Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.258exploits catalogados
36.019CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.697GitHub PoC 14.455VulnCheck XDB 8.811Nuclei 4.349Metasploit 3.488✓ só verificadosrecentespopularesrisco
78.258 exploits
GitHub PoC★ 3
Different rules to detect if CVE-2021-31166 is being exploited
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISCO
abrir ↗Exploit-DB
Subrion CMS 4.2.1 - Arbitrary File Upload
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca
50RISCO
abrir ↗Exploit-DB
IPFire 2.25 - Remote Code Execution (Authenticated)
lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It
50RISCO
abrir ↗Metasploit600
IPFire 2.25 Core Update 156 and Prior pakfire.cgi Authenticated RCE
lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It
50RISCO
abrir ↗GitHub PoC★ 1
0xm4ud/ProFTPD_CVE-2015-3306
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISCO
abrir ↗GitHub PoC★ 2
Pega Infinity Password Reset
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to byp
75RISCO
abrir ↗GitHub PoC★ 60
RCE for Pega Infinity >= 8.2.1, Pega Infinity <= 8.5.2
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to byp
75RISCO
abrir ↗GitHub PoC★ 1
PoC of CVE-2019-14322: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
50RISCO
abrir ↗GitHub PoC★ 827
Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely.
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISCO
abrir ↗VulnCheck XDB
denial-of-service
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 4
Exploit CVE-2017-7494 for Net Security course final Assignment. This would reveal the vulnerability of services that run in administrative priority on Linux.
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Chamilo LMS 1.11.14 - Remote Code Execution (Authenticated)
A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a paramete
46RISCO
abrir ↗GitHub PoC★ 1
This is modified code of 46635 exploit from python2 to python3.
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir ↗VulnCheck XDB
local
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISCO
abrir ↗VulnCheck XDB
initial-access
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISCO
abrir ↗Exploit-DB
Microsoft Internet Explorer 11 and WPAD service 'Jscript.dll' - Use-After-Free
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RISCO
abrir ↗Exploit-DB
Firefox 72 IonMonkey - JIT Type Confusion
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are
83RISCO
abrir ↗Exploit-DB
ZeroShell 3.9.0 - Remote Command Execution
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISCO
abrir ↗GitHub PoC★ 4
weblogic CVE-2021-2109批量验证poc
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
63RISCO
abrir ↗GitHub PoC★ 236
Exploit to SYSTEM for CVE-2021-21551
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISCO
abrir ↗GitHub PoC★ 6
CVE-2020-9496和CVE-2021-26295利用dnslog批量验证漏洞poc及exp
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISCO
abrir ↗GitHub PoC★ 12
exiftool arbitrary code execution vulnerability
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISCO
abrir ↗VulnCheck XDB
client-side
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISCO
abrir ↗VulnCheck XDB
client-side
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISCO
abrir ↗VulnCheck XDB
initial-access
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,
50RISCO
abrir ↗VulnCheck XDB
initial-access
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RISCO
abrir ↗GitHub PoC★ 3
POC Exploit written in Ruby
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISCO
abrir ↗GitHub PoC★ 96
Python exploit for the CVE-2021-22204 vulnerability in Exiftool
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISCO
abrir ↗GitHub PoC
fu2x2000/CVE-2017-17058-woo_exploit
The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/wooco
46RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.