Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.295exploits catalogados
36.048CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.721GitHub PoC 14.464VulnCheck XDB 8.813Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
78.258 exploits
GitHub PoC★ 225
CVE-2021-3156 - Sudo Baron Samedit
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir ↗Exploit-DB
Cacti 1.2.12 - 'filter' SQL Injection
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead
60RISCO
abrir ↗GitHub PoC★ 1
PoC for CVE-2018-13382, never successfully tested so swim at your own risk
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RISCO
abrir ↗Exploit-DB
Kirby CMS 3.5.3.1 - 'file' Cross-Site Scripting (XSS)
Cross-site scripting (XSS) from unsanitized uploaded SVG files
41RISCO
abrir ↗GitHub PoC★ 2
Authenticated SQL injection to command execution on Cacti 1.2.12
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead
60RISCO
abrir ↗VulnCheck XDB
initial-access
InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.
50RISCO
abrir ↗Metasploit400
SuiteCRM Log File Remote Code Execution
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumsta
50RISCO
abrir ↗Metasploit400
SuiteCRM Log File Remote Code Execution
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain
50RISCO
abrir ↗VulnCheck XDB
initial-access
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
Guangzhou 1GE ONU V2801RW 1.9.1-181203 through 2.9.0-181024 and V2804RGW 1.9.1-181203 through 2.9.0-181024 devices allow
35RISCO
abrir ↗GitHub PoC★ 10
lsw29475/CVE-2018-8611
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "
71RISCO
abrir ↗VulnCheck XDB
local
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "
71RISCO
abrir ↗VulnCheck XDB
initial-access
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISCO
abrir ↗GitHub PoC★ 1
streghstreek/CVE-2020-1938
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir ↗GitHub PoC★ 1
CVE-2019-12725 ZeroShell 远程命令执行漏洞
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISCO
abrir ↗VulnCheck XDB
initial-access
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability i
100RISCO
abrir ↗Metasploit600
Git LFS Clone Command Exec
malicious repositories can execute remote code while cloning
58RISCO
abrir ↗Exploit-DB
SEO Panel 4.8.0 - 'order_col' Blind SQL Injection (2)
The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads
28RISCO
abrir ↗GitHub PoC★ 31
Read my blog for more info -
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC
edsonjt81/sudo-cve-2019-18634
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISCO
abrir ↗GitHub PoC
edsonjt81/CVE-2019-14287-
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir ↗GitHub PoC★ 1
rebuild cve
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the mod
28RISCO
abrir ↗VulnCheck XDB
local
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir ↗GitHub PoC★ 2
b1tg/CVE-2018-6065-exploit
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch
83RISCO
abrir ↗VulnCheck XDB
client-side
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch
83RISCO
abrir ↗Exploit-DB
DzzOffice 2.02.1 - 'Multiple' Cross-Site Scripting (XSS)
attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter.
23RISCO
abrir ↗GitHub PoC★ 66
CVE-2021-1732 poc & exp; tested on 20H2
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.