Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.813exploits catalogados
35.788CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.455Referência 22.549GitHub PoC 14.290VulnCheck XDB 8.722Nuclei 4.320Metasploit 3.477✓ só verificadosrecentespopularesrisco
77.813 exploits
VulnCheck XDB
client-side
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir ↗Exploit-DB
VUPlayer 2.49 - '.wax' Local Buffer Overflow (DEP Bypass)
Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in
50RISCO
abrir ↗VulnCheck XDB
initial-access
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3
83RISCO
abrir ↗GitHub PoC★ 5
lsw29475/CVE-2020-9715
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3
83RISCO
abrir ↗VulnCheck XDB
infoleak
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗VulnCheck XDB
initial-access
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC★ 2
h3x0v3rl0rd/CVE-2018-16763
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir ↗VulnCheck XDB
initial-access
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir ↗GitHub PoC★ 2
Log4jshell - CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗VulnCheck XDB
initial-access
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISCO
abrir ↗Exploit-DB
Nettmp NNT 5.1 - SQLi Authentication Bypass
Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel
23RISCO
abrir ↗Exploit-DB
WordPress Plugin WP Visitor Statistics 4.7 - SQL Injection
WP Visitor Statistics (Real Time Traffic) < 4.8 - Subscriber+ SQL Injection
50RISCO
abrir ↗Exploit-DB
ConnectWise Control 19.2.24707 - Username Enumeration
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumer
28RISCO
abrir ↗Exploit-DB
SAFARI Montage 8.5 - Reflected Cross Site Scripting (XSS)
Reflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScrip
23RISCO
abrir ↗Exploit-DB
Gerapy 0.9.7 - Remote Code Execution (RCE) (Authenticated)
Gerapy may contain remote code execution vulnerability
60RISCO
abrir ↗Exploit-DB
WordPress Plugin The True Ranker 2.2.2 - Arbitrary File Read (Unauthenticated)
True Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read
78RISCO
abrir ↗GitHub PoC
alexpena5635/CVE-2021-44228_scanner-main-Modified-
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗Exploit-DB
Automox Agent 32 - Local Privilege Escalation
Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory.
23RISCO
abrir ↗GitHub PoC
the name of virus is the detection of microsoft defender, is the tipic antivirus
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir ↗GitHub PoC
Atmail XSS-CSRF-RCE Exploit Chain
Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote atta
23RISCO
abrir ↗GitHub PoC
Bassmaster Plugin NodeJS RCE
Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for t
60RISCO
abrir ↗GitHub PoC
Log4j2 LDAP 취약점 테스트 (CVE-2021-44228)
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC
the name of virus is the detection of microsoft defender, is the tipic antivirus
The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls
100RISCO
abrir ↗GitHub PoC★ 9
darkpills/CVE-2021-25094-tatsu-preauth-rce
Tatsu < 3.3.12 - Unauthenticated RCE
60RISCO
abrir ↗GitHub PoC
This repository contains a Spring Boot web application vulnerable to CVE-2021-44228, known as log4shell.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC★ 1
Presents how to exploit CVE-2021-44228 vulnerability.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗VulnCheck XDB
initial-access
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗VulnCheck XDB
initial-access
SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailing
50RISCO
abrir ↗GitHub PoC★ 4
Auerswald VoIP System Secret Backdoors -PoC
Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.