachment (or other means).
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 4
FeatherStark/CVE-2023-21716
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC
adriyansyah-mf/CVE-2023-23752
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗VulnCheck XDB
initial-access
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir ↗VulnCheck XDB
client-side
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RISCO
abrir ↗VulnCheck XDB
infoleak
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗VulnCheck XDB
local
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISCO
abrir ↗GitHub PoC★ 46
RTF Crash POC Python 3.11 Windows 10
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir ↗VulnCheck XDB
initial-access
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISCO
abrir ↗GitHub PoC
Script in Ruby for the CVE-2022-35914 - RCE in GLPI
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISCO
abrir ↗GitHub PoC★ 8
spring cloud function 一键利用工具! by charis 博客https://charis3306.top/
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir ↗Metasploit600
Pretalx Limited File Write to Remote Code Execution
pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Organizers can trigger the over
28RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.