Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.214exploits catalogados
36.016CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.697GitHub PoC 14.449VulnCheck XDB 8.773Nuclei 4.349Metasploit 3.488✓ só verificadosrecentespopularesrisco
78.056 exploits
GitHub PoC★ 53
alt3kx/CVE-2021-26084_PoC
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir ↗GitHub PoC★ 48
ProxyToken (CVE-2021-33766) : An Authentication Bypass in Microsoft Exchange Server POC exploit
Microsoft Exchange Server Information Disclosure Vulnerability
100RISCO
abrir ↗GitHub PoC★ 19
Exploit code for CVE-2019-17662
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RISCO
abrir ↗GitHub PoC
Strapi <= 3.0.0-beta.17.8 authenticated remote code execution
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISCO
abrir ↗Exploit-DB
Strapi 3.0.0-beta.17.7 - Remote Code Execution (RCE) (Authenticated)
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISCO
abrir ↗Exploit-DB
Strapi 3.0.0-beta - Set Password (Unauthenticated)
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISCO
abrir ↗VulnCheck XDB
initial-access
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511
100RISCO
abrir ↗VulnCheck XDB
infoleak
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir ↗GitHub PoC★ 3
guglia001/CVE-2019-18818
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISCO
abrir ↗GitHub PoC
BabyTeam1024/CVE-2017-3248
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RISCO
abrir ↗GitHub PoC★ 7
Strapi Framework Vulnerable to Remote Code Execution
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISCO
abrir ↗GitHub PoC★ 9
Exploit for CVE-2019-19609 in Strapi (Remote Code Execution)
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISCO
abrir ↗GitHub PoC★ 1
Citrix ADC RCE cve-2019-19781
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir ↗GitHub PoC★ 11
CVE-2020-25223
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511
100RISCO
abrir ↗GitHub PoC★ 1
CVE-2004-2687 DistCC Daemon Command Execution
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote at
60RISCO
abrir ↗GitHub PoC
AssassinUKG/CVE-2021-29447
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir ↗GitHub PoC★ 1
A proof of concept for CVE-2016-6515
The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password a
35RISCO
abrir ↗Exploit-DB
HP OfficeJet 4630/7110 MYM1FN2025AR/2117A - Stored Cross-Site Scripting (XSS)
A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross
23RISCO
abrir ↗Metasploit600
Atlassian Confluence WebWork OGNL Injection
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir ↗VulnCheck XDB
infoleak
SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated at
60RISCO
abrir ↗GitHub PoC★ 1
Kibana Prototype Pollution
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISCO
abrir ↗GitHub PoC★ 24
my exp for chrome V8 CVE-2021-30551
Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corru
83RISCO
abrir ↗VulnCheck XDB
client-side
Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corru
83RISCO
abrir ↗VulnCheck XDB
infoleak
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RISCO
abrir ↗GitHub PoC
rood8008/CVE-2021-35464
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RISCO
abrir ↗GitHub PoC★ 1
An implementation of CVE-2015-3306
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.