Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.056exploits catalogados
35.925CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.640GitHub PoC 14.392VulnCheck XDB 8.755Nuclei 4.333Metasploit 3.478✓ só verificadosrecentespopularesrisco
77.900 exploits
GitHub PoC
Hunting CVE-2018-13379
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISCO
abrir ↗VulnCheck XDB
infoleak
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate
100RISCO
abrir ↗GitHub PoC★ 1
koharin/CVE-2020-0041
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
71RISCO
abrir ↗GitHub PoC★ 1
CVE-2021-40444 Sample
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 1.743
CVE-2021-40444 PoC
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC
Something I wrote for CVE-2019-15107, a Webmin backdoor
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir ↗GitHub PoC★ 3
maguireja/CVE-2020-25223
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511
100RISCO
abrir ↗GitHub PoC
Confluence OGNL injection
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir ↗GitHub PoC★ 16
rfcxv/CVE-2021-40444-POC
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 3
vysecurity/CVE-2021-40444
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC
Immersive-Labs-Sec/cve-2021-40444-analysis
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir ↗VulnCheck XDB
initial-access
ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi
100RISCO
abrir ↗GitHub PoC★ 3
CVE-2020-9054 PoC for Zyxel
ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi
100RISCO
abrir ↗GitHub PoC★ 2
Patched Confluence 7.12.2 (CVE-2021-26084)
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir ↗GitHub PoC★ 1
CVE-2021-26084 patch as provided in "Confluence Security Advisory - 2021-08-25"
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir ↗VulnCheck XDB
client-side
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir ↗VulnCheck XDB
client-side
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result
90RISCO
abrir ↗GitHub PoC★ 16
Microsoft MSHTML Remote Code Execution Vulnerability CVE-2021-40444
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 2
Exploit chain for CVE-2019-9791 & CVE-2019-11708 against firefox 65.0 on windows 64bit
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects w
28RISCO
abrir ↗Metasploit600
ManageEngine ADSelfService Plus CVE-2021-40539
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISCO
abrir ↗GitHub PoC★ 1
A quick and dirty PoC of cve-2021-26084 as none of the existing ones worked for me.
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir ↗VulnCheck XDB
local
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.