Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.813exploits catalogados
35.788CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.455Referência 22.549GitHub PoC 14.290VulnCheck XDB 8.722Nuclei 4.320Metasploit 3.477✓ só verificadosrecentespopularesrisco
77.813 exploits
GitHub PoC★ 27
Oracle WebLogic Server 12.1.3.0.0 / 12.2.1.3.0 / 12.2.1.4.0 / 14.1.1.0.0 Local File Inclusion
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
78RISCO
abrir ↗Exploit-DB
PHPIPAM 1.4.4 - SQLi (Authenticated)
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su
28RISCO
abrir ↗Metasploit600
Local Privilege Escalation in polkits pkexec
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗VulnCheck XDB
local
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗VulnCheck XDB
client-side
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir ↗VulnCheck XDB
infoleak
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
78RISCO
abrir ↗VulnCheck XDB
local
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗GitHub PoC
Exploit-WordPress Plugin The True Ranker 2.2.2 - Arbitrary File Read
True Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read
78RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISCO
abrir ↗GitHub PoC★ 2
Strapi CMS 3.0.0-beta.17.4 - Unauthenticated Remote Code Execution (CVE-2019-18818, CVE-2019-19609)
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISCO
abrir ↗Metasploit300
Wordpress RegistrationMagic task_ids Authenticated SQLi
RegistrationMagic < 5.0.1.6 - Admin+ SQL Injection
60RISCO
abrir ↗GitHub PoC★ 28
CVE-2022-21907 Vulnerability PoC
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 1
jcarabantes/CVE-2022-23046
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su
28RISCO
abrir ↗Metasploit600
Apache Couchdb Erlang RCE
Remote Code Execution Vulnerability in Packaging
100RISCO
abrir ↗GitHub PoC★ 5
test 反向辣鸡数据投放 CVE-2022-23305 工具 利用 教程 Exploit POC
SQL injection in JDBC Appender in Apache Log4j V1
60RISCO
abrir ↗VulnCheck XDB
initial-access
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, coul
100RISCO
abrir ↗VulnCheck XDB
initial-access
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISCO
abrir ↗Metasploit600
Oracle Access Manager unauthenticated Remote Code Execution
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported ver
100RISCO
abrir ↗GitHub PoC★ 24
💀 Linux local root exploit for CVE-2018-18955
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISCO
abrir ↗VulnCheck XDB
local
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RISCO
abrir ↗GitHub PoC★ 375
CVE-2022-0185
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RISCO
abrir ↗VulnCheck XDB
initial-access
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗Exploit-DB
Creston Web Interface 1.0.0.2159 - Credential Disclosure
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI
60RISCO
abrir ↗VulnCheck XDB
initial-access
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir ↗GitHub PoC★ 83
Proof of concept of CVE-2022-21907 Double Free in http.sys driver, triggering a kernel crash on IIS servers
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.